Skip to content
Trust Center

Trust, security & transparency.

How BSCT.Cloud protects the businesses that run on us — security posture, privacy commitments, data protection, platform availability, compliance roadmap and legal policies, published honestly.

All systems operational · 99.98% uptime · trailing 90 days
GDPR · DPA available ISO 27001 · on roadmap AES-256 at rest · TLS 1.2+ Sub-processor list · documented
Governance
Data
Application
Network
Identity
Layered controls, published SLAs, honest posture
updated monthly
Live Status

Every region, green.

A live rollup of the BSCT.Cloud production fabric. A full incident history and per-service breakdown will land with the dedicated Status page.

No incidents · trailing 90 days
multi-region
Global control plane
operational
ap-south-1
Asia-Pacific
operational
eu-west-1
Europe
operational
us-east-1
North America
operational
Reliability rollup
99.98%
Uptime · trailing 90 days
99.95%
Uptime · trailing 12 months
0
Sev-1 incidents · last quarter
< 15 min
Mean time to recovery
Security

Six pillars that protect every tenant.

Security is designed into the platform fabric — not bolted onto it. Every product surface inherits the same controls, isolation and audit posture by default.

Defence in depth

Multiple, independent layers of controls across network, application, data and identity — designed so a single misconfiguration cannot become a breach.

Encryption everywhere

TLS 1.2+ for every request in transit and AES-256 at rest for every persisted store — including databases, object storage and backups.

Tenant isolation

Every tenant lives in a logically isolated schema and object-storage prefix, with row-level security and tenant-scoped keys enforced at the fabric layer.

Access control · RBAC + SSO

Role-based access, single sign-on (SAML / OIDC on Enterprise), least-privilege internal roles and short-lived credentials for all engineering access.

Monitoring & audit

Every privileged action is captured in an append-only audit log. Anomaly detection and paging are wired to production 24×7 for Sev-1 and Sev-2 events.

Incident response

A documented incident response plan with clear severity ladders, on-call rotation, customer-notification SLAs and blameless post-mortems for every incident.

Privacy

Four principles that govern personal data.

We treat personal data as a responsibility, not a resource. These principles apply to every module and every tenant on the platform.

Data minimisation

We collect only what is needed to deliver the service and honour a contract with you — never for onward sale or advertising.

Purpose limitation

Personal data is processed for the purposes documented in our DPA and Privacy Policy — nothing else. Purpose changes require a new lawful basis.

User rights

Data subjects can exercise access, rectification, erasure, restriction, portability and objection rights via a documented workflow — with a 30-day SLA.

Transparent processing

A published sub-processor list, incident-notification commitments and change-log means you always know who processes your data and why.

Data Protection

Every stage of the data lifecycle.

From the moment data enters the platform to the moment it leaves, controls are applied consistently and are visible to the customer.

step 1

Ingestion

Data enters the platform over TLS 1.2+ via authenticated APIs. Payloads are validated and sanitised before being persisted.

TLS 1.2+ · signed requests · schema validation
step 2

Storage

Persisted in tenant-scoped, encrypted stores. Database and object storage encryption keys are managed independently per environment.

AES-256 at rest · tenant-scoped keys · encrypted backups
step 3

Processing

Only the smallest set of services required for a given feature has access. All access is logged and reviewed on a rotating cadence.

Least-privilege IAM · audit log · rotation reviews
step 4

Retention

Retention windows are configurable per data class and per tenant. Defaults are documented; overrides land in the DPA on request.

Configurable per data class · documented defaults
step 5

Deletion

Right-to-erasure requests are honoured on a 30-day SLA. On tenant termination, all customer data is deleted or returned per the MSA.

30-day erasure SLA · MSA termination workflow
Availability

Uptime, recovery and resilience.

Concrete numbers rather than adjectives. Formal service-credit remedies live in the MSA for Enterprise-tier customers.

Uptime target
99.9% monthly
Contractual target on Professional and Enterprise licences. Higher targets available under enterprise agreements.
RPO (data loss window)
≤ 15 minutes
Point-in-time recovery for primary data stores with < 15-minute recovery point objective for the production fabric.
RTO (recovery time)
≤ 60 minutes
Recovery time objective for Sev-1 events under the documented incident-response playbook.
Backups
Daily · 30-day
Encrypted, region-redundant snapshots retained for 30 days by default. Longer retention available on request.
Disaster recovery
Documented DR plan
A tested DR plan with quarterly failover drills. Multi-region active-active is on the 2026 roadmap for Enterprise-tier tenants.
SLA & credits
MSA · Enterprise
Formal SLA with service-credit remedies is provided in the Master Services Agreement for Enterprise-tier tenants.
A note on SLAs. The uptime target and remedies above are indicative of the current production posture. The formal, contractual SLA — including service-credit calculations, exclusions and reporting cadence — is provided in the Master Services Agreement for Professional and Enterprise licences.
Compliance

Compliance posture, stated honestly.

What we have, what is in progress, what is on our roadmap and what does not apply to us. We would rather earn certifications than claim them.

Aligned

GDPR

Data-subject-rights workflow, DPA and standard contractual clauses available for EU customers on Enterprise licences.

On roadmap

ISO / IEC 27001

Gap analysis complete. Formal certification programme on the compliance roadmap.

Not in scope

PCI-DSS

BSCT.Cloud does not store, process or transmit primary account numbers. Card data flows are handled by our PCI-compliant payments provider.

Not in scope

HIPAA

The platform is not currently offered under a BAA and is not intended for the processing of PHI.

Documented

Sub-processor programme

Vetted sub-processor list with contracted DPAs. Material changes are notified in advance under the DPA.

Enterprise procurement pack

Our vendor-security questionnaire response (SIG Lite / CAIQ), pen-test summary letter and DPA are available under NDA to prospects in active procurement.

Request pack
Frequently Asked

Security & trust questions.

The questions we get most often during vendor evaluations, security reviews and enterprise procurement. Anything we haven't answered — write to us at security@bsct.cloud.

BSCT.Cloud is GDPR-aligned and operates under a documented sub-processor programme. ISO/IEC 27001 certification is on the roadmap. Enterprise procurement questionnaires, penetration-test summaries and vendor security packets are available under NDA.

Talk to us

Have security or compliance questions?

Our security team is happy to walk you through the platform posture, share the enterprise procurement pack under NDA, and support your vendor-risk review from evaluation through renewal.

security@bsct.cloud·NDA available·Business-hours response·Enterprise 24×7