Security Policy
Last updated: April 26, 2025
bifajya ("we", "us", or "our") takes the security of our platform, services, and user data seriously. This Security Policy describes the measures we implement to protect information processed through bifajya.com and outlines responsibilities shared between us and our users.
1. Scope
This policy applies to all systems, infrastructure, applications, and data managed by bifajya in connection with the operation of bifajya.com and any associated services. It covers information collected from visitors, registered users, and any individuals who interact with our platform.
2. Data Protection Principles
We apply the following principles when handling data:
- Data is collected only to the extent necessary for the stated purpose.
- Access to data is restricted to personnel and systems that require it to perform their function.
- Data is retained only for as long as necessary and disposed of securely when no longer needed.
- Security controls are reviewed and updated on a regular basis.
3. Infrastructure Security
3.1 Hosting and Network
Our services are hosted on infrastructure maintained by reputable third-party cloud providers. These providers implement physical access controls, environmental safeguards, and network-level protections. We configure our environments to follow security best practices, including network segmentation and access restrictions.
3.2 Encryption in Transit
All data transmitted between your browser and our servers is encrypted using Transport Layer Security (TLS). We do not support deprecated or insecure protocol versions.
3.3 Encryption at Rest
Sensitive data stored on our systems is encrypted at rest using industry-standard encryption algorithms. Encryption keys are managed securely and rotated on a defined schedule.
3.4 Firewalls and Intrusion Detection
We employ firewalls, traffic filtering, and monitoring tools to detect and respond to unauthorized access attempts and anomalous activity across our infrastructure.
4. Application Security
4.1 Secure Development Practices
Security is considered throughout the software development lifecycle. Our development practices include code review, dependency management, and testing for common vulnerabilities prior to deployment.
4.2 Vulnerability Management
We monitor for known vulnerabilities in the software components we use. Security patches are applied in a timely manner based on the assessed risk level of each vulnerability.
4.3 Authentication
User accounts are protected through secure authentication mechanisms. Passwords are stored using strong one-way hashing algorithms. We recommend that users choose strong, unique passwords and enable any available additional verification options.
4.4 Session Management
User sessions are managed using secure, time-limited tokens. Sessions are invalidated upon logout and after periods of inactivity to reduce the risk of unauthorized access.
5. Access Control
Access to production systems and user data is granted on a least-privilege basis. Internal access is subject to authentication requirements and is logged for audit purposes. Access rights are reviewed periodically and revoked when no longer required.
6. Third-Party Services
We work with third-party service providers to operate our platform. These providers are selected with security in mind and are required to maintain appropriate security standards. We do not sell or share user data with third parties for purposes unrelated to the operation of our services.
A list of the categories of third-party providers we use is available in our Privacy Policy.
7. Monitoring and Logging
We maintain logs of system activity, access events, and errors. These logs are used to detect security incidents, investigate anomalies, and support operational continuity. Logs are retained for a defined period and protected against unauthorized modification.
8. Incident Response
8.1 Detection and Containment
We maintain procedures for identifying, classifying, and containing security incidents. Our team is prepared to act promptly when a potential incident is detected.
8.2 Notification
In the event of a confirmed security incident that affects user data, we will notify affected users as required by applicable obligations. Notifications will describe the nature of the incident, the data involved, and the steps we are taking in response.
8.3 Post-Incident Review
Following any significant security incident, we conduct a review to identify root causes and implement improvements to prevent recurrence.
9. Business Continuity and Backups
We maintain regular backups of critical data and systems. Backup integrity is tested periodically. Our continuity procedures are designed to restore service availability within a reasonable timeframe following an unexpected disruption.
10. User Responsibilities
Users of bifajya.com share responsibility for the security of their accounts and interactions with our platform. We ask that users:
- Use strong, unique passwords for their accounts.
- Do not share account credentials with others.
- Log out of their accounts when using shared or public devices.
- Keep their contact information up to date so we can reach them if needed.
- Report any suspicious activity related to their account promptly.
11. Reporting a Security Concern
If you believe you have discovered a security vulnerability or have a concern related to the security of our platform, we encourage you to contact us directly. Please do not publicly disclose potential vulnerabilities before giving us the opportunity to investigate and address them.
You can reach us at: help@bifajya.com
We will acknowledge your report and work to assess and resolve confirmed issues in a timely manner.
12. Changes to This Policy
We may update this Security Policy from time to time to reflect changes in our practices, technology, or applicable requirements. The date at the top of this page indicates when the policy was last revised. Continued use of our services after changes are posted constitutes acceptance of the updated policy.
13. Contact
If you have questions about this Security Policy or our security practices, please contact us: