Security & Trust
Security claims should be inspectable. This page describes current application controls and clearly separates implemented safeguards from certifications BlueTier does not claim.
Effective and last updated: 2026-08-06Data minimization
- The onboarding form does not collect LinkedIn, Gmail, or other account passwords.
- Legacy credential columns remain blank.
- Client APIs filter password, credential, recovery, secret, and token fields.
- Request bodies are size limited and validated before processing.
Authentication and sessions
- Dashboard sessions use signed, expiring tokens.
- The browser receives the session in an HttpOnly, SameSite=Strict cookie.
- Secure cookies are used in HTTPS environments.
- Login attempts and public form submissions are rate limited.
- Authenticated APIs return no-store caching directives.
Application and browser controls
- Content Security Policy and other security headers restrict browser capabilities.
- Cross-origin access is not broadly enabled.
- Executable chart code is self-hosted instead of loaded from a public CDN.
- User-supplied content is validated and escaped before email or HTML rendering.
- Google API access uses the spreadsheet scope required by the application.
Encryption
Data is encrypted in transit using TLS across the public website, dashboard, and connected provider APIs. At-rest encryption applies to the platform’s Postgres data store through managed database encryption as the migration from spreadsheet storage completes.
Audit logging
Internal operator access to customer records is logged with the actor, timestamp, and action taken, and these logs are being extended as the platform matures. Audit logging supports access review, troubleshooting, and dispute resolution.
Breach notification
If we confirm a security breach affecting your personal data, we will notify affected customers without undue delay and, where legally required, no later than 72 hours after confirming the breach. Notifications describe what happened, the data involved, and the steps being taken.
Access and service providers
Access should be limited to authorized operators with a business need. Current subprocessors are Vercel (hosting), Google Sheets (operational records mirror), Neon (Postgres database), Brevo (transactional email), and Unipile (LinkedIn account connectivity and automation vendor). The current list, roles, and data categories are published on the subprocessors page. Provider access and credentials are managed outside the public repository.
What BlueTier does not claim
BlueTier does not claim SOC 2, ISO 27001, PCI DSS, HIPAA certification, or another assurance status unless a current, verifiable statement is published here. No website can promise absolute security.
Responsible disclosure
If you believe you found a vulnerability, email IT@bbmgroup.io with “Security report” in the subject. Include the affected URL, reproducible steps, expected impact, and a safe way to contact you. Do not access other users’ data, degrade the service, use social engineering, or publish sensitive details before BlueTier has had a reasonable opportunity to investigate. We will not pursue legal action against good-faith security research conducted under this policy.
Client responsibilities
Clients remain responsible for accurate authorization, internal approvals, their own devices and accounts, and compliance with third-party platform terms. Never send a password or verification code through the public contact or onboarding forms.
Questions or correction requests?
Use the contact form or email IT@bbmgroup.io. Never include an account password or verification code.
Contact BlueTier →