Security Policy
Last updated: July 7, 2026
1. Overview
At 86Connect, the security of your data is a top priority. This Security Policy outlines the technical and organizational measures we implement to protect personal and business information across our Study in China and Product Sourcing services, our website (the86connects.com), and supporting systems.
This policy should be read alongside our Privacy Policy and Data Processing Agreement.
2. Scope
This policy applies to all systems, applications, networks, and personnel involved in storing, processing, or transmitting data on behalf of 86Connect and our clients, including:
- Our public website and client-facing applications
- Admin and internal management systems
- Databases storing inquiry, account, and service records
- Communication channels (email, messaging, support tools)
3. Security Governance
86Connect maintains a security governance framework that defines roles, responsibilities, and accountability for information security. Security ownership is assigned to designated personnel responsible for:
- Maintaining and reviewing security controls
- Coordinating incident response
- Managing vendor and third-party risk
- Ensuring compliance with applicable laws and standards
4. Data Encryption
We protect data using industry-standard encryption:
- In transit: All data transmitted between users and our systems is encrypted using TLS (HTTPS).
- At rest: Sensitive data stored in databases and backups is encrypted.
- Passwords: User passwords are stored using strong, salted hashing algorithms.
5. Access Control
Access to systems and data is governed by the principle of least privilege:
- Role-based access controls limit data access to authorized personnel only
- Multi-factor authentication is required for administrative systems
- Access rights are reviewed regularly and revoked upon role change or departure
- Audit logs record access to sensitive systems and data
6. Infrastructure and Network Security
Our infrastructure is hosted with reputable cloud providers that maintain robust physical and network security. Measures include:
- Firewalls and network segmentation
- DDoS protection and rate limiting
- Regular patching and update management
- Secure configuration baselines for all servers and services
- Automated, encrypted database backups with tested restore procedures
7. Application Security
We build and maintain our applications with security in mind:
- Input validation and output encoding to prevent injection attacks
- Protection against cross-site scripting (XSS) and CSRF
- Secure session management and token handling
- Regular dependency scanning for known vulnerabilities
- Security review of code changes before deployment
8. Incident Response
We maintain an incident response plan to detect, contain, and remediate security incidents. In the event of a data breach affecting your information, we will:
- Investigate and contain the incident promptly
- Notify affected parties without undue delay
- Take corrective action to prevent recurrence
- Cooperate with regulators and law enforcement as required
9. Business Continuity and Disaster Recovery
To ensure resilience and availability, we maintain:
- Regular, encrypted backups of critical data
- Documented disaster recovery procedures
- Redundancy for key services to minimize downtime
- Periodic testing of backup restoration and recovery plans
10. Personnel Security
Our team is an essential part of our security posture:
- Employees and contractors sign confidentiality agreements
- Security and data protection training is provided
- Access is revoked promptly upon termination or role change
- Background checks are conducted where appropriate
11. Third-Party and Vendor Security
We assess the security practices of third-party service providers before engaging them and require them to maintain appropriate safeguards. Vendors handling personal data are bound by data processing terms consistent with our Data Processing Agreement.
12. Vulnerability Management
We actively monitor and address security vulnerabilities:
- Regular vulnerability scanning of infrastructure and applications
- Prompt patching of identified vulnerabilities, prioritized by severity
- Periodic security assessments and penetration testing
- Responsible disclosure handling for reported issues
13. Compliance and Audits
We align our practices with applicable laws and frameworks, including the GDPR, CCPA, and China’s PIPL. Internal reviews and external assessments are conducted periodically to verify the effectiveness of our security controls.
14. Reporting a Security Issue
If you believe you have discovered a security vulnerability in our systems, please report it responsibly to beijingbridgepath@gmail.com. We ask that you avoid exploiting the issue and provide sufficient detail for us to investigate and remediate.
15. Changes to This Security Policy
We may update this Security Policy as our systems and practices evolve. Material changes will be posted on this page with an updated “Last updated” date.
16. Contact Us
For security-related questions or concerns, please contact us:
- Email: beijingbridgepath@gmail.com
- Phone: +86 176 1153 3296