NACSA Licensed CSSP · SOC Service Provider, Licence No. 20080-01 · VAPT Service Provider, Licence No. 20071-02

Compliance that comes from where your data lives.

Raw logs stay in your network and personal data is removed on site. Most of what your auditor asks for follows from that.

Frameworks we support.

Malaysian, Singaporean and international, all served by the same build.

FrameworkJurisdictionHow GhostAnalyst supports it
Personal Data Protection Act 2010 (Act 709)MalaysiaAligned. Personal data is removed on your site before any event leaves, with a tamper-evident processing trail.
Cyber Security Act 2024MalaysiaAligned to the national baseline. SOC monitoring and VAPT are delivered by a licensed provider.
JDN iSMS referenceMalaysia public sectorControl mapping for public-sector information security management.
MAS Technology Risk ManagementSingaporeAligned. Audit-ready evidence reporting and access monitoring for financial institutions.
Cybersecurity ActSingaporeSupports Critical Information Infrastructure obligations with data kept in your jurisdiction.
ISO/IEC 27001:2022InternationalReady. Access control, cryptography, operations security and audit logging are built in.
GDPREuropean UnionAligned. Data minimisation on site, privacy by design, and a Data Processing Agreement available.
NIST Cybersecurity FrameworkInternationalAligned across identify, protect, detect, respond and recover.

How personal data is handled.

  1. Step 1CollectedLogs arrive at the Sidecar in your network
  2. Step 2ScrubbedPersonal data is removed before anything leaves
  3. Step 3EncryptedCleaned events travel over mutual TLS
  4. Step 4RecordedA tamper-evident trail shows what was processed

Properties of the build, not settings you switch on.

Raw logs never leave your network

Reading and personal-data removal happen inside the Sidecar. Only cleaned events travel.

Mutual TLS on every connection

Both sides prove who they are, so the collector cannot be impersonated.

An open data standard

Every event is stored in OCSF, so your data stays portable and there is no lock-in.

Evidence your auditor can read

Every verdict and every approved response is recorded with its reasoning.

Regulatory Hub tracks the controls for you.

Map controls, collect evidence from live telemetry and produce the reports your regulator expects, from the same platform that watches your estate.

Explore Regulatory Hub
Vulnerability view with exposed assets and findings by severity

Bring your auditor's checklist.

60-day full-platform trial. No credit card. No inbound firewall changes. Live in under an hour.