Security Policy
1. Our Commitment to Security
Security is treated as a core engineering discipline at BitNiti Technologies, not an afterthought. This policy summarizes the practices we follow to protect our own systems, the systems we build for clients, and the data entrusted to us.
2. Infrastructure Security
- Production systems run on reputable cloud infrastructure with network segmentation, firewalls, and restricted administrative access.
- Access to infrastructure is limited to authorized personnel on a least-privilege basis.
- Systems and dependencies are kept current with security patches on a regular schedule.
3. Application Security
- Software is built following a secure development lifecycle, including code review before changes reach production.
- Data in transit is protected using industry-standard encryption (TLS).
- Third-party libraries and dependencies are monitored for known vulnerabilities.
- Input validation and output encoding practices are applied to guard against common web vulnerabilities such as injection and cross-site scripting.
4. Data Protection
We apply encryption for data in transit and, where applicable, for data at rest. Access to client and personal data is restricted to individuals who need it to perform their role, and is reviewed periodically.
5. Access Control & Authentication
- Access to internal systems is role-based and granted on a least-privilege basis.
- Multi-factor authentication is used to protect access to critical systems and accounts.
- User access is reviewed periodically and revoked promptly when no longer needed.
6. Vulnerability Management
We monitor for security advisories affecting our infrastructure and software dependencies, and prioritize patching based on severity and exposure. Where appropriate, we use automated scanning tools as part of our development workflow.
7. Incident Response
We maintain an internal process for identifying, assessing, and responding to security incidents. Where an incident affects client or personal data, we aim to notify affected parties without undue delay and in line with applicable legal obligations.
8. Employee Security Practices
- Team members are required to follow internal security and confidentiality practices as a condition of engagement.
- Access to sensitive systems and data is granted only where necessary for a person's role.
- Security awareness is reinforced through onboarding and ongoing internal guidance.
9. Third-Party & Vendor Security
Where we rely on third-party providers — for hosting, communication, or other infrastructure — we consider their security posture as part of choosing and working with them, and put appropriate confidentiality and data protection terms in place.
10. Reporting a Vulnerability
If you believe you've found a security vulnerability affecting our website or systems, please report it to contact@bitniti.com. Include enough detail for us to reproduce the issue, and avoid accessing or modifying data that isn't yours. We'll acknowledge reports and aim to keep you updated as we investigate.
11. Changes to This Policy
We may update this policy as our practices evolve. The "last updated" date above reflects the most recent revision.
12. Contact Us
Questions about this policy can be sent to contact@bitniti.com.