School Logo

Campus Visitor Safety

CVTS Portal

Staff Authentication

Sign In to Portal

Enter your institutional email and password to access the system.

Need technical assistance or system support?

WhatsApp Support: +60 11-5449 9913
🛡️

Campus Data Security & PDPA Compliance

Official technical specification for School Board (LPS) & PIBG

🔐 AES-256-CBC

Encrypted at Rest

Sensitive visitor personal data (IC, contact phone, visitor name, student name) is encrypted using standard AES-256-CBC cryptography before storage on disk.

SHA-256 Blind Index

Blind Indexing

Returning visitor deduplication uses one-way SHA-256 cryptographic hashing, preventing raw IC numbers from being exposed during database query execution.

👥 RBAC Masking

Role-Based Privacy

Security guards access names and phone numbers for entry verification, while IC numbers are automatically masked (e.g. 880101-10-****) to protect visitor privacy.

🎫 Anti-IDOR

Cryptographic Tokens

Scannable badges and digital passes utilize unpredictable 32-character tokens, eliminating sequential ID enumeration risks.

📜 Personal Data Protection Act 2010 (PDPA) Aligned

Architected in accordance with the 7 statutory data protection principles under Malaysian law: General, Notice & Choice, Disclosure, Security, Retention, Data Integrity, and Access.

⚖️ Technology Provider & Data Governance Disclaimer

The School Board and Administration act as the sole Data Controller under PDPA 2010. The technology provider (SGEN AI) supplies the software infrastructure on an "as-is" basis and does not own, process, or assume custody of visitor data. The institution is solely responsible for on-premise server environment security, key safeguards, and staff credential management.