Security & Data Protection
Your RFP documents contain sensitive business information. Here's how we protect it — with the same standards federal contractors expect.
Data Encryption
All data is encrypted at rest using AES-256 and in transit using TLS 1.3. Your RFP documents, account data, and analysis results are protected with industry-standard encryption that meets federal security requirements.
- AES-256 encryption for all stored documents
- TLS 1.3 for all data in transit
- Encrypted database connections at all times
- Secure key management with automatic rotation
Infrastructure Reliability
Our infrastructure is designed for high availability with redundant systems, automated failover, and 24/7 monitoring. We maintain a 99.9% uptime SLA to ensure the platform is available when you need it most.
- 99.9% uptime SLA with redundant systems
- Automated backups with point-in-time recovery
- 24/7 infrastructure monitoring and alerting
- Global CDN for fast, reliable access
Access Control
We follow the principle of least privilege across our entire organization. Every access request is authenticated, authorized, and logged. Your data is accessible only to you and your authorized team members.
- Role-based access control (RBAC) internally
- Multi-factor authentication for all staff accounts
- Session management with automatic timeout
- Comprehensive audit logging of all access events
Data Retention & Deletion
You control your data. Uploaded RFP documents are retained for 90 days by default, and you can delete them at any time. When you delete your account, all your data is permanently removed within 30 days.
- User-controlled data retention settings
- Automatic 90-day document cleanup (default)
- Immediate deletion available on request
- Complete account data purge within 30 days of deletion
Compliance Roadmap
We're actively pursuing industry-standard security certifications. Our security practices are designed to meet the requirements federal contractors expect and need.
- SOC 2 Type II — In progress (planned 2026)
- NIST 800-171 alignment — In progress
- FedRAMP readiness — Future roadmap
- Regular third-party security assessments
Responsible Disclosure
We take security seriously and welcome reports from the security research community. If you discover a vulnerability, we commit to acknowledging your report within 24 hours and resolving critical issues promptly.
- Dedicated security response team
- 24-hour acknowledgment for all reports
- 48-hour resolution for critical vulnerabilities
- Responsible disclosure recognition program
Have security questions or concerns? Contact our security team at security@bidrank.pro. We take every inquiry seriously and respond promptly.