Security Policy
Last updated: September 20, 2025
Data Protection
We employ enterprise-grade security measures to protect your data and ensure the integrity of our platform.
- All data encrypted in transit and at rest using AES-256 encryption
- Regular security audits and penetration testing
- Multi-factor authentication (MFA) support
- Role-based access control (RBAC)
Authentication & Access Control
- OAuth 2.0 integration with Google, LinkedIn, and Microsoft
- Session management with secure tokens
- Automated logout after inactivity
- Password strength requirements and hashing
Blockchain Security
- Immutable tender records on blockchain
- Smart contract auditing and verification
- Secure wallet integration protocols
- Transparent bidding process verification
Payment Security
- PCI DSS compliant payment processing
- PayPal secure payment gateway integration
- Tokenized payment data storage
- Regular financial security assessments
Incident Response
- 24/7 security monitoring and alerting
- Automated threat detection systems
- Rapid incident response protocols
- User notification procedures for security events
Compliance & Standards
- GDPR compliance for EU users
- SOC 2 Type II certification
- ISO 27001 information security standards
- Regular compliance audits and assessments
Security Contact
If you discover a security vulnerability, please report it to our security team:
- Email: security@pantender.com
- Response time: Within 24 hours
- PGP Key: Available upon request
Bug Bounty Program: We reward security researchers who help us improve our platform security.