When "Legal Threats" Become the Threat, Misconduct By Burman Noviansyah CMU CISO Program Graduate and Xendit Company

A figure connected to Xendit invoked criminal procedure codes, mental health stigma, and time-barred allegations to silence me. Here is why that backfires legally and ethically, and who we are actually talking about.
There is a particular kind of pressure campaign that does not announce itself as intimidation. It wears the costume of legal counsel, of professional concern, of advice between people who "know how things work." It is designed to make you feel exposed, isolated, and guilty before any court has heard a word. I experienced exactly that when messages from an individual connected to Xendit landed in my feed and inbox.
Who Is Burman Noviansyah?
Before examining what was said, context matters. The individual involved is Burman Noviansyah, identifiable via his LinkedIn profile at linkedin.com/in/mrburman. His public professional footprint tells a specific story that is directly relevant to how his messages should be read and weighed.


About
Detest stagnancy, love challenging jobs, self-motivated, and think out-of-box. Experienced in Java Development and Information Security, specialized in Cyber Forensics and Incident Response. A holder of EC-Council's Certified Ethical Hacker (CEH) v4.1, EXIN's ITIL V2, CERT® Certified Cyber Forensics and Incident Response (CyFIR) Track and ISC2 CISSP. CMU CISO Certificate Program graduate with Honorable Mention Project Group Final Presentation. Specialties: IT Forensics (network and host-based), Secure Programming, Java Development, Penetration Tester, Computer Network Security, Cyber Forensics Analyst, Blockchain and Smart Contract Development on Ethereum.
Burman holds a Master of Science in Information Security Policy and Management (MSISPM) from Carnegie Mellon University's Heinz College, completed between 2012 and 2014. He attended SMA Negeri 1 Palembang. He operates in the computer and network security industry, and his current employer is deliberately kept undisclosed on his public profile despite his willingness to reference his former Xendit role as a credential when engaging in disputes.
The deliberate concealment of a current employer on a professional profile, while simultaneously invoking the name of a past employer as institutional authority during a private dispute, is a pattern worth noting. It creates the impression of institutional backing without the accountability that comes with it.
His LinkedIn self-description reads: "Detest stagnancy, love challenging jobs, self-motivated, and think out-of-box." What the screenshots below reveal is someone who, in the context of my labor dispute with Xendit, chose to channel that self-described energy into private threats referencing buried legal cases and criminal procedure codes rather than engaging with the substance of my claims.
What Was Actually Said By Burman Noviansyah and Xendit
Two screenshots tell the story. The first is a public comment posted under the Xendit brand account, addressed to me by name. The second is a private message from Burman himself. Both deserve scrutiny.
Exhibit A: Public Comment, Xendit Account (@soullesemployee)

"Perlu diingatkan lagi gak apa yang pernah kamu 'ambil' dari logo? Kondisi mental kamu gak bisa digunakan buat menyelamatkan kamu dari apa yang sudah kamu perbuat loh."
Translation: "Need a reminder of what you once 'took' from logo? Your mental condition cannot be used to save you from what you have done."
Exhibit B: Private Message, Burman Noviransyah

"Pisahkan lu punya masalah dengan personal atau punya masalah dengan kantor tempat personal yg lu targetin. Lu somasi Xendit, legal council akan bongkar lagi kasus lu yg dulu gw tangani. Padahal itu kasus ga ada yg tau. Kalo sampe kasus ini P21 dan gw diseret jadi saksi, I'm not going to cover up everything karena sudah duduk di kursi saksi harus patuh dengan sumpah. Your lawyer should've told you this. Jadi, lu mau somasi pegawai Xendit atau lu mau somasi Xendit?"
Translation: "Separate your personal problem from your problem with the company where that person works. If you send a somasi to Xendit, legal counsel will reopen a past case I handled. No one knows about that case. If this reaches P-21 and I am pulled in as a witness, I will not cover everything up because a witness chair demands an oath. Your lawyer should've told you this. So, do you want to somasi a Xendit employee or do you want to somasi Xendit?"
Several things are striking here. First, Burman implicitly admits he handled a prior case involving me, and that its existence was kept quiet. Second, he frames his potential testimony as a threat rather than a civic duty. Third, he positions the somasi process itself as something that would trigger adverse consequences for me, not Xendit. This is an inversion of how legal process is supposed to work.
The Mental Health Smear: A Legal Minefield
The public comment invokes my "mental condition" as though it were a confession of criminal culpability or a character defect to be weaponized. This framing is not only factually baseless, it is legally illiterate under Indonesian law.
The new Criminal Code (KUHP UU 1/2023) addresses mental disability in criminal proceedings with precision and empathy. Pasal 38 provides that a person who commits an offense while experiencing a mental or intellectual disability may have their sentence reduced or face an appropriate measure instead. Pasal 39 goes further: a person who commits an offense during an acute episode of mental disability with psychotic features cannot be sentenced at all.

