For AI agents: use /llms.txt for the Nakafa content index.
Last updated: August 22, 2026
This Security Policy describes the security measures PT NAKAFA TEKNO KREATIF ("Nakafa," "we," "us," or "our") uses, and the measures we expect users to take, to help protect the confidentiality, integrity, and availability of the Services and related data.
For information about how we collect and use Personal Data, please review our Privacy Policy.
This Security Policy applies to the Services operated by Nakafa, including websites and applications hosted and supported through third-party providers.
This Security Policy does not cover the security practices of third parties you interact with directly outside the Services, even if those third parties are linked from the Services.
Security is a shared responsibility:
The following sections distinguish implementation-backed measures, provider responsibilities, and public commitments accepted by Nakafa.
Our production web delivery uses HTTPS. Nakafa also applies HTTP Strict Transport Security and related browser security headers across all application paths. The implementation and provider documentation for this revision are linked below.
At application boundaries, authenticated user capabilities require a validated session and an active application user. Internal content endpoints accept only a bearer credential checked with a timing-safe comparison. This statement does not describe how individual infrastructure providers assign access to their administrative consoles.
Application data is stored in Convex. Nakafa application functions that require authentication use the validated sessions and active-user checks linked below. Infrastructure-level storage protection is supplied by Convex and is not represented here as a separately verified Nakafa storage control.
Production Next.js request failures are reported to PostHog only when server exception reporting is enabled. Each report keeps sanitized stack frames and an allowlisted, length-bounded technical context such as the route, request method, or framework error digest. Nakafa uses these reports to diagnose the specific failure and plan corrective maintenance. This is not a representation that Nakafa operates a separate security-information or abuse-detection system.
Operational exception reports do not carry a user, account, or product-analytics identifier. Optional product-usage events are separate and require an effective analytics consent decision.
The Nakafa repository workflow automatically audits dependencies and runs tests for pull requests. Trusted internal and main-branch runs also build the production application. These checks reduce risk but do not establish that every vulnerability has been found or remediated.
The technical statements above are bounded to the following exact Nakafa implementation revision and provider documentation:
The Services rely on third-party services. Their security practices and controls are important to the overall security of the Services. Our core third-party services include:
Each third party may process data as part of providing the Services. For details about categories of data shared and purposes, review our Privacy Policy.
We encourage responsible disclosure of security vulnerabilities.
If you believe you have found a security vulnerability, contact us at nakafaai@gmail.com with the subject line “Security Report”.
To help us triage and respond, include:
Do not include sensitive Personal Data in your report. Do not exploit the vulnerability beyond what is necessary to demonstrate it. Do not attempt to access data that is not your own.
If we become aware of a suspected incident, we will take steps appropriate to the facts to:
Notification timelines vary by jurisdiction and the nature of the incident. For example, if a security incident qualifies as a personal data breach under GDPR and notification is required, notification obligations may include reporting to a supervisory authority without undue delay and, where applicable, within 72 hours of becoming aware of the breach.
You can help protect your account by:
Authenticated user capabilities require a validated session and an active application account as described above. We may restrict access when reasonably necessary to protect the Services or users.
We may update this Security Policy from time to time to reflect changes in our security practices or legal requirements. Updates will be posted on this page with a revised “Last updated” date.
PT NAKAFA TEKNO KREATIF, Taman Sukahati Permai Blok H-6, Sukahati, Cibinong, Kabupaten Bogor, Jawa Barat 16913, Indonesia
Email: nakafaai@gmail.com