ZENTARA

Industries · Technology & Startups

Your longest sales cycle is the security review.

The product demo went well. Then procurement sent a 300-line questionnaire, your best engineer lost two weeks to it, and the deal is still sitting in vendor risk review. Security stopped being a cost centre for companies like yours the moment your buyers became banks, ministries and hospitals — it is now the gate the revenue passes through. Zentara works on getting you through it, and on being worth passing.

PSE
Registration required to operate
Komdigi — for electronic system providers in Indonesia
ISO 27001
What Indonesian enterprise procurement asks for
Certifiable, and increasingly a precondition rather than a differentiator
SOC 2
What foreign customers ask for instead
An attestation, not a certification — the two are not interchangeable
72 hrs
To notify a personal data breach
UU PDP — including on behalf of your customers' data

What we are defending

What a serious buyer will actually examine.

01

Tenant isolation

The first question a competent reviewer asks and the one most answers dodge. Prove separation rather than describing the intent to separate.

02

The build pipeline

Access to CI is access to production, usually with less logging and fewer approvals than the front door it bypasses.

03

Customer data lifecycle

Where it lives, who can reach it, how it leaves, and what happens on offboarding. Deletion is the answer that is least often true.

04

APIs and integrations

Authorisation at object level, rate limiting, and what a partner token can reach if it is stolen. Where fast-growing products break first.

05

Subprocessors

Your customer inherits every one of them. A subprocessor list you cannot produce quickly is a review you will not pass quickly.

06

The questionnaire itself

A surface in its own right. Answered from scratch each time it consumes senior engineering; answered from a maintained evidence base it takes an afternoon.

Instrument · Obligation · Commercial outcome

Your customer's regulator has become your regulator.

Sell to a bank and POJK 11 makes your security their problem to evidence, which makes it yours to demonstrate. Sell to a ministry and PP 71/2019 constrains where you may run. The obligations below are not all directly yours in law — several arrive through a contract, which is why they surface in procurement rather than from a regulator.

PSE registration

Komdigi

Requires

Registration as an electronic system provider operating in Indonesia, with the obligations that follow it.

We do

Establish where you sit, complete the position, and make it verifiable by a customer who checks — because increasingly they do.

What unblocks the deal

Registered status, evidenced

UU PDP

Republik Indonesia

Requires

Lawful processing and 72-hour breach notification. As a processor you also carry contractual duties to every controller you serve.

We do

Controller and processor mapping, data flow documentation, and a notification runbook that names who calls the customer and when.

What unblocks the deal

DPIA, data flow map, notification runbook

ISO 27001

Certifiable

Requires

A management system, certified by an accredited body. The default request from Indonesian enterprise and government procurement.

We do

Readiness and implementation scoped to your actual size — the smallest scope that is honest, rather than the largest that is billable.

What unblocks the deal

Certifiable ISMS, audit-ready

SOC 2

Attestation

Requires

An independent report on controls over a period, requested by North American and some European buyers. Not a certification, and not a substitute for ISO 27001 with a local buyer.

We do

Advise honestly on which your pipeline actually needs. Pursuing both before either is required is a common and expensive mistake.

What unblocks the deal

Readiness assessment, control evidence

POJK 11/POJK.03/2022

Inherited via contract

Requires

Where your customer is a bank, their third-party and outsourcing obligations become terms in your agreement and questions in their audit.

We do

Prepare for the bank's assessment rather than reacting to it, using the same framework we use when we sit on the bank's side of the table.

What unblocks the deal

Pre-built response pack

PP 71/2019

Inherited via contract

Requires

Where your customer is a public-scope operator, placement and residency constraints reach your architecture.

We do

Architecture and documentation that answers the residency question with a diagram rather than a clause.

What unblocks the deal

Documented data path

Review · How far you get before someone asks for a call

The gap between true and provable is where deals die.

Most growth-stage companies are more secure than their paperwork suggests. The controls exist, the engineers are careful, and none of it is written down in a form a reviewer can accept — so a deal that was technically won stalls for six weeks in a process nobody owns. The ladder below is not a security maturity scale. It is how much of your sales cycle security is currently costing you, and the move from level three to level four is usually worth more commercially than the security improvement itself.

Procurement readiness

  1. 1

    Ad hoc

    Every questionnaire answered from scratch, by an engineer, at the expense of the roadmap.

  2. 2

    Documented

    Policies exist and answers are reusable. Claims are still assertions.

