Compliance and security
Built for Singapore and Malaysia first: the tax returns, the e-invoicing mandates and the data-protection law your auditors will ask about.
Singapore GST and the F5 return
The Singapore country pack sets up GST codes with their full rate history, effective-dated so documents keep the rate in force on their date. The tax return produces the IRAS GST F5 box by box, and refuses to give a figure to file from if any line was left out — a line with no tax code, a code from the wrong country, or one that maps to nothing.

InvoiceNow (Peppol)
IRAS is phasing in InvoiceNow for GST-registered businesses: from 1 April 2026 for new voluntary registrants, through to all GST-registered businesses by 1 April 2031. The E-invoicing module produces InvoiceNow (Peppol) documents, and a readiness screen lists what is still missing, customer by customer. Sending them on the Peppol network needs an accredited access point, which is not yet connected.

Malaysia SST
The Malaysia country pack sets up sales tax and service tax with the MyInvois tax types and their rate history, and a tax return report for SST.
MyInvois e-invoicing
MyInvois is enforced for all businesses in Malaysia from 1 July 2026. The E-invoicing module issues MyInvois e-invoices from the invoices you already raise.
Personal data (PDPA Singapore and Malaysia)
Consoletium is a data processor for the personal data its customers store, under a data processing agreement covering the Singapore and Malaysia PDPA. It is not used for any other purpose. When a customer leaves they receive a full export, and their database and backups are deleted after the agreed retention period.
Data hosted in Singapore, one database per company
Hosted companies run on servers in Singapore. Each company has its own database and its own database login, which can open only that database, and its own application container. Companies never share tables. Self-hosted customers keep everything on their own servers.
Encrypted backups
Backups are encrypted (AES-256) before they leave the server, include attachments as well as the database, are copied to a separate provider and kept for 14 days. A restore is tested every month.
Security in brief
HTTPS with HSTS everywhere. Passwords hashed with bcrypt; the rule is at least 8 characters, following NIST SP 800-63B, with lockout after repeated failures. Every change is in the audit trail. Modules a company has not bought are refused by the server, not just hidden. Employee bank details are encrypted under a key held outside the database. If a subscription lapses, the system becomes read-only and your data can always be exported.
Tax rates and classifications in the country packs are researched, not professional tax advice. Have your tax adviser confirm the codes before your first return.
Security questions or a vulnerability to report: security@consoletium.com
See Consoletium on your own processes
Book a demo and we will walk through your order-to-cash, your warehouse and your month-end. Or pick your modules and get started today.
There is no free trial: a demo on your own scenarios is the quickest way to judge it.