📍 6 Raffles Quay, #14-06, Singapore 048580 ✉ enquiries@twotwotech.ai ☎ +65 6717 0088
Service · Powered by Jumborca SERVICE

Find out whether your backups actually survive a ransomware event — or an audit

We find out whether your backups actually survive a ransomware event or an audit, and hand you an audit-ready remediation plan. In Singapore, Malaysia and Indonesia we combine our local delivery with Jumborca's Resilience Intelligence platform — one team for sales, deployment, operations and the regulatory layer.

SupAI.ONE — unified BaaS / DRaaS for M365, VMs, endpoints, databases, NASSupInsight — a queryable, replayable, auditable DR decision layerSupDRC — active-active + cross-region DR · RTO ≤ 10min · RPO ≤ 10s90-day POC — terminate any day, no fee2-week Resilience Assessment as the low-commitment way in

The problem

2:47 AM. The CIO of a Singapore-licensed insurer gets a page: the core policy database is being encrypted by ransomware. Six people crowd onto the incident bridge, staring at twelve screens. Then the hardest question of the night lands: “Do we fail over to DR right now? What’s the success probability? Who explains it to the board tomorrow if it doesn’t work?”

That has never been a question backup software could answer. It’s a judgement call. For thirty years, that call has lived in a senior engineer’s gut at 2 AM — untraceable, unauditable, and impossible to reproduce. Jumborca’s claim — and ours, as their regional partner — is that a judgement like that belongs in software.

The Jumborca product portfolio we resell

SupAI.ONE · Unified BaaS / DRaaS

One console, many workloads. M365 (Exchange, OneDrive, SharePoint, Teams), VMs (VMware, Hyper-V, KVM), endpoints, databases (SQL Server, Oracle, MySQL, PostgreSQL, MongoDB), NAS, K8s persistent volumes. Tri- cloud (AWS, Azure, GCP) with Singapore-region default for PDPA data residency. WORM + BYOK + zero-trust. Immutable snapshots an attacker with admin credentials cannot delete. Instant VM Power-On under 90 seconds, second-grade RPO. This is the offering most customers start with after the assessment.

SupInsight · The AI decision brain

What separates Jumborca from every other backup or DR vendor. Three modes:

You can disable AI recommendations at any time and fall back to a traditional rule engine. No lock-in.

SupDRC · Active-active + cross-region DR

In-city active-active, cross-region DR, application-level consistency, failover by business group, graceful rollback. Oracle / DB2 / MySQL / PG / SAP HANA / VMware / K8s. Goal: RTO ≤ 10 minutes · RPO ≤ 10 seconds. Measured RTO 8 minutes on a deployed nationwide retail bank.

SupVault · Long-term compliance retention

Object storage plus WORM plus tiered retention plus access audit trail. Pre-wired templates for MAS, CBIRC, healthcare and energy regulators. Designed so the evidence chain comes out in under 1 hour when an auditor asks.

SupDrill · Rehearsal & audit automation

Runbook engine plus sandbox target environments plus auto-generated regulator reports. Takes the rehearsal cycle from yearly paper exercise to monthly real failover. Reporting effort: 5 days down to 2 hours.

How to start

Tier 1 · The 2-week Resilience Assessment (fixed fee)

Best for: customers who want a defensible posture quickly without committing to a product purchase yet.

What you walk away with after 2 weeks:

  1. A sensitive-data inventory mapping where personal, financial and health-relevant data lives across every system we touch.
  2. A scorecard against ~80 PDPA + ISO 27001 control objectives, with evidence.
  3. A prioritized remediation plan sequenced to get you to a defensible posture inside 6 months.

Delivered to the documentation standard IMDA / EDG audits require. During your PSG or EDG application, TWO TWO will make every effort to make these assessment artifacts available as application materials.

Tier 2 · The 90-day Jumborca POC

Best for: customers ready to evaluate the full Resilience Intelligence platform under real conditions before signing.

You can terminate at any day during the 90 days. No fee owed, no explanation required. Lock-in is something we and Jumborca both refuse to do — any DR purchase anchored by contract lock-in has already lost.

Contact sales · Start a 90-day POC

Stack we typically reach for

Jumborca SupAI.ONE (BaaS / DRaaS)Jumborca SupInsight (AI decision brain)Jumborca SupDRC / SupVault / SupDrillAzure Southeast Asia / AWS Singapore / Alibaba Cloud InternationalCompliance: ISO 27001 · GDPR · HIPAA · DJCP L3 · PDPA · MAS TRM

Frequently asked about Find out whether your backups actually survive a ransomware event — or an audit