  3. 3

    Evidenced

    Each control has an artefact behind it — a test result, a log, a configuration — that a reviewer can accept.

  4. 4

    Certified

    ISO 27001 or SOC 2, current, with scope that genuinely covers the product being bought.

  5. 5

    Pre-empted

    A published trust centre answers most of the review before it starts. Reviewers verify rather than interrogate.

Highlighted: where a company selling to regulated buyers needs to be for security to stop delaying revenue.

Derived from enterprise and public sector vendor review practice

Sector threat model

  • Cloud and IaC misconfiguration shipped at the speed the roadmap demands
  • CI/CD as the shortest path to production for anyone who reaches a developer's laptop
  • Multi-tenant isolation that was correct at ten customers and has not been re-examined at a thousand
  • Dependency and supply chain exposure inherited from packages nobody chose deliberately
  • Secrets in repositories, in CI variables, and in the Slack message where somebody pasted one
  • A single enterprise customer's incident becoming your incident, contractually and reputationally

What this sector answers to

The regulatory landscape for technology & startups. Our own accreditations are listed on certifications.

PSE registrationUU PDPISO 27001SOC 2POJK 11 — inheritedPP 71/2019 — inherited

Track record

Penetration testing and ISO 27001 readiness delivered for scaling platforms, and third-party assessment run from the other side of the table for the banks and institutions those platforms sell into.

For companies selling into regulated buyers

You will be audited by people who audit for a living.

The first time a bank's third-party risk team assesses you is a different experience from any customer conversation you have had. They have a framework, a mandate and no commercial incentive to be satisfied. The good news is that the framework is knowable in advance, and we spend the other half of our week on their side of the table.

  • Pre-assessment against the same third-party framework a bank or ministry will apply, before they apply it.
  • Evidence pack assembled once and maintained, rather than reconstructed per deal by whoever is least busy.
  • Subprocessor register and data flow documentation ready to hand over — routinely the slowest item in a review.
  • Support on the call when their assessor asks something your team has not been asked before.

Before you have to justify us internally

Bringing in a security vendor is itself a risk you have to evidence.

So here is the answer to the questions your risk committee will ask, before they ask them.

A test that blocks your release has failed

Work is scheduled around your deployment cadence, on staging wherever it is representative, and production only with a plan you agreed. Velocity is not something you should trade for this.

We write the answers, not only the report

Findings come mapped to the frameworks your buyers actually ask about, in language you can paste into a questionnaire. A PDF nobody can use is half the job.

We will tell you not to buy the certification yet

Chasing ISO 27001 and SOC 2 simultaneously before either is required has sunk more startup quarters than any breach. Sequence follows your pipeline, not our invoice.

Retest is included, not a second engagement

You fix, we verify, the evidence updates. Charging again to confirm a fix turns remediation into a budget conversation and slows it down.

Scoped for the stage you are at

A twelve-person company does not need the programme a bank needs. Selling you one anyway is easy, and it is the reason security firms have the reputation they do here.

Your engineers end up able to answer

The durable outcome is your own team fielding a security review without escalating. That reduces what you spend with us, and it is still the right outcome.

VAPT & Offensive Security

Penetration testing for Technology & Startups

42 services in the catalog apply to Technology & Startups — from point-in-time pentests to red team and continuous validation.

Explore all 42
Penetration Test

External Network Penetration Test

Black-box test of internet-facing assets, perimeter exposure, and exploitable services.

Penetration Test

Internal Network Penetration Test

Assumed-breach lateral movement, AD abuse, sensitive data discovery from inside.

Penetration Test

Wireless Penetration Test

WPA2/3 Enterprise, rogue AP, evil twin, BLE, guest network segregation.

Penetration Test

Network Segmentation Validation

Verifies VLAN/firewall isolation between zones (CDE, OT, corporate).

Penetration Test

Active Directory / Entra ID Security Assessment

Kerberoasting, AS-REP, ACL abuse, BloodHound paths, hybrid identity review.

Assessment

Firewall, Router & Switch Configuration Review

Rule base hygiene, ACL drift, hardening against CIS Benchmarks.

Penetration Test

VPN Security Assessment

IKE/IPsec, SSL VPN, split tunneling, ZTNA migration readiness.

Assessment

Email & DNS Security Review

SPF/DKIM/DMARC, MTA-STS, DNSSEC, BIMI, phishing surface.

Securing technology & startups?

Start with a scored maturity baseline or go straight to a specialist conversation.