Indonesia's largest crypto exchange with SOC 2 certification roadmap
INDODAX operates Indonesia's largest digital asset exchange, serving the region since 2014. The tech stack is security-focused—Burp Suite, OWASP ZAP, Nessus, OpenVAS, and Frida dominate alongside cloud infrastructure (AWS, Azure, GCP)—reflecting active work on SOC 2 certification, red-team campaigns, and bug-bounty oversight. Security and QA represent half the hiring mix, and the project roadmap (purple-team exercises, automation frameworks, vulnerability prioritization) indicates a compliance-driven maturation phase rather than feature velocity.
Notable leadership hires: QA Lead
INDODAX is a crypto and digital asset exchange headquartered in Jakarta, serving Indonesia and Southeast Asia. The platform provides trading, custody, and related financial services to retail and institutional users in the region. At 51–200 employees, the company is scaling compliance infrastructure and security posture in parallel with product development. Current operational focus includes SOC 2 readiness, KYC/AML enforcement, and cross-market expansion.
Burp Suite, OWASP ZAP, Nessus, OpenVAS, Frida, and Postman for testing and vulnerability assessment. They're also designing red-team campaigns and running purple-team exercises.
SOC 2 certification, automation framework development, red/purple team exercises, bug bounty program oversight, and market-entry strategy. Internally, talent grooming and succession planning are underway.
Other companies in the same industry, closest in size