UNIMAS REKA Logo UNIMAS REKA Usage Policy
Governance Standard Effective Academic Session

REKA Application Platform

Official Acceptable Use Policy (AUP). This policy outlines access rules, safety principles, naming guidelines, and project handovers.

UNIMAS Logo

AUP Compliance & Availability Checker

Check if your proposed REKA subdomain complies with the rules and search live server registry availability.

.ia.unimas.my

1. Objective

This policy explains the rules for creating, deploying, and owning applications on the REKA platform. It helps protect university data, ensures clear accountability, and separates administrative work, academic projects, and open sandbox testing.

2. Platform Architecture & Instance Scope

To protect university data, REKA is divided into three separate environments based on who will use the applications and how sensitive the data is:

Administrative

ia.unimas.my

This instance is strictly for administrative work, automating processes, and official university operations. It is restricted to UNIMAS departments and units.

Academic

aa.unimas.my

This instance is strictly for official academic applications and systems that support academic processes (such as course registration, online applications, transcripts, viva, and thesis submission).

Sandbox & Open

ireka.my

This is a completely open playground and testing environment. Students, external users, and developers can use it to try out REKA, build prototypes, and run commercial projects.

3. Mandatory Ownership & Governance Requirements

To maintain operational continuity and clear responsibility, application creation and ownership are governed by strict access rules:

Mandatory Staff Oversight Mandate (Strictly for ia & aa)

If you build or host an application on either the Administrative (ia.unimas.my) or Academic (aa.unimas.my) instances, you must include at least one (1) active UNIMAS Staff member as a registered co-creator or owner in the application settings.

4. Final Executive Authority & Oversight

While UNIMAS staff provide direct project oversight, final deployment validation, namespace rights, and lifecycle management rest centrally to maintain enterprise architecture standards.

TAHODC Institutional Mandate

The Tun Abang Haji Openg Digital Centre (TAHODC) holds the absolute and final decision-making authority over the approval, production deployment, and continuation of any application hosted on the ia.unimas.my and aa.unimas.my domains. TAHODC reserves the right to audit, veto, suspend, or terminate access to any application within these domains.

5. URL Subdomain Allocation & Namespace Governance

Every application can have a unique, accessible web link (such as <app-path>.aa.unimas.my). To keep university systems clean and organized, your web links must follow these rules:

  • Be Specific: The link must clearly describe what the application does. Do not use generic or broad names like register, admin, or portal. For example, use course-register instead of register.
  • Branding & Initiatives: If the application has a specific brand or official initiative name, it is highly recommended to use it. Examples include edonation (for the eDonation System), ipserv4all (for the IP·SERV 4 ALL Initiative), or traqr (for TraQR - QR File Tracking System).
  • Include Faculty Abbreviations: If your application is only used within a single faculty or department, you should include the standard faculty abbreviation in the link (for example, viva-fskpm.aa.unimas.my).
  • Reserved Keywords: The paths io, create, design, and core are strictly reserved for platform operations and cannot be used.
  • Path Dispute Resolution: If there is any conflict, dual claims over identical subdomains, or ambiguous requests, TAHODC has the final say in assigning, altering, or revoking links.

6. Security, Safety & Regulatory Compliance

All applications must be safe. Applications built on this platform must never threaten the university’s network, data, or reputation.

Zero-Tolerance Security Enforcement

Every app built on the REKA platform must satisfy strict safety requirements. If an app performs illegal activities, contains malicious content or scripts, leaks data, or leaves the university open to security hacks, TAHODC will take immediate action.

All security violations will be processed and penalized in accordance with the Dasar Keselamatan ICT UNIMAS, which may result in removing the app immediately, suspending developer profiles, and disciplinary actions.

7. Project Handover Lifecycle & Quality Assurance

To make sure applications are secure, stable, and easy to maintain over the long term, we follow a specific process when transitioning projects into TAHODC custody:

Target Handover Scope

This process applies strictly to any application developed outside of TAHODC or not initiated through the formal JKSPA (Jawatankuasa Saringan Pembangunan Aplikasi) process that is scheduled to be officially handed over to TAHODC.

Mandatory Assessment Request

Project teams must submit a formal assessment request to TAHODC before the app can be handed over.

Design & Approach Verification

TAHODC will check that the app's user interface (UI/UX) style, system database design, and coding methods fit their standards.

⏳ App Stabilization Window

Once TAHODC gives technical feedback, the project will enter a mandatory cleanup period. The creators must adjust, optimize, or fix the platform code based on TAHODC's feedback before the center accepts final custody.

8. Production Deployment: Dev to Live

To ensure platform stability and quality, all applications must go through a formal registration process before transitioning from Development to Live (Production) mode.

Step 1: Mandatory Registration

An application must be formally registered through the REKA dashboard before it can be requested for a transition to Live mode. Unregistered applications will remain locked in Development.

Step 2: Committee Processing

The registration request will be processed by the REKA Committee. If the app meets all criteria, it will be transitioned to live. If it falls short, the committee will provide actionable feedback for necessary revisions.