WiBiz Information Security Programme Summary
Version: v1.0
Published: 6 August 2026
Owner: WiBiz Operations
Classification: Public
Status: Current public summary
1. Purpose
Digital Benefits Pte Ltd, trading as WiBiz, maintains an information security programme for its corporate operations and client delivery. This summary explains the public commitments and the boundary between a written control requirement and evidence that the control operated for a specific service.
2. Governance commitments
WiBiz requires:
- named ownership for security, privacy, systems, delivery, evidence, and risk acceptance;
- risk-based security requirements before a production build is approved;
- documented policies, operating standards, review dates, and controlled versions;
- independent review where the risk, client requirement, or assurance tier calls for it;
- recorded exceptions with an accountable approver, compensating control, deadline, and expiry;
- prompt reassessment after a material change, serious vulnerability, or incident;
- accurate public and client statements that remain within the verified evidence scope.
3. Evidence rule
A policy is a commitment. It is not proof that a control operated in every system. A control claim for a client or product requires evidence that identifies:
- the organisation, service, environment, and period in scope;
- the exact claim or control;
- the owner and verifier;
- the source record, configuration, contract, log, test, or report;
- the collection and verification dates;
- the result, limitation, exception, and next review;
- the version and checksum where applicable.
If current evidence is absent or incomplete, the approved status is not yet confirmed, partial, or an open exception.
4. Build-specific assurance
Each applicable production build receives a Security and Data Annex. It records data categories, providers, regions, access, encryption, logging, retention, recovery, service providers, security testing, exceptions, and evidence references for that exact build.
5. Disclosure
Public summaries are available in this Trust Center. Detailed architecture, internal procedures, access records, raw evidence, test findings, incident material, and restricted provider records are shared only through an approved confidential channel.
6. Contact
Security enquiries: security@wibiz.ai
Data-protection enquiries: dpo@wibiz.ai
WiBiz Information Security Programme Summary v1.0, 6 August 2026.