E-Auction← Back to Sign In
Security

Security Policy

Last updated: January 2025

Data Protection

All data transmitted through the ProcureX platform is encrypted in transit using TLS 1.3 and at rest using AES-256. We do not store sensitive credentials — passwords are hashed using bcrypt with a minimum work factor of 12.

Authentication

Access to the platform requires authenticated sessions issued via signed JWT tokens with short-lived expiry. Session tokens are rotated on each login and invalidated on logout.

  • Multi-factor authentication available for all accounts
  • Automatic session expiry after 30 minutes of inactivity
  • IP-based anomaly detection on login attempts
  • Rate limiting applied to all authentication endpoints

Infrastructure

ProcureX infrastructure is hosted in certified EU data centres (ISO 27001). Access to production systems is restricted to authorised personnel via VPN with hardware-based MFA. All infrastructure changes are logged and audited.

Vulnerability Disclosure

We operate a responsible disclosure programme. If you discover a security vulnerability, please contact security@procurex.io. We commit to acknowledging reports within 48 hours and resolving critical issues within 7 days.

SecurityComplianceTermsPrivacy