MLV Empire / Company / Security & data

Where your data lives, and what we don't claim.

Security, privacy & data residency · Updated 6 October 2026

Most vendor security pages are written to end a conversation. This one is written to save you a questionnaire: where the data physically sits today, where it is moving, what protects it, and — the part usually left out — what we do not have.

DEFrankfurt, Germany, today
INMumbai, India, after the move
TLSOn every connection
0Certifications overclaimed

In short

Your data is not hosted in Malaysia. Today the products run on Amazon Web Services in Frankfurt, Germany (eu-central-1). They are moving to a Hostinger data centre in Mumbai, India; this page will be updated when the move is complete. Outgoing email is sent through Amazon's email service in Mumbai, and backups are kept on Amazon S3. Traffic is encrypted with TLS. We handle personal data with the Personal Data Protection Act 2010 in mind, and we hold no SOC 2 or ISO 27001 certification and claim none.

01

Where your data lives

Data residency is the first question a careful buyer asks, so it goes first — including the move that is under way.

WhatHosted inWho runs it
Application servers and databases for the live products — AsliCRM, Asli ERP, Asli Dine, Asli Campus, Asli Lex, Aslio, Aslio Flow, QRasli, GuestopixToday: Amazon Web Services, Frankfurt, Germany (eu-central-1)Asli One Global, our technology partner
The same servers, after the planned moveMoving to: Hostinger, Mumbai, IndiaAsli One Global
Outgoing email (Aslio, and the emails the products send)Amazon Simple Email Service, Mumbai, India (ap-south-1) — stays on AWS after the moveAsli One Global
Database backups and uploaded filesAmazon S3 — stays on AWS after the moveAsli One Global
A dedicated deployment of a quoted productA region agreed with you, including Malaysia, written into the quoteBy agreement

If your organisation needs personal data to stay inside Malaysia, say so before you sign. For Asli ERP, Asli Dine, Asli Campus and Asli Lex a dedicated deployment in Malaysia can be priced into the quote. For AsliCRM, Aslio, QRasli and Guestopix there is no Malaysian hosting option today.

02

What is actually in place

Only things that are true today. Nothing on this list is a roadmap item.

02.01

Encryption in transit

TLS on every connection to every application and API. No plaintext endpoint is offered.

02.02

Account separation

Each customer's data is separated by account inside the applications. A dedicated deployment — its own instance and database — is available for the quoted products.

02.03

Role-based access control

Roles inside the products — Asli Dine alone ships twelve distinct roles, so floor staff cannot see what the owner sees.

02.04

Your own sending identity

Aslio sends on your verified domain with your DKIM, so your mail reputation stays yours and is not pooled with other senders.

02.05

Suppression handling

Bounces and complaints are suppressed automatically — a deliverability control and a recipient-privacy control at the same time.

02.06

Backups and export

Databases are backed up to Amazon S3, and your data is exportable. Leaving is a supported operation, not a support ticket to be slow-walked.

03

PDPA 2010 and your data

Malaysia's Personal Data Protection Act 2010 governs how personal data is handled in commercial transactions. For the personal data you give MLV Empire as a customer — your name, email, billing details — we are responsible for it under the Act. For the personal data you put into the products — your customers, students, guests or clients — you decide what is collected and why, and we and our technology partner process it on your behalf.

Because the servers are outside Malaysia, personal data you store in the products is transferred abroad: to Germany today and to India after the move. The Act has rules on transfers out of Malaysia; if your organisation's own policy limits them, raise it with us before you sign.

We do not claim PDPA certification, and you should be wary of any vendor that does. What we will do is put our handling of your data in writing, help you answer access and correction requests from the people whose data you hold, and tell you promptly if something goes wrong.

Ask for any of this in writing, or a response to your own security questionnaire, at hello@mlvempire.my.

04

What we do not have

A security page that lists only strengths is not information. Here is the other half, stated plainly so you can rule us in or out without wasting a procurement cycle.

  • No hosting in Malaysia for the shared products. See the table above.
  • No SOC 2 Type I or Type II report. If your procurement process requires one, we cannot pass it today.
  • No ISO 27001 certification.
  • No card data handled by us. Card payments go through a third-party payment provider; we never see or store card numbers.
  • No published uptime SLA or public status page for the self-serve products yet. A dedicated deployment can carry a contractual SLA; ask for it in writing.
  • No third-party penetration test report to share.
  • We are a small, new company, and the software is built by a small team at our technology partner. That is a real risk factor for a large buyer and you should weigh it.

These are gaps, not positions. But you should decide on what exists today, which is what this page is for.

Questions your IT team will ask? Ask them now.

05

Frequently asked questions

Q.01Where is my data stored?

Outside Malaysia. Today on Amazon Web Services in Frankfurt, Germany (eu-central-1); the servers are moving to Hostinger in Mumbai, India. Outgoing email goes through Amazon Simple Email Service in Mumbai, and backups are kept on Amazon S3.

Q.02Can our data be kept in Malaysia?

For Asli ERP, Asli Dine, Asli Campus and Asli Lex, yes, as a dedicated deployment priced into the quote. For AsliCRM, Aslio, QRasli and Guestopix, not today.

Q.03Are you PDPA compliant?

We handle personal data with the Personal Data Protection Act 2010 in mind and will put our obligations in writing, including the fact that data is stored outside Malaysia. There is no PDPA certificate, and we do not claim one.

Q.04Do you have SOC 2 or ISO 27001?

No. There is no SOC 2 report and no ISO 27001 certification, and we do not claim either. If your procurement requires one, we will not pass it today and would rather tell you now.

Q.05Is my data separated from other customers?

On a dedicated deployment, completely — its own instance and database. On the shared products, data is separated per account in the ordinary way of a multi-customer application.

Q.06Can we get our data out if we leave?

Yes. Data export is supported. We would rather be chosen again than keep you by making it hard to leave.

Q.07Who do we contact about a security issue?

Write to hello@mlvempire.my with the details. Please do not publish an unpatched issue before we have had a chance to respond.

Last updated 6 October 2026 · MLV Empire · Malaysia