Skip to content

Security: jetbards/app

Security

SECURITY.md

Security Policy

Research Team

  • Hani Setiawan (2702464202) - Team Lead
  • Jetbar Runggu Hamonangan Doloksaribu (2702462973) - Model Development
  • Naufal Yafi (2702476240) - Data Analysis & Visualization

Data Classification

This research project handles Confidential Data provided by PT PLN Icon Plus Central Java under specific data sharing agreement. The dataset contains sensitive customer information and proprietary business data.

Supported Versions

The following versions of this research project are currently being supported with security updates:

Version Supported Notes
2.0.x Current stable release
1.1.x Security updates only
1.0.x End of life
< 1.0 Not supported

Data Security Measures

Access Control

  • Dataset access restricted to authorized research team members only
  • No raw data stored in public repositories
  • Data anonymization applied for analysis
  • Secure storage on encrypted devices

Code Security

  • Public repository contains only synthetic data and source code
  • No credentials or API keys committed to version control
  • Regular dependency vulnerability scanning

Reporting a Vulnerability

How to Report Security Issues

Please do NOT report security vulnerabilities through public GitHub issues.

Preferred Method:

  1. Email: Send details to research team at [hani.setiawan@binus.ac.id]
  2. Subject: Use "SECURITY: Customer Churn Project Vulnerability"
  3. Include:
    • Description of the security concern
    • Steps to reproduce (if applicable)
    • Potential impact assessment
    • Your contact information

Response Timeline

  • Initial Response: Within 2 business days
  • Assessment: Complete within 5 business days
  • Updates: Weekly status provided
  • Resolution: Based on severity (1-30 days)

If Vulnerability is Validated:

  • Immediate patch development
  • Coordinated disclosure with data provider (PT PLN Icon Plus)
  • Credit acknowledgment (if desired)
  • Release of security update

If Vulnerability is Declined:

  • Detailed explanation provided
  • Opportunity for follow-up discussion
  • Escalation path available

Data Handling Procedures

Confidential Data

  • Original dataset from PT PLN Icon Plus stored locally only
  • No upload to cloud services without encryption
  • Access logs maintained for audit purposes

Public Repository Content (Zenodo)

  • Synthetic datasets only
  • Anonymized code and models
  • No customer-identifiable information
  • No proprietary business intelligence

Security Best Practices for Users

Researchers using our code should:

  • Use virtual environments for isolation
  • Regularly update dependencies
  • Never commit real customer data
  • Implement proper access controls
  • Follow data protection regulations (PDPA/Indonesia)

Emergency Contact

Primary Security Contact: Hani Setiawan
Email: [hani.setiawan@binus.ac.id]
Backup Contact: Jetbar Runggu Hamonangan Doloksaribu, Naufal Yafi

Institution: Bina Nusantara University

Data Provider Coordination

All security incidents involving the original dataset will be coordinated with PT PLN Icon Plus Central Java security team.


Last Updated: November 2025
This policy applies to the research project: "Customer Churn Prediction for Telecommunication Industry in Indonesia"

There aren't any published security advisories