Trust centre

Incident response policy

This policy describes the operating process used for suspected security, privacy, availability, payment, and document-processing incidents.

Last updated: 20 July 2026

1. Detect and triage

Monitoring, support reports, audit logs, queue health, and provider alerts are reviewed. The incident is assigned a severity based on service impact, data sensitivity, scope, and recoverability.

2. Contain

Affected credentials, jobs, routes, integrations, or deployments may be disabled or isolated. Temporary processing is stopped when continuing could increase impact.

3. Investigate and recover

TenderPDF preserves relevant technical evidence, identifies the cause, removes the fault, restores service carefully, and verifies the recovery before closing the incident.

4. Communicate

Material service incidents are reflected on the status page. Affected users and regulators are notified when required by applicable law and when reliable scope information is available.

5. Learn

A post-incident review records the timeline, cause, impact, corrective actions, owner, and due date. Relevant benchmark tests, monitoring, or procedures are updated to prevent recurrence.

Report an incident

Email support@tenderpdf.co.za with Security Incident in the subject. Include the affected URL, time, observed behavior, and safe reproduction steps. Do not send passwords, payment-card details, or confidential customer files by ordinary email.

Independent assurance status

TenderPDF has not yet published an independent penetration-test report or security certification. A scoped third-party assessment is planned; no certification or test result will be claimed before written evidence exists.