Trust, security & transparency.
How BSCT.Cloud protects the businesses that run on us — security posture, privacy commitments, data protection, platform availability, compliance roadmap and legal policies, published honestly.
Every region, green.
A live rollup of the BSCT.Cloud production fabric. A full incident history and per-service breakdown will land with the dedicated Status page.
Six pillars that protect every tenant.
Security is designed into the platform fabric — not bolted onto it. Every product surface inherits the same controls, isolation and audit posture by default.
Defence in depth
Multiple, independent layers of controls across network, application, data and identity — designed so a single misconfiguration cannot become a breach.
Encryption everywhere
TLS 1.2+ for every request in transit and AES-256 at rest for every persisted store — including databases, object storage and backups.
Tenant isolation
Every tenant lives in a logically isolated schema and object-storage prefix, with row-level security and tenant-scoped keys enforced at the fabric layer.
Access control · RBAC + SSO
Role-based access, single sign-on (SAML / OIDC on Enterprise), least-privilege internal roles and short-lived credentials for all engineering access.
Monitoring & audit
Every privileged action is captured in an append-only audit log. Anomaly detection and paging are wired to production 24×7 for Sev-1 and Sev-2 events.
Incident response
A documented incident response plan with clear severity ladders, on-call rotation, customer-notification SLAs and blameless post-mortems for every incident.
Four principles that govern personal data.
We treat personal data as a responsibility, not a resource. These principles apply to every module and every tenant on the platform.
Data minimisation
We collect only what is needed to deliver the service and honour a contract with you — never for onward sale or advertising.
Purpose limitation
Personal data is processed for the purposes documented in our DPA and Privacy Policy — nothing else. Purpose changes require a new lawful basis.
User rights
Data subjects can exercise access, rectification, erasure, restriction, portability and objection rights via a documented workflow — with a 30-day SLA.
Transparent processing
A published sub-processor list, incident-notification commitments and change-log means you always know who processes your data and why.
Every stage of the data lifecycle.
From the moment data enters the platform to the moment it leaves, controls are applied consistently and are visible to the customer.
Ingestion
Data enters the platform over TLS 1.2+ via authenticated APIs. Payloads are validated and sanitised before being persisted.
Storage
Persisted in tenant-scoped, encrypted stores. Database and object storage encryption keys are managed independently per environment.
Processing
Only the smallest set of services required for a given feature has access. All access is logged and reviewed on a rotating cadence.
Retention
Retention windows are configurable per data class and per tenant. Defaults are documented; overrides land in the DPA on request.
Deletion
Right-to-erasure requests are honoured on a 30-day SLA. On tenant termination, all customer data is deleted or returned per the MSA.
Uptime, recovery and resilience.
Concrete numbers rather than adjectives. Formal service-credit remedies live in the MSA for Enterprise-tier customers.
Compliance posture, stated honestly.
What we have, what is in progress, what is on our roadmap and what does not apply to us. We would rather earn certifications than claim them.
GDPR
Data-subject-rights workflow, DPA and standard contractual clauses available for EU customers on Enterprise licences.
ISO / IEC 27001
Gap analysis complete. Formal certification programme on the compliance roadmap.
PCI-DSS
BSCT.Cloud does not store, process or transmit primary account numbers. Card data flows are handled by our PCI-compliant payments provider.
HIPAA
The platform is not currently offered under a BAA and is not intended for the processing of PHI.
Sub-processor programme
Vetted sub-processor list with contracted DPAs. Material changes are notified in advance under the DPA.
Our vendor-security questionnaire response (SIG Lite / CAIQ), pen-test summary letter and DPA are available under NDA to prospects in active procurement.
Policies that govern the platform.
The commercial, privacy and acceptable-use terms under which BSCT.Cloud is offered. The full text of each policy is available on request while these documents finalise their public review.
Terms of Service
The master commercial terms under which the BSCT.Cloud platform is made available to customers and users.
Privacy Policy
How we collect, use and protect personal data — and how data subjects can exercise their rights under GDPR and similar regimes.
Data Processing Addendum
Contractual GDPR/UK-GDPR data-processing terms, including standard contractual clauses for international transfers.
Acceptable Use Policy
The behaviour we expect from operators and end-users on the platform — and the categories of activity that are prohibited.
Cookie Policy
The cookies and similar technologies used across the BSCT.Cloud marketing site and platform, and how to control them.
Sub-processors
The list of vetted sub-processors that support the delivery of the BSCT.Cloud platform, with jurisdictions and purposes.
Security & trust questions.
The questions we get most often during vendor evaluations, security reviews and enterprise procurement. Anything we haven't answered — write to us at security@bsct.cloud.
BSCT.Cloud is GDPR-aligned and operates under a documented sub-processor programme. ISO/IEC 27001 certification is on the roadmap. Enterprise procurement questionnaires, penetration-test summaries and vendor security packets are available under NDA.
Have security or compliance questions?
Our security team is happy to walk you through the platform posture, share the enterprise procurement pack under NDA, and support your vendor-risk review from evaluation through renewal.