Acceptable Use & Security Policy
Last Updated: August 2, 2026
1. Purpose and Scope
This Acceptable Use & Security Policy outlines the rules and technical standards for interacting with BE Survey ("Platform," "We," "Us," or "Our"). This policy applies to every user who accesses the platform, including Super Administrators, Company Administrators, Survey Managers, internal company employees, external raters, and survey participants.
The goal of this policy is to keep our system secure, protect database integrity, shield personal data from unauthorized access, and ensure that our platform operates reliably for all corporate tenants without interruption.
2. General User Responsibilities
All users are expected to use BE Survey responsibly, ethically, and strictly for legitimate corporate survey activities. When logged into the system, you must:
- Maintain valid, real profile information tied to your actual identity within your organization.
- Follow all local, national, and international laws regarding data collection, workplace communication, and online conduct.
- Operate strictly within the permissions assigned to your user role and company account.
- Respect system resources and refrain from taking actions that degrade web performance or server responsiveness for other tenant accounts.
3. Account Authentication and Credential Security
Your user credentials serve as the first line of defense for system security. To ensure account protection:
- Credential Protection: Passwords, session tokens, and One-Time Password (OTP) verification codes belong strictly to you. Sharing login credentials with colleagues, assistants, or third parties is prohibited.
- Password Standards: Users must create strong passwords that meet system complexity requirements and avoid reusing passwords across multiple external web applications.
- Session Termination: Users must log out of their session when using shared computers or ending work sessions to prevent unauthorized physical access to dashboard data.
- Compromise Notification: If you suspect that your login credentials have been lost, stolen, or accessed by someone else, you must immediately report the incident to your Company Admin or system support.
4. Strictly Prohibited Actions
To safeguard our database schema, web API controllers, and client data, the following activities are strictly prohibited on BE Survey:
A. Unauthorized Access & Hacking Attempts
- Attempting to bypass authentication checks, brute-force passcodes, or manipulate query parameter strings to view unauthorized pages.
- Attempting to access, query, or modify survey data or company profiles belonging to other tenant organizations.
- Running automated security vulnerability scanners, port scanners, or penetration testing scripts against our domain without explicit written authorization.
- Injecting malicious SQL commands, script tags (XSS), or hidden executable code into survey question fields, input forms, or user profile records.
B. Content and Survey Misuse
- Publishing survey questions or collecting response content that is unlawful, defamatory, abusive, harassing, discriminatory, or sexually explicit.
- Using survey forms to harvest prohibited sensitive personal information (such as credit card numbers, passwords, or personal banking keys) outside agreed corporate survey frameworks.
- Distributing deceptive, phishing, or scam questionnaires intended to mislead respondents or misrepresent your true organization.
C. System Abuse and Network Interference
- Using automated bots, web crawlers, or submission scripts to post fake survey responses or flood system tables with artificial records.
- Launching Denial-of-Service (DoS) or Distributed Denial-of-Service (DDoS) attacks against platform hosting infrastructure.
- Uploading files containing computer viruses, trojan horses, worms, keyloggers, or other harmful scripts designed to disrupt backend services.
5. Data Privacy and Cross-Company Isolation
BE Survey enforces strict multi-tenant isolation. Your administrative access is restricted to your organization's verified Company ID:
- Users must not attempt to guess or manipulate parameter IDs in application URLs to view another organization's reporting views or user mappings.
- Company Admins must ensure that survey participant lists and employee contact details imported into the system are gathered legally and managed responsibly.
- Survey creators must ensure that survey response collection adheres to internal company confidentiality policies and participant disclosure notices.
6. Security Monitoring and Audit Logging
To maintain platform security and fulfill legal audit obligations, BE Survey continuously monitors and logs system interaction metadata:
- System Event Logging: Application controllers log user authentication attempts, password changes, OTP requests, administrative edits, and system errors via integrated logging frameworks (e.g., Serilog).
- Network Tracing: IP addresses, browser agent headers, HTTP request paths, and execution timestamps are recorded for security auditing.
- Incident Investigation: In the event of a suspected security breach, illegal access attempt, or policy violation, system audit logs will be inspected to trace activity and protect platform infrastructure.
7. Enforcement and Consequences of Misuse
BE Survey takes system security and acceptable use seriously. If a user or organization violates this policy, we reserve the right to take swift corrective action, including:
- Issuing formal warnings to account holders or company administrators.
- Temporarily locking or revoking individual user profile access.
- Terminating active survey forms or removing non-compliant content from public views.
- Permanently terminating the account access of repeat or severe offenders.
- Reporting malicious illegal activities, cyber attack attempts, or data breaches to law enforcement agencies and legal authorities.
8. Reporting Security Issues
We encourage responsible disclosure of potential system vulnerabilities or misuse. If you discover a security flaw, broken access control, or potential data exposure on BE Survey, please report it immediately to platform technical support or your designated Company Administrator with detailed step-by-step information so our engineering team can address it promptly.
9. Policy Updates
We may update this Acceptable Use & Security Policy from time to time to address emerging security standards, technical system updates, or legislative changes. Revised versions will be published on this page with an updated "Last Updated" timestamp.