Security claims you can inspect
This page distinguishes implemented controls from certifications and assurances that BizDash has not yet earned or published.
Tenant Isolation
Organization-scoped records are protected by database row policies, with cross-tenant access tests included in the production verification program.
Role Checks
Application and data access paths carry organization membership and role checks. Custom-role coverage is represented only where the route enforces it.
Audit History
Governed changes and consequential actions are designed to leave an organization-scoped audit record that can be inspected during verification.
Governed Credentials
Provider credentials are resolved inside an authenticated tenant boundary and are not exposed to public pages or committed to source control.
Fail-Closed Integrations
A missing provider, permission, or configuration is shown as unavailable. BizDash does not replace a failed external action with a fake success.
Release Evidence
Production changes are tied to reviewed source, deployment identifiers, migration checks, and live workflow evidence before a completion claim is made.
Assurance status
SOC 2 Type II
Not currently claimed
HIPAA
Not currently offered
Formal uptime SLA
Not currently published
Independent penetration test
No current report published
Report a Vulnerability
We take security issues seriously and appreciate responsible disclosure. Use the contact page to report a suspected vulnerability; receipt and remediation times are not represented as an SLA.
Contact BizDashPlease do not publicly disclose vulnerabilities before we have had a chance to address them.