At Likha ERP, security isn’t a claim — it’s a verified fact.
Our platform has undergone a comprehensive, independent Vulnerability Assessment and Penetration Testing (VAPT) by DATA-PROVE Cybersecurity.
We don’t just rely on business policies or internal checks. LikhaERP was tested at the application layer — the level where real cyber threats strike.
DATA-PROVE’s team of certified penetration testers used the OWASP Top 10 framework — the global gold standard for web application security — to simulate real-world attack scenarios. Their assessment covered both authenticated and unauthenticated vectors, probing every critical function of the system.
The audit went deep into the heart of LikhaERP’s web infrastructure:
API & GraphQL Endpoint Security — Ensuring no schema or data exposure vulnerabilities exist.
Session Management & Cookies — Validating protection against hijacking, replay, and timeout misuse.
Authentication Systems — Verifying login strength, password controls, and brute-force resistance.
Access Control Validation — Confirming that user roles and permissions are isolated and secure.
The testing was led by Rhenzo Verdad, VAPT Lead of DATA-PROVE, under Project Reference DP216.
Conducted from October 31 to November 2, 2025, the full-scope test included both primary and backup staging environments — ensuring consistent security across deployments.
The result?
LikhaERP passed all application-level validation tests after rigorous review, confirming our platform’s ability to withstand real-world attack patterns.
At LikhaERP, we design with collaboration in mind — and security at the core.
Independent testing ensures that every workflow, automation, and integration you use is backed by a foundation that’s been technically validated, not just policy-approved.
Because true security isn’t about saying you’re protected.
It’s about proving it — through transparency, third-party validation, and continuous improvement.
Conducted by: DATA-PROVE Cybersecurity
Assessment Period: October 31 – November 2, 2025
Testing Standard: OWASP Top 10
Discover why more Philippine SMEs are choosing hybrid ERP solutions — cloud-ready systems with offline capabilities. Learn how this trend saves costs, boosts reliability, and fits the unique challenges of doing business in the Philippines.
Learn what features matter most when choosing an ERP system in the Philippines — hybrid cloud reliability, automation, centralized data, and modern workflows for SMEs, enterprises, and government offices.
Compare cloud ERP and on-premise ERP options in the Philippines. Learn the pros, cons, costs, and why hybrid ERP is becoming the most practical choice for Philippine SMEs, enterprises, and government agencies.
A complete guide for Philippine SMEs on choosing an affordable ERP system. Learn cost factors, must-have modules, hidden fees, and how to pick the best ERP without overspending.
Learn the essential ERP integrations needed by Philippine SMEs, enterprises, cooperatives, and government agencies to streamline operations, automate workflows, and ensure compliance.
LikhaERP is validated for security through independent Vulnerability Assessment and Penetration Testing (VAPT). Tested under OWASP standards, our platform ensures robust application-level resilience and secure operations.