BigVIRALS support@bigvirals.com
Security Document

Information Security Policy

This policy summarizes the administrative, technical, and organizational safeguards used to protect BIGVIRALS systems, user data, creator outreach records, business information, and service operations.

1. Scope

This Information Security Policy applies to BIGVIRALS websites, applications, APIs, creator outreach workflows, analytics services, AI report generation, seller support tools, internal systems, and related operational processes.

2. Security Governance

BIGVIRALS is operated by 江西深蓝智科文化有限公司. Security responsibilities are assigned to authorized personnel who manage access, monitor operational risks, review incidents, and coordinate remediation activities.

3. Access Control

Access to production systems, customer data, platform integrations, and administrative tools is limited to authorized personnel with a business need. We apply role-based permissions, password protection, limited privileges, and periodic access review where appropriate.

4. Data Protection

We use reasonable safeguards to protect personal data, business contact information, creator outreach records, campaign notes, analytics records, uploaded media, and operational logs against unauthorized access, misuse, alteration, loss, or disclosure.

5. Transmission and Storage

Where applicable, data is transmitted over encrypted connections. Storage systems and cloud services are configured with access restrictions, credential controls, and operational monitoring. Sensitive credentials are separated from public code and should not be exposed in logs or client-side applications.

6. System Monitoring and Logging

We maintain technical logs and operational records to support security monitoring, troubleshooting, abuse prevention, fraud detection, and incident investigation. Access to logs is restricted according to operational need.

7. Vendor and Third-Party Services

BIGVIRALS may use third-party providers for hosting, cloud storage, AI processing, analytics, communication, customer support, security, payment, and platform integrations. Service providers are expected to protect data and use it only for authorized business purposes.

8. Incident Response

If a suspected or confirmed security incident occurs, we will investigate, contain, remediate, and document the issue. Where required by law, contract, or platform policy, we will notify affected parties, merchants, platform partners, or regulators.

9. Business Continuity

We maintain operational practices intended to reduce service disruption, including backup, monitoring, deployment controls, and recovery procedures appropriate to the service context.

10. Employee and Operator Responsibilities

Authorized personnel must protect credentials, follow access control requirements, avoid unauthorized data disclosure, and report suspected security issues promptly.

11. Policy Review

This policy may be updated from time to time to reflect changes in service architecture, legal requirements, platform requirements, or security practices.

12. Contact

Security questions or reports may be sent to support@bigvirals.com.