The law treats mental health as a mitigating or exempting factor, not an aggravating one. Using it as a cudgel to intimidate someone in a labor dispute is both legally incoherent and a violation of the disability rights principles embedded in Indonesian legislation. A Carnegie Mellon-educated cybersecurity professional should know better.
The P-21 Threat: Weaponizing Criminal Procedure
Burman deploys a specific piece of procedural vocabulary: P-21. In Indonesian criminal procedure, P-21 is the administrative code issued by the Public Prosecutor's office confirming that investigation files are complete and that the case may proceed to prosecution. It is not a verdict. It is not a conviction. Invoking it as a threat in a private message, before any case has even been filed, is a calculated intimidation tactic.

More critically: the alleged incident being referenced is stated to have occurred more than two and a half years ago. Under Pasal 29 of UU 1/2023, the statute of limitations for filing a criminal complaint is six months from the date the right-holder becomes aware of the offense if they reside in Indonesia. A matter from 2.5 years ago, never formally reported, is time-barred. Invoking it as a threat is not a legal strategy. It is theater designed to produce fear.

The Credential Gap: Information Security Background vs. Legal Conduct
There is an irony worth naming directly. Burman holds a graduate degree in Information Security Policy and Management from one of the most respected programs in the world for that discipline. The Heinz College MSISPM program is specifically oriented toward the intersection of technology, law, and policy. It trains professionals to understand governance, legal frameworks, and the ethical dimensions of information systems.
Someone with that educational background, operating in the computer and network security industry, would be expected to understand the legal parameters of threatening communications, the limitations of procedural intimidation, and the distinction between legitimate legal process and coercive pressure. The messages documented above do not reflect that understanding. They reflect, instead, a confidence that the target will not know the law well enough to push back.
That confidence was misplaced.
The Core Question Being Avoided
Notice what neither message does: it does not address the substance of my labor dispute. It does not engage with the documented violations of UU No. 6/2023 or PP No. 35/2021. It offers no facts, no evidence, no legal counter-argument. It pivots instead to character attacks, mental health stigma, procedural threats, and vague references to buried secrets.
This is a pattern I have seen consistently throughout this process. When the substance of a dispute is weak, pressure shifts to the person. The goal is to make the complainant feel so exposed and frightened that they withdraw, not because the law is against them, but because the social and psychological cost feels unbearable. I want to name that pattern clearly so that others facing similar pressure recognize it for what it is.
Why I Am Writing This Publicly
I am not writing this out of anger. I am writing it because accountability in Indonesia's tech ecosystem requires documentation. When individuals connected to well-resourced companies use private channels to deliver thinly veiled threats, and when those messages invoke legal machinery selectively and inaccurately, the public interest demands that someone describe exactly what was said and what the law actually says in response.
I have filed formal reports at Bareskrim and through PERADI. I am proceeding with the somasi process through Infraloka's legal infrastructure. Every communication is documented. And I will continue to write about what I experience, precisely and without exaggeration, because transparency is the only protection available to individuals who face institutional pressure.
If you are a founder, engineer, or professional in Indonesia's tech industry who has faced similar pressure, I am open to conversation. This ecosystem grows stronger when people stop staying silent out of fear and start building the documentation culture that accountability requires.
#IndonesianLaborLaw #DigitalAccountability #Infraloka #SomasiAsAService #TechEcosystem #KUHP2023 #UUITE #WorkerRights #PublicAccountability #IndonesiaTech #HukumKetenagakerjaan #StartupIndonesia #Xendit #CyberLaw #InformationSecurity