KitaJagaKita seeks to apply safeguards appropriate to the platform and information handled. Security is a shared responsibility: users must protect their accounts, devices, documents and case-reference information.
1. Purpose and scope
This Notice applies to the KitaJagaKita website, account access, concern-reporting, case-tracking, document-upload and support functions operated by the Malaysian Sub-Contractors Association (MSCA).
It explains the intended security approach and provides practical instructions for using the platform safely. It does not disclose confidential system configurations, credentials or controls that could increase security risk.
2. Security is a shared responsibility
KitaJagaKita, its authorised personnel, relevant technology providers and platform users each have responsibilities for protecting information and reducing avoidable risk.
3. Platform safeguards
KitaJagaKita seeks to use reasonable administrative, organisational and technical safeguards appropriate to the nature of the platform, the information handled and the identified risk. Depending on the relevant system and provider, safeguards may include:
- account authentication and restricted administrative access;
- role-based permissions and need-to-know access to case records;
- secure transmission technologies supported by the website and service providers;
- system logging, access records and security monitoring;
- software maintenance, security updates and provider-managed infrastructure controls;
- backups, recovery measures and operational continuity planning;
- confidentiality requirements for authorised personnel and relevant service providers;
- incident investigation, containment, documentation and corrective action.
The specific safeguards available may vary according to the website, authentication, database, document-storage, communication or other technology service involved.
4. Account and login security
Users are responsible for maintaining control of their account, login credentials, email account and devices used to access KitaJagaKita.
Do not reuse the same password used for email, banking, business systems or social-media accounts.
Each authorised user should use their own account. Shared credentials weaken accountability and access control.
Password-reset and security messages may rely on the email address connected to your account.
Do not save passwords or leave an active case session open on a shared, public or unattended device.
Apply supported operating-system, browser and security updates and use reputable device protection where appropriate.
Use a trusted connection when viewing or uploading confidential case information.
Do not send your password, one-time password, authentication code or full recovery information by email, WhatsApp, telephone or a support form.
5. Protecting case references and confidential access
A case reference may be used together with account or identity information to locate or discuss a case. Treat it as confidential operational information.
- share a case reference only with an authorised representative or the official KitaJagaKita Case Support team;
- do not post case references, screenshots or confidential status information on public social-media channels;
- verify the destination before sending case records or evidence;
- notify us if a case reference or related account information has been disclosed to an unauthorised person.
Use the official Check Status page and the secure account pathway when reviewing case information.
6. Safe document uploads
Before uploading a file, confirm that it is relevant, lawfully obtained and safe to provide. Upload only the information needed to explain or support the matter.
- check the file name and contents before selecting it;
- remove unrelated personal, financial, medical or identity information;
- conceal passwords, security codes, full card numbers and banking credentials;
- redact information about uninvolved people where possible;
- use supported file formats and comply with the displayed size and file-count limits;
- avoid uploading executable programs, macros or files obtained from an untrusted source.
Keep an unedited original copy of relevant documents and communications. A redacted copy may be used for platform submission when unrelated sensitive information should be concealed.
7. Communications, links and phishing
Attackers may impersonate organisations, support personnel or known contacts to obtain passwords, money or confidential information. Exercise caution with unexpected messages relating to account verification, urgent payment, document access or case status.
- check the sender and website destination before opening a link;
- access KitaJagaKita through the official website rather than an unfamiliar link;
- do not install software or browser extensions requested through an unexpected support message;
- independently confirm suspicious requests through the published Case Support contact;
- do not transfer money solely because a message claims that a case, report or account requires urgent payment.
Do not reply with confidential information. Preserve the sender, date, time, link and screenshot, then contact KitaJagaKita using the published details on this page.
8. Monitoring, logging and misuse prevention
To support security, accountability and service integrity, KitaJagaKita and relevant technology providers may maintain logs, authentication records, access records, submission records, administrative activity and technical security information.
