Skip to content
Bid & Sign

Security

Your bids and your customers stay yours.

Every company's data is kept apart

Every record carries its company id, and the data layer refuses to run a query that isn't limited to the signed-in company. Automated checks enforce this on every release.

Passwords are never stored

Passwords are hashed with PBKDF2-SHA256 at 210,000 iterations, plus a server-side secret. Repeated failed logins are throttled per address and per account. A password change signs out every other session and remembered device.

Secrets are encrypted

Stored secrets such as two-factor seeds are encrypted with AES-256-GCM, each bound to its owner so a copied value can't be decrypted anywhere else.

Signatures are tamper-evident

Each sent estimate is fingerprinted with SHA-256. A signature is only accepted if the document is unchanged, and the signed PDF records the signer, time, IP address and fingerprint.

Everything is logged

Sign-ins, estimate changes, sends, views, signatures and admin actions are written to append-only activity and audit logs that your admins can review.

Locked-down by default

All traffic is HTTPS with HSTS. Pages ship with a strict Content-Security-Policy, forms are protected against cross-site request forgery, and staff access to our own admin console requires two-factor authentication.

Found a vulnerability? Please email support@bidandsign.com with the details. We respond within two business days and don't pursue good-faith research.