Security - BMaiKR
Skip to content

Security

Home»Security

Security controls, labeled honestly

Every control below is marked as implemented, planned, deployment dependent, or a customer responsibility — not a blanket claim of being "fully secure." Deployment-dependent controls apply according to the specific service and infrastructure configuration in use.

Infrastructure security

  • Supported operating systems

    Implemented

    Hosted workloads run on maintained, supported operating system versions.

  • Security patching

    Implemented

    Operating system and platform patches are applied on an ongoing basis.

  • Firewalling

    Implemented

    Network-level firewalling restricts inbound access to hosted services.

  • Network restrictions

    Implemented

    Administrative and database access is restricted at the network layer.

  • TLS

    Implemented

    Traffic to BMaiKR-operated applications is encrypted in transit via TLS.

  • Database access controls

    Implemented

    Database access is limited to the application and authorized administrators.

Application security

  • Authentication

    Implemented

    Application access requires authenticated credentials.

  • Authorization

    Implemented

    Actions and data access are gated by the authenticated user’s permissions.

  • Role-based access control (RBAC)

    Deployment dependent

    Where an application supports multiple roles, permissions follow a role-based model.

  • Least privilege

    Implemented

    Accounts and services are scoped to the access they need to function.

  • Input validation

    Implemented

    User-supplied input is validated before processing.

  • API security

    Implemented

    APIs require authenticated, authorized requests.

  • Secrets management

    Implemented

    Credentials and API keys are kept out of source code and application code repositories.

Operational security

  • Access reviews

    Planned

    Access to production systems is reviewed periodically.

  • Monitoring

    Implemented

    Hosted services are monitored for availability and errors.

  • Logging

    Implemented

    Application and infrastructure events are logged for operational and security review.

  • Vulnerability management

    Implemented

    Known vulnerabilities in dependencies and infrastructure are tracked and addressed.

  • Dependency updates

    Implemented

    Application dependencies are kept up to date as part of ongoing maintenance.

  • Incident response

    Implemented

    A documented process governs how security incidents are handled — see the Incident Response page.

Data security

  • Encryption in transit

    Implemented

    Data moving between the customer, the application, and BMaiKR infrastructure is encrypted via TLS.

  • Encryption at rest

    Deployment dependent

    Applied where the underlying storage and hosting platform supports it.

  • Backup protection

    Implemented

    Backups are access-restricted in the same way as production data.

  • Retention

    Customer responsibility

    Retention periods follow the applicable service configuration — see Customer Data Lifecycle.

  • Deletion

    Implemented

    Deletion follows the service’s configured procedure after the recovery window closes.

AI security

The bmaikr.com marketing website has no AI/LLM integration of its own. These controls describe how AI steps are architected in applicable client-delivered automation projects — see AI Data Handling for the full picture.
  • Data minimization

    Deployment dependent

    Client-delivered AI workflows are designed to supply only the context a specific task requires.

  • Controlled model access

    Deployment dependent

    AI models are not given open, unrestricted access to a customer’s full database.

  • Provider selection

    Customer responsibility

    The AI provider used for a workload is a configuration decision, documented per project.

  • Prompt/context handling

    Deployment dependent

    Context passed to a model is scoped and constructed by the application layer, not passed raw.

  • Controlled retrieval

    Deployment dependent

    Retrieval-augmented workflows are designed to query only the knowledge base relevant to the task.

Customer isolation

The controls below describe what BMaiKR can implement for applicable client-delivered platforms, according to the agreed architecture — not the bmaikr.com marketing site itself, which has no multi-tenant application.
  • Tenant-scoped authorization

    Deployment dependent

    For applicable client-delivered platforms, access can be scoped to a specific customer’s data according to the agreed architecture.

  • Isolated data access

    Deployment dependent

    Customer data and workflows can be kept separate at the application and storage layer where a platform’s architecture calls for it.

  • Scoped credentials

    Deployment dependent

    Integration credentials can be scoped to the customer and service they belong to.

  • Storage separation

    Deployment dependent

    Applied according to the deployment model agreed for a given platform.

  • Auditability

    Deployment dependent

    Depends on the logging configuration deployed for a given platform.