ISO/IEC 27001:2022

MYeBills holds current ISO/IEC 27001:2022 certification — the international standard for information security management systems. This is the 2022 revision, the most current version of the standard.

ISO/IEC 27001:2022
Information Security Management

Independently audited and certified to ISO/IEC 27001:2022. Certifying body: Guardian Independent Certification Ltd (GICG), accredited by IAF MLA and JAS-ANZ.

Valid until 07 August 2028
Certificate No. 763497
Standard ISO/IEC 27001:2022
Scope Provision of Mailing Processing Services for Bank and Telecommunication
Date of Issue 08 August 2025
Date of Expiry 07 August 2028
Certifying Body Guardian Independent Certification Ltd (GICG)
Accreditation IAF MLA · JAS-ANZ

Built to Malaysian regulatory requirements.

Beyond certification, MYeBills' platforms are designed and built to align with Malaysia's specific financial regulatory frameworks. These are not post-hoc compliance additions — they are built into the architecture of each platform.

LHDN · Malaysia
MyInvois — Built to Specification

MYeBills' Enterprise Invoice Management (EIM) platform is built to LHDN's MyInvois API specifications. EIM handles the full e-invoice submission lifecycle — ingestion, validation, submission, response handling — and is live in production at a major Malaysian financial institution since July 2025.

Note: MYeBills builds to LHDN MyInvois specifications. This is a compliance alignment, not an LHDN accreditation or certification status.

PayNet · Malaysia
Open Finance Platform — OFP Aligned

MYeBills' Open Finance Infrastructure is built to PayNet's Open Finance Platform (OFP) specifications — covering Data Consumer (DC), Data Provider (DP), FAPI-compliant API gateway, and consent management. Developed in direct engagement with the PayNet team.

Note: MYeBills builds to PayNet OFP specifications. This is a technical alignment, not a PayNet certification or endorsement.

BNM · Malaysia
BNM Guidelines — Deployment Aligned

All MYeBills platforms are deployed on-premise within client infrastructure — consistent with Bank Negara Malaysia's data residency and outsourcing guidelines for financial institutions. No customer financial data is processed or stored outside of the client's own environment.

Note: On-premise deployment is a standard practice across all MYeBills engagements, not a BNM-specific waiver or exception.

PDPA · Malaysia
Personal Data Protection Act — Policy in Place

MYeBills maintains a formal Personal Data Protection Act (PDPA) policy governing the collection, processing, and handling of personal data across all platform operations and client engagements. Our PDPA policy is available on request.

Full PDPA documentation available to clients and prospective clients upon request.

How we deploy — and why it matters to your security team.

Beyond certifications and regulatory alignment, the way MYeBills deploys its platforms is designed to meet the security and governance requirements of enterprise financial institutions.

On-premise deployment

All platforms are deployed within the client's own infrastructure. No data is processed, stored, or transmitted to MYeBills infrastructure or third-party cloud environments.

Role-based access control

All platforms support Active Directory integration, role-based access control, and Checker/Maker workflows — aligned with enterprise banking governance requirements.

Full audit logging

Every platform maintains comprehensive audit logs — all user actions, system events, data submissions, and access requests are logged with full traceability for internal and regulatory review.

Encrypted communications

All platform communications — API calls, file transfers, email delivery — use encrypted channels. Customer document delivery (e.g. e-invoice PDFs) uses document-level encryption with customer-specific keys.

99.9% uptime SLA

Enterprise SLA with 24/7 support. Every deployment includes a named support contact and documented escalation path — not a generic helpdesk.

Documentation on request

Security architecture documents, PDPA policy, audit reports, and platform technical specifications are available to prospective clients under NDA for due diligence purposes.

Need compliance documentation for your due diligence?

Our team is happy to provide full compliance documentation to prospective clients under NDA — including ISO certificate, PDPA policy, and platform security architecture.

Request documentation