Skip to main content

Security & Data Protection

Your RFP documents contain sensitive business information. Here's how we protect it — with the same standards federal contractors expect.

Data Encryption

All data is encrypted at rest using AES-256 and in transit using TLS 1.3. Your RFP documents, account data, and analysis results are protected with industry-standard encryption that meets federal security requirements.

  • AES-256 encryption for all stored documents
  • TLS 1.3 for all data in transit
  • Encrypted database connections at all times
  • Secure key management with automatic rotation

Infrastructure Reliability

Our infrastructure is designed for high availability with redundant systems, automated failover, and 24/7 monitoring. We maintain a 99.9% uptime SLA to ensure the platform is available when you need it most.

  • 99.9% uptime SLA with redundant systems
  • Automated backups with point-in-time recovery
  • 24/7 infrastructure monitoring and alerting
  • Global CDN for fast, reliable access

Access Control

We follow the principle of least privilege across our entire organization. Every access request is authenticated, authorized, and logged. Your data is accessible only to you and your authorized team members.

  • Role-based access control (RBAC) internally
  • Multi-factor authentication for all staff accounts
  • Session management with automatic timeout
  • Comprehensive audit logging of all access events

Data Retention & Deletion

You control your data. Uploaded RFP documents are retained for 90 days by default, and you can delete them at any time. When you delete your account, all your data is permanently removed within 30 days.

  • User-controlled data retention settings
  • Automatic 90-day document cleanup (default)
  • Immediate deletion available on request
  • Complete account data purge within 30 days of deletion

Compliance Roadmap

We're actively pursuing industry-standard security certifications. Our security practices are designed to meet the requirements federal contractors expect and need.

  • SOC 2 Type II — In progress (planned 2026)
  • NIST 800-171 alignment — In progress
  • FedRAMP readiness — Future roadmap
  • Regular third-party security assessments

Responsible Disclosure

We take security seriously and welcome reports from the security research community. If you discover a vulnerability, we commit to acknowledging your report within 24 hours and resolving critical issues promptly.

  • Dedicated security response team
  • 24-hour acknowledgment for all reports
  • 48-hour resolution for critical vulnerabilities
  • Responsible disclosure recognition program
AES-256 Encryption
99.9% Uptime SLA
Your Data, Your Control
24hr Response

Have security questions or concerns? Contact our security team at security@bidrank.pro. We take every inquiry seriously and respond promptly.