What does TWO TWO actually do here vs going direct to Jumborca?
Jumborca builds the products in Singapore (HQ at 6 Raffles Quay) and Suzhou. TWO TWO is the regional resale and delivery partner across SG / MY / ID — we run the sales conversation in Mandarin, English, Bahasa Malaysia or Bahasa Indonesia; we integrate Jumborca into your existing Veeam / Oracle DG / VMware / hyperscaler stack; we layer PDPA / MAS TRM / BNM RMiT / OJK POJK regulatory documentation on top; we run the bilingual 24×7 helpdesk; and we are your contractual counterparty. You never coordinate across two vendors.
Walk me through the product portfolio I'm reselling.
SupAI.ONE — unified BaaS / DRaaS, M365 + VMs + endpoints + databases + NAS in one console, Instant VM Power-On under 90 seconds, second-grade RPO. SupInsight — AI decision brain that answers 'should I fail over right now?' with probability, cost and explainability for the board or regulator. SupDRC — in-city active-active + cross-region DR with business-group failover, RTO ≤ 10min · RPO ≤ 10s. SupVault — long-term compliance retention with WORM and pre-built MAS / BNM / OJK templates. SupDrill — rehearsal automation, from annual paper exercise to monthly real failover with auto-generated regulator reports.
How does the 90-day POC work?
Three phases. Weeks 1–3: discovery — current DR inventory, last 12 months of incidents, regulatory scope (MAS / BNM / OJK). Weeks 4–9: pilot — pick 1–2 representative systems, deploy SupAI.ONE + SupInsight, weekly sandbox rehearsals, your engineers feed RLHF back into the model. Weeks 10–13: validate — live failover, compliance review, ROI model, rollout plan. You can terminate any day during the 90 days — no fee, no explanation owed. Lock-in contracts on critical-system DR are something we and Jumborca both refuse to do.
What if I'm not ready for a 90-day POC yet?
Start with the 2-week Resilience Assessment — fixed fee, delivered to audit-grade documentation standards. You walk away with a sensitive-data inventory, a posture scorecard against ~80 PDPA + ISO 27001 control objectives, and a prioritised remediation plan. If you choose to apply for PSG or EDG, the same artefacts work as evidence. No commitment to the broader Jumborca POC — many clients stop here, take the plan, and execute themselves over the next 6 months.
Who's the typical customer in SG / MY / ID?
Regulated mid-market and enterprise: MAS-licensed banks, insurance and fintech in Singapore; BNM RMiT scope in Malaysia; OJK POJK 11 / 12 scope in Indonesia; healthcare with PDPA + HIPAA-equivalent obligations; energy / utilities with critical-infrastructure designations; large e-commerce or logistics groups where 30 minutes of downtime crosses the headline threshold. Also: China-outbound enterprises with Jumborca already deployed at HQ who need consistent continuity posture at their Singapore subsidiary.

Other services

SERVICE One customer view across ERP, dealers, cross-border e-commerce and after-sales

For Chinese manufacturers and tech companies expanding overseas: bring the customer and business data scattered across HQ ERP, overseas dealer CRMs, cross-border e-commerce and after-sales — into a single working view. LLMs sit inside the tools the field sales team and HQ management already use, so everyone is finally looking at the same picture.

Read →
SERVICE One IT foundation, delivered by one team — for Singapore SMEs and Chinese enterprises expanding overseas

Most SME IT stacks grew organically — ad-hoc procurement, staff changes, one-off requests. Email, endpoint, network, backup and permissions live in separate systems. Everything runs, but nothing is easy to audit, scale, or plug an AI project into. TWO TWO brings the whole foundation under one plan, one delivery and one team. Business systems (ERP / CRM / OA) are covered separately under our Yonyou alliance.

Read →
SERVICE Singapore / SEA IT Landing

For Chinese enterprises where HQ has an IT team back home but the Singapore, Malaysia or Indonesia office has nobody on the ground — we take over the local IT setup end to end. Cloud accounts, domains, mailbox, data centre, devices, compliance posture. Bilingual, so HQ back home can talk to us directly.

Read →
SERVICE Hardware & Software Procurement

Authorised reseller across server, network, endpoint hardware and licensed software — plus renewal management, true-up tracking and hardware-refresh planning. Local SGD invoicing, warranty handled, one renewal calendar we actually keep. Your team doesn't wake up to a locked-out production account.

Read →
SERVICE TWO TWO × Yonyou Alliance — YonSuite / YonBIP in Singapore

TWO TWO is an accredited channel partner of Yonyou Singapore. Around YonSuite (for SMEs) and YonBIP (for mid-to-large groups) we cover the full lifecycle — solution advisory, blueprint, product licensing, professional delivery, custom development and managed operations. We specialise in customers whose HQ already runs Yonyou and needs overseas subsidiaries on the same stack.

Read →
SERVICE Custom Web & Application Development

Web portals, mobile apps and internal tools built around your actual workflow — not a SaaS template you have to bend the business to fit. We wire them into the systems you already run (ERP, CRM, identity, billing) and keep operating them on Day 2, so the product keeps evolving with you instead of going stale six months after launch.

Read →
SERVICE TWO TWO BaaS

Nightly snapshots of servers, VMs, Microsoft 365 and Yonyou Cloud into Singapore data nodes. After a ransomware hit or an outage, we run the restore. Monthly fee scales with protected capacity.

Read →
SERVICE Overseas compute · data-centre integration + 24×7 NOC

Carrier-grade data-centre project integration and ongoing operations across Singapore and SEA. We build and run DC-scale projects for the major telcos (CMI, China Telecom, China Unicom, Singtel, NTT) on behalf of their enterprise customers — especially Chinese enterprises expanding overseas standing up GPU compute, cross-border BGP, multi-DC HA and AI training / inference farms.

Read →

Dive Deeper

Talk to us

Start with the problem. The solution comes after.

A 30-minute call with a solution architect. No spec needed — just tell us where the business is stuck. Systems that don't talk. Data that won't behave. An overseas office with no one running IT. A DR plan on paper that no one has tested. A first AI use case you want to try for real. If we fit, we'll show you the next step. If not, we'll tell you straight.