1. Compliance position
iBugFix aims to support customers operating under privacy and security obligations, including frameworks such as POPIA and GDPR where applicable. A standard repair or development engagement does not constitute legal advice, regulatory certification or a guarantee that the customer is compliant.
2. Data minimisation
Only information reasonably required to diagnose, quote or deliver the service should be shared. Customers should remove unrelated personal data from logs, exports and screenshots before submission where practical.
3. Access management
- Temporary, named and least-privilege accounts are preferred.
- Production access is requested only where the scope requires it.
- Credentials should be exchanged through an agreed secure channel, not the public form.
- Customers should revoke or rotate credentials after completion.
4. Secure development practices
- Validate and constrain external input.
- Use appropriate output escaping and request-forgery protections.
- Avoid exposing secrets in source code or public directories.
- Preserve rollback and recovery options before material changes.
- Review authentication, authorisation and data access when they are affected by scope.
- Document known limitations and unresolved risks.
5. Backups and change control
Risk-sensitive changes should have an identified recovery path. Where appropriate, work is staged, versioned or performed after a verified backup. The available controls depend on the customer environment and must be agreed before implementation.
6. Incident handling
When an engagement involves suspected compromise, the immediate priorities are containment, preservation of relevant evidence, safe restoration and reduction of repeat exposure. Formal forensic investigation, breach notification and legal reporting are separate services unless included in writing.
7. Subprocessors and infrastructure
Hosting, SMTP, Cloudflare Turnstile, backup and other providers may process limited service data. Provider selection, region and contractual safeguards should be reviewed where the customer has regulated or sensitive data.
8. Customer responsibilities
Compliance remains a shared responsibility. Customers control the lawful basis for their data, user notices, internal access, retention, licences, hosting choices and operational policies. iBugFix can implement agreed technical controls but cannot replace organisational governance.
9. Data-processing agreements
Where iBugFix will process personal information on behalf of a customer beyond incidental technical access, the parties may agree a separate data-processing or operator agreement defining instructions, safeguards, retention and incident communication.
10. No unsupported claims
The website should not be read as claiming ISO certification, PCI certification, HIPAA certification or another formal accreditation unless a current, verifiable certification is expressly published. Scope-specific security work and compliance support must be described accurately in the quotation.
11. Security contact
Report a security concern involving iBugFix services to hello@ibugfix.com with a concise description and safe contact details. Do not include exploit payloads, credentials or sensitive customer data in the initial email.