Legal

Security Policy

Last updated: September 26, 2026

1. Our Commitment to Security

Security is treated as a core engineering discipline at BitNiti Technologies, not an afterthought. This policy summarizes the practices we follow to protect our own systems, the systems we build for clients, and the data entrusted to us.

2. Infrastructure Security

  • Production systems run on reputable cloud infrastructure with network segmentation, firewalls, and restricted administrative access.
  • Access to infrastructure is limited to authorized personnel on a least-privilege basis.
  • Systems and dependencies are kept current with security patches on a regular schedule.

3. Application Security

  • Software is built following a secure development lifecycle, including code review before changes reach production.
  • Data in transit is protected using industry-standard encryption (TLS).
  • Third-party libraries and dependencies are monitored for known vulnerabilities.
  • Input validation and output encoding practices are applied to guard against common web vulnerabilities such as injection and cross-site scripting.

4. Data Protection

We apply encryption for data in transit and, where applicable, for data at rest. Access to client and personal data is restricted to individuals who need it to perform their role, and is reviewed periodically.

5. Access Control & Authentication

  • Access to internal systems is role-based and granted on a least-privilege basis.
  • Multi-factor authentication is used to protect access to critical systems and accounts.
  • User access is reviewed periodically and revoked promptly when no longer needed.

6. Vulnerability Management

We monitor for security advisories affecting our infrastructure and software dependencies, and prioritize patching based on severity and exposure. Where appropriate, we use automated scanning tools as part of our development workflow.

7. Incident Response

We maintain an internal process for identifying, assessing, and responding to security incidents. Where an incident affects client or personal data, we aim to notify affected parties without undue delay and in line with applicable legal obligations.

8. Employee Security Practices

  • Team members are required to follow internal security and confidentiality practices as a condition of engagement.
  • Access to sensitive systems and data is granted only where necessary for a person's role.
  • Security awareness is reinforced through onboarding and ongoing internal guidance.

9. Third-Party & Vendor Security

Where we rely on third-party providers — for hosting, communication, or other infrastructure — we consider their security posture as part of choosing and working with them, and put appropriate confidentiality and data protection terms in place.

10. Reporting a Vulnerability

If you believe you've found a security vulnerability affecting our website or systems, please report it to contact@bitniti.com. Include enough detail for us to reproduce the issue, and avoid accessing or modifying data that isn't yours. We'll acknowledge reports and aim to keep you updated as we investigate.

11. Changes to This Policy

We may update this policy as our practices evolve. The "last updated" date above reflects the most recent revision.

12. Contact Us

Questions about this policy can be sent to contact@bitniti.com.