Security & Trust

    Your tender data.
    Protected.

    The platform is built to the same standards of trust and reliability that civil engineering demands on site.

    ✓ GDPR Compliant
    ✓ UK Hosted ·
    ⟳ ISO 27001 (Roadmap)

    Data Residency

    UK Only

    Encryption

    AES-256 & TLS 1.2+

    Uptime SLA

    99.9% Target

    How we protect your data

    Six core security pillars built into every layer of Bidonix.

    Data Encryption

    All data encrypted at rest using AES-256. All data in transit protected by TLS 1.2+. Encryption keys are managed and rotated regularly.

    UK Data Residency

    All data is hosted and processed within the UK regulatory zone on AWS eu-west-1. No data leaves the region. GDPR-compliant infrastructure.

    Access Controls

    Role-based access control (RBAC) ensures each user sees only what they need. Multi-factor authentication (MFA) available for all accounts.

    GDPR Compliance

    We are fully GDPR compliant. We act as a data processor for your organisation. A Data Processing Agreement (DPA) is available on request.

    Audit Logging

    Every action in the platform is logged with a full audit trail. Admins can review who accessed what data and when. Complete transparency and accountability.

    ISO 27001 (Roadmap)

    We are working toward ISO 27001 certification. Our security management system is being built to this standard from day one.

    Built on AWS.
    Hosted in the UK.

    Bidonix runs on Amazon Web Services (AWS), the most trusted cloud infrastructure in the world. Your data is hosted in the .

    We use auto-scaling, redundant availability zones, and automated backups to ensure your data is always available and protected. provides the security and compliance standards required for UK civil engineering data.

    What data
    we hold

    • Tender opportunity data (aggregated from public sources)
    • Bid documentation and workspace files
    • User account and authentication data
    • Communication logs (RFI & correspondence)

    We never sell your data. We never share it with third parties without your consent.

    If something goes wrong

    Security is a commitment we take seriously. Our incident response process prioritises transparency and rapid resolution.

    24-Hour Notification

    You'll be notified within 24 hours of any security incident affecting your data.

    Dedicated Contact

    A dedicated security contact ensures you're always in direct communication with our team.

    Transparent Process

    We communicate clearly about what happened, what we're doing, and how we're preventing it again.

    Contact us: security@bidonix.com

    Need a Data Processing Agreement?

    We provide a standard DPA for all customers. Contact us to request yours.