Security Trust Center — Profit Bid
Profit Bid (operated by S.C. AXP GLOBAL RETAIL S.R.L., Romania) takes security and privacy seriously. This Trust Center describes how we protect customer and store data. It is an informational overview — not a certification claim.
1. Security overview
We design Profit Bid around least privilege, defense in depth, and fail-closed defaults where they do not break storefront tracking or store connect flows.
- Authenticated app APIs require a valid session; recovery and MFA step-up are enforced where configured.
- Organization role checks (owner/admin) gate store connect, billing, and ad-platform mutations.
- Signed OAuth state binds connect flows to the starting user and organization.
- Outbound fetches to merchant store URLs are gated against private/link-local SSRF targets.
- Webhook and click-capture paths use HMAC or signed tokens where platforms support them.
2. Encryption
- In transit: public endpoints are served over HTTPS/TLS.
- At rest: store and ad-platform credentials are encrypted application-side (AES-GCM) before storage when
CREDENTIALS_ENCRYPTION_KEYis configured. - Payment card data is never stored by Profit Bid; card processing is handled by Stripe (or Shopify App Store billing where applicable).
3. Multi-factor authentication (MFA)
- Customers can enable TOTP MFA from Settings → Security.
- Staff admin surfaces require MFA enrollment and verification.
- Organization owners/admins may be required to use MFA for sensitive mutations when operators enable
REQUIRE_ORG_ADMIN_MFA(off by default).
4. Hosting & EU operations
Profit Bid is operated by a Romanian company under EU GDPR. Application hosting runs on Vercel; primary application data is stored in Supabase (PostgreSQL). Some sub-processors may process data outside the EEA with appropriate transfer safeguards (for example Standard Contractual Clauses). See our Data Processing Agreement and Privacy Policy for details.
5. Sub-processors
We use specialized providers to deliver the Service. Categories and typical providers include:
- Application hosting & edge — Vercel
- Database, auth, storage — Supabase
- Email delivery — Resend
- Payments & billing — Stripe (and Shopify billing for App Store subscriptions)
- Ad platforms you choose to connect (Google Ads, Meta, TikTok, and others) — as processors under your instructions
Material changes to sub-processors are handled as described in the DPA. This list is informational and may evolve with the Service.
6. What we do not claim
We do not display unverified certification badges (for example SOC 2 or ISO 27001) on this page. When independent certifications are completed, we will update this Trust Center with accurate scope and dates.
7. Vulnerability disclosure
Report security issues to office@profit-bid.com. See also security.txt for contact and preferred languages.
Please include enough detail to reproduce the issue. Do not access customer data beyond what is necessary to demonstrate a vulnerability.
Contact
S.C. AXP GLOBAL RETAIL S.R.L.
Email: office@profit-bid.com








