Security
This page describes the technical and organizational measures „BEE FRIEND" Ltd uses to protect customer data, payment information, and the availability of the O2ODDS platform. It is intended as a plain-language overview — for detailed processing terms see our Privacy Policy.
Data in transit
- All connections to O2ODDS use TLS 1.2 or later with modern cipher suites.
- HTTP requests are automatically upgraded to HTTPS.
- Communications between the trading advisors and our license validation endpoint are encrypted end-to-end.
Data at rest
- Customer account passwords are never stored in plain text. We use industry-standard password hashing (bcrypt or equivalent) with per-user salts.
- License keys are stored hashed on the license server.
- Database and file storage sit on managed hosting infrastructure with disk-level encryption.
Payment security
- We do not store your payment card details on our servers. Card data is handled entirely by our payment service provider, which is PCI-DSS compliant.
- Card information is transmitted directly from your browser to the payment processor via a secure hosted checkout or tokenized form. Our servers never see the full card number.
- Refunds and chargebacks are processed through the same provider.
Access controls
- Administrative access to production systems is limited to authorized personnel, using individual credentials with strong password requirements.
- Sensitive administrative actions are logged.
- Support staff have access only to the customer information needed for the specific ticket they are handling.
Infrastructure
- The website runs on managed hosting infrastructure with 24/7 monitoring.
- Software dependencies are kept up to date with security patches.
- Regular backups of customer data are taken and stored in encrypted form.
- The web-application layer is protected against common attack classes (SQL injection, cross-site scripting, cross-site request forgery) through parameterized queries, output escaping, and CSRF tokens.
Your part in security
The strongest protections on our side are only effective when combined with your own good practice:
- Use a unique, strong password for your O2ODDS account.
- Never share your license key with anyone.
- Keep the email address on your account secured with a strong password and two-factor authentication.
- If you use a VPS to run your trading platform, keep the VPS operating system patched and use strong VPS credentials.
- Report any suspicious activity on your account to us immediately.
Incident response
In the event of a security incident that affects your personal information, we will notify affected customers by email as soon as reasonably practicable, and where required by applicable law we will also notify the competent data protection authority. Our incident response process includes containment, investigation, remediation, and post-incident review.
Reporting a security issue
If you believe you have found a security vulnerability in our website, license server, or products, please report it privately to support@o2odds.com with the subject line SECURITY: followed by a short description. Please give us reasonable time to investigate and address the issue before public disclosure. We do not currently operate a paid bug-bounty programme, but we appreciate responsible disclosure and will credit reporters where they wish.
Contact
General security questions: support@o2odds.com.