These records may be reviewed to investigate suspected unauthorised access, account misuse, fraud, malicious files, harassment, platform abuse, service disruption or a security incident.
Access may be restricted, suspended or terminated where reasonably necessary to protect users, records, systems or the integrity of the service.
9. Managed infrastructure and technology providers
The platform may rely on third-party website, hosting, authentication, database, customer relationship management, document-storage, email, messaging, analytics, backup and security services.
Security responsibilities may therefore be shared between MSCA, KitaJagaKita administrators and the relevant provider. Provider access should be limited to the services supplied and governed by appropriate contractual, confidentiality and security controls.
More information about the processing of personal data is available in the Privacy Notice.
10. Availability, maintenance and recovery
The website or a connected service may occasionally be unavailable because of maintenance, provider interruption, internet failure, security response, software issues or circumstances outside the platform operator’s reasonable control.
Where appropriate, the operator may perform maintenance, apply updates, restrict access, restore records or activate recovery procedures to protect the service and its users.
KitaJagaKita should not be treated as the only storage location for contracts, invoices, evidence or other important business records.
11. Responsible vulnerability reporting
If you believe you have identified a technical vulnerability, report it privately and responsibly. Do not exploit the issue, access another user’s data, download unnecessary records, alter information, disrupt the service or publicly disclose sensitive technical details before there has been a reasonable opportunity to investigate and respond.
A useful report should include:
- a clear description of the suspected issue;
- the affected page, feature or service;
- the approximate date and time observed;
- safe, minimal steps that allow the issue to be understood or reproduced;
- screenshots or technical evidence that do not expose unnecessary personal data;
- your contact details for follow-up.
Do not perform denial-of-service testing, destructive testing, credential attacks, social engineering, malware deployment, physical attacks, mass automated scanning or unauthorised access to another person’s account or information.
12. Security incident and personal data breach response
When a suspected security incident is reported or identified, the operator may take steps appropriate to the circumstances, including:
Gather available information and assess the affected system, account, data and potential impact.
Restrict access, preserve evidence, reset credentials, isolate affected functions or take other protective action.
Review relevant records, provider information, technical indicators and the circumstances of the incident.
Correct identified weaknesses, restore service where appropriate and monitor for continued risk.
Make applicable notifications to affected individuals, authorities, providers or other parties where required or appropriate.
Personal data breaches are handled according to the applicable Malaysian personal-data-protection requirements and the nature and impact of the incident.
13. What to do if your account may be compromised
Act promptly when you notice an unfamiliar login, password-reset message, changed account information, unexpected case activity or another sign of unauthorised access.
- change the account password using a trusted device and network;
- change any other account that reused the same or a similar password;
- secure the connected email account and review its recovery settings;
- sign out of shared devices and stop using any device suspected of being compromised;
- preserve relevant messages, dates, screenshots and account activity;
- contact KitaJagaKita Security Support using the details below;
- report fraud, threats or criminal activity to the appropriate authorities where necessary.
14. No absolute security guarantee
No website, account, device, network, transmission method, service provider or storage environment can be guaranteed to be completely secure or continuously available.
This Notice describes the security approach and user expectations. It is not a warranty that the platform will be free from every vulnerability, interruption, unauthorised act or security incident.
15. Changes to this Security Notice
This Notice may be updated when platform functions, technology providers, security practices, risks or applicable requirements change. The current version will be published on this page with its effective date.
16. Report a security concern
Provide a clear description, the affected page or service, approximate date and time, relevant evidence and your contact details. Do not email passwords, one-time passwords, banking credentials or unnecessary identification documents.
Malaysian Sub-Contractors Association (MSCA)
KitaJagaKita Security Support
6A Office Suites, Scott Sentral Service Suites,
28, Jalan Scott, Brickfields,
50470 Kuala Lumpur, Malaysia
Email:
support@kitajagakita.my
Case Support:
+60 12-379 5729