Security at Bidvera

Effective for the Bidvera production platform. This operational draft should be reviewed before public launch.

Security approach

Bidvera uses tenant separation, private document access, password hashing, Platform Owner MFA, audit logging, secure cookies, HTTPS enforcement in production, login throttling, signed payment webhooks and encrypted logical backups when configured.

Customer responsibilities

Use unique passwords, protect MFA/recovery codes, remove departed users promptly and upload only records your organisation is authorised to process.

Reporting

Security concerns should be reported to the Bidvera support/security contact published for the production domain. Do not include passwords or full sensitive documents in ordinary email.