1. Detect and triage
Monitoring, support reports, audit logs, queue health, and provider alerts are reviewed. The incident is assigned a severity based on service impact, data sensitivity, scope, and recoverability.
Trust centre
This policy describes the operating process used for suspected security, privacy, availability, payment, and document-processing incidents.
Last updated: 20 July 2026
Monitoring, support reports, audit logs, queue health, and provider alerts are reviewed. The incident is assigned a severity based on service impact, data sensitivity, scope, and recoverability.
Affected credentials, jobs, routes, integrations, or deployments may be disabled or isolated. Temporary processing is stopped when continuing could increase impact.
TenderPDF preserves relevant technical evidence, identifies the cause, removes the fault, restores service carefully, and verifies the recovery before closing the incident.
Material service incidents are reflected on the status page. Affected users and regulators are notified when required by applicable law and when reliable scope information is available.
A post-incident review records the timeline, cause, impact, corrective actions, owner, and due date. Relevant benchmark tests, monitoring, or procedures are updated to prevent recurrence.
Email support@tenderpdf.co.za with Security Incident in the subject. Include the affected URL, time, observed behavior, and safe reproduction steps. Do not send passwords, payment-card details, or confidential customer files by ordinary email.
TenderPDF has not yet published an independent penetration-test report or security certification. A scoped third-party assessment is planned; no certification or test result will be claimed before written evidence exists.