Security at Bon Gou Peyi
Last updated 14 August 2026
We keep our website and the information you share with us simple and well-protected. This page explains how, and how to reach us if you ever spot a problem.
How your information is protected
- Encrypted in transit. The entire site is served over HTTPS with HSTS, so data moving between your browser and us is encrypted.
- Minimal data. We only collect what you type into our inquiry form — your name, contact details, and event notes. Nothing more.
- No payments on this site. We don't take card numbers or payments here; inquiries lead to a direct conversation.
- Reputable infrastructure. The site runs on SOC 2 Type II cloud infrastructure, and inquiry emails are delivered through a SOC 2 Type II email provider.
- Hardened by default. Standard security response headers (content-type, framing, referrer, and permissions policies) are applied across the site.
Reporting a vulnerability
We welcome responsible disclosure. If you believe you've found a security issue, please email security@synthbridge.net. Give us a reasonable window to investigate and fix before any public disclosure, and we'll keep you updated.
Our machine-readable policy lives at /.well-known/security.txt (aligned with RFC 9116). Researchers we thank are listed on our acknowledgements page.
Threat model, in plain terms
This is a marketing site with a single inquiry form. The main things we guard against are interception of form data (handled by encryption) and misuse of submitted details (handled by minimal collection and access controls). Because we store no payment data and no accounts, the sensitive-data surface is intentionally small.
← Back to site