Legal & Compliance

Trust Center

A central overview of MumuWorks security, privacy, AI governance, infrastructure practices, compliance posture, and incident handling approach.

Last updated: 23 June 2026 Applies to: mumuworks.com and MumuWorks services

1. Security overview

MumuWorks maintains reasonable technical and organizational safeguards designed to support the confidentiality, integrity, and availability of customer data. Security controls may include encryption in transit, encryption at rest where supported by the environment or provider, secure authentication flows, access controls, and audit logging aligned to operational needs.

2. Privacy overview

MumuWorks documents its data handling approach through customer-facing privacy and compliance notices, including the Privacy Policy, GDPR Notice, and Malaysia PDPA Notice. These materials describe how data is collected, used, disclosed, retained, and protected across the platform.

3. AI governance

MumuWorks is designed to support responsible AI usage through customer-configured prompts, workflow boundaries, channel controls, and human oversight. AI-generated outputs may be reviewed, edited, escalated, or rejected by users before business reliance. Customer-submitted content remains customer-owned, and prompt or output handling is limited to the operational purposes described in applicable customer-facing policies and agreements.

4. Infrastructure

MumuWorks operates as a cloud-hosted SaaS platform with tenant-aware application boundaries, storage services, background job processing, operational monitoring, backups, and disaster-recovery planning appropriate to the service stage and deployment context. Backup and recovery practices are maintained to support restoration after service disruption or data-loss events.

5. Compliance

MumuWorks aligns its public documentation and platform practices with GDPR readiness, Malaysia PDPA compliance, Meta Platform compliance, and WhatsApp Business compliance as relevant to the service features customers enable. MumuWorks does not claim ISO 27001, SOC 2, PCI-DSS, or other certifications unless those certifications are explicitly stated by MumuWorks in writing.

6. Incident response

MumuWorks monitors production systems, investigates suspicious activity, mitigates confirmed issues, and coordinates customer notification where an incident materially affects customer data or service integrity and notification is legally or contractually required. Response activities may include triage, containment, remediation, recovery, and post-incident improvement work.

7. Contact

Deploy your first AI employee

Start free, connect channels later.

Start