Legal
Security
Last updated: 2 September 2026
Tender data is commercially sensitive. This page sets out the measures we take to protect the drawings, rates and submissions our customers trust us with.
Encryption
All traffic between your browser and BOQBid is encrypted in transit using TLS. Project files and database contents are encrypted at rest by our infrastructure providers.
Access control
Access to production systems is limited to the small number of staff who need it, protected by multi-factor authentication and reviewed periodically. Within your organisation, roles and permissions let you decide who can see or edit each project.
Tenancy and isolation
Customer data is logically separated so that one organisation's drawings, rate libraries and estimates are never visible to another. Support staff access customer content only when you ask us to investigate an issue.
Backups and continuity
Databases and uploaded files are backed up regularly, and restores are tested so that data can be recovered after a failure. Infrastructure is hosted with established cloud providers operating in resilient, geographically separated data centres.
Secure development
Changes are reviewed before release, dependencies are monitored for known vulnerabilities, and security fixes are prioritised over feature work. We use least-privilege credentials and keep secrets out of source control.
Monitoring and response
We log access to production systems and monitor for unusual activity. If an incident affects your data, we will investigate, contain it, and notify affected customers promptly with what we know and what we are doing about it.
Reporting a vulnerability
If you believe you have found a security issue in BOQBid, please tell us before disclosing it publicly. Write to us with the details and steps to reproduce, and we will acknowledge your report and keep you updated on the fix.