Security Policy
The company Qbid AB, with corporate registration number 559478-3077, will be referred to in this document as BidPal.ai, which is our brand name.
At BidPal.ai, protecting customer data is one of our top priorities. We are committed to being transparent about our security practices and helping you understand our approach. Below is an overview of our security program.
Security Governance
We periodically conduct internal assessments of risks and potential threats, as well as load and stability testing. Based on these reviews, we create action plans to improve security and infrastructure. As part of our roadmap, we plan to introduce regular external vulnerability assessments and penetration testing to further strengthen our security posture.
Operational Security
Access Management
Access privileges are role-based across our core platforms, including Microsoft Azure, Google Cloud, and within the application itself. We follow the principle of least privilege by granting access only to those who need it for their role. Access to production systems is protected with strong authentication methods, and access rights are reviewed and adjusted when roles or responsibilities change.
Vulnerability Management
We implement a robust vulnerability management process that includes regular third-party scans, automated and manual penetration testing, and software security reviews. Identified vulnerabilities are logged, prioritized by severity, assigned to an owner, and remediated promptly.
Malware Prevention
Anti-malware solutions are deployed on all corporate devices and servers. Safe link services are used to prevent malware from being installed via malicious websites or infected links.
Monitoring and Alerting
We use logging, automated health checks, and Messenger-based notifications to monitor system activity and errors. Critical issues are escalated to the development team for investigation and resolution. In addition, our cloud providers (Microsoft Azure and AWS) supply built-in monitoring tools that further enhance visibility into infrastructure performance and availability.
Data Center Security
BidPal.ai uses Microsoft Azure for its cloud infrastructure. Azure data centers are protected by multiple layers of physical and digital security, including 24/7 monitoring and strict access controls. Customer data is encrypted at rest using AES-256 and in transit using TLS 1.2 or higher.
Data Security
Data Segregation
Customer data is logically separated within our systems through company- and user-level access controls. Each customer can only access their own data and related tenders, ensuring proper isolation within the shared infrastructure.
Employee Access to Customer Data
Access to customer data is restricted to a very limited number of authorized personnel and is granted only when necessary for business or technical reasons. All access to infrastructure is logged through Azure, providing an audit trail of activities
Data Retention and Destruction
Customer data is retained as long as the account remains active, unless a customer requests deletion. Upon such a request, data is securely deleted from our systems.
Application Security
Secure Software Development Lifecycle (SDLC)
All code is managed through Git, and production releases are tracked in version control. Access to the source code repository is restricted to a small number of authorized developers. As part of our development roadmap, we plan to introduce more automated testing and formal code review practices to further enhance security
Security by Design
We incorporate security considerations directly into development by leveraging built-in protections of frameworks such as Laravel and FastAPI, including safeguards against common attacks (e.g., CSRF, input validation, and output encoding). In addition, API endpoints are tested during development to help identify and mitigate potential risks.
Security Testing
We conduct internal testing of our applications, including manual reviews of API endpoints, functional tests, and load/stability checks. Identified issues are prioritized and resolved as part of our development cycle.
Network Security
Our infrastructure is protected by Azure’s built-in security features and network firewalls configured on our virtual machines. These measures help safeguard our environment against unauthorized access and common threats.
Third-Party Vendor Management
BidPal.ai conducts rigorous security assessments of third-party vendors before onboarding. Vendors must comply with BidPal’s.ai security, confidentiality, and privacy requirements.
Regulatory Compliance and Privacy
Customer data privacy is a core priority at BidPal.ai. We do not sell personal data and use it only to provide and improve our services. While customers may use our platform to participate in tenders across various industries, the responsibility for submissions and compliance with specific industry regulations rests with the customer. We follow applicable data protection standards and are prepared to adapt our practices to evolving regulatory requirements.
For further inquiries regarding our security policy, please contact us at: [email protected]