Engineering aligned to Malaysia's national cloud vision.
Malaysia's National Cloud Computing Policy sets the direction: secure, sovereign, inclusive, and sustainable cloud futures. JamaCore is establishing in Kuala Lumpur to build exactly that way — cloud-agnostic, compliance-first, and committed to local capability.
The policy names the risk: vendor lock-in. Our model is the answer.
The NCCP lists vendor lock-in and data sovereignty among the national barriers to cloud adoption. JamaCore's practice was built around avoiding both: portable infrastructure-as-code, model-agnostic AI, documented exit paths, and sovereign patterns where the data must stay in Malaysia.
Sovereignty without lock-in
Architectures that keep Malaysian data under Malaysian control — without surrendering choice.
- Multi-cloud designs across AWS, Azure, and Google Cloud Malaysian regions
- In-country residency for the data categories that require it
- Customer-held sovereign encryption keys for data processed abroad
- Portable Terraform and documented exit strategies as standard
Compliance-first delivery
Every system we ship in Malaysia is designed against the frameworks that govern it — with the evidence generated by the platform.
- Personal Data Protection Act 2010 (Act 709) by design
- Cyber Security Act 2024 (Act 854) alignment for critical sectors
- BNM Risk Management in Technology (RMiT) for financial services
- ISO/IEC 27001 and 27017 cloud-security controls
Growing local capability
The NCCP's inclusivity pillar is a commitment we share: Malaysian MSMEs are 96.9% of businesses, and cloud adoption still has far to run.
- Right-sized cloud and AI packages for Malaysian SMEs
- Skills transfer built into every engagement — your team learns the system
- Local engineering hires as the practice grows
- Bahasa Malaysia and English delivery
Built for Malaysian frameworks.
| Ref | Framework | Applies to | How JamaCore delivers |
|---|---|---|---|
| NCCP | National Cloud Computing Policy — five pillars: Enhance, Nurture, Secure, Include, Sustain | All sectors | Cloud-agnostic architecture, sovereign patterns, SME enablement, energy-aware design |
| ACT 709 | Personal Data Protection Act 2010 (PDPA) | All commercial data processing | Privacy by design: data mapping, consent flows, PII sealing in AI pipelines |
| ACT 854 | Cyber Security Act 2024 | National critical information infrastructure | Zero Trust architecture, incident readiness, NACSA-aligned governance |
| RMiT | Bank Negara Malaysia — Risk Management in Technology | Financial services | Control mapping, resilience design, and audit evidence generated from the platform |
| ISO | ISO/IEC 27001:2022 & 27017 cloud controls | All engagements | Controls deployed as code and verified continuously, not annually |
Delivered from Melbourne today, supported from Kuala Lumpur as the practice grows — the same senior engineers, to the same standard.