Security at Bidvera
Effective for the Bidvera production platform. This operational draft should be reviewed before public launch.
Security approach
Bidvera uses tenant separation, private document access, password hashing, Platform Owner MFA, audit logging, secure cookies, HTTPS enforcement in production, login throttling, signed payment webhooks and encrypted logical backups when configured.
Customer responsibilities
Use unique passwords, protect MFA/recovery codes, remove departed users promptly and upload only records your organisation is authorised to process.
Reporting
Security concerns should be reported to the Bidvera support/security contact published for the production domain. Do not include passwords or full sensitive documents in ordinary email.
