-
Client Type: SaaS HR/payroll provider serving medium-sized enterprises
-
Challenge:
-
Centralized database stored employee salary, tax IDs, and contract details
-
Dev and QA teams accessed production data copies for testing purposes
-
No masking or audit logs on sensitive fields
-
-
Key Risks:
-
Non-compliance with internal and partner data-handling policy
-
Potential exposure of PII during routine operations
-
-
SEVOLA’s Database Security Solution:
-
Enabled dynamic masking of PII fields (e.g., salary, NIK, NPWP)
-
Limited data exports to defined IP addresses and user roles
-
Enabled full audit logging for every access to sensitive tables
-
-
Result:
-
Improved data discipline and segregation between teams
-
Passed third-party data protection review
-
Established a clean and auditable framework for PDP readiness
-
