Updated20 August 2026

Security overview

This page describes controls that can be supported for the current website and inquiry workflow. It does not claim an independent certification or define controls for every future dataset.

Website transport and browser controls

Production traffic is served over HTTPS. BGraph sends HTTP Strict Transport Security, Content Security Policy, frame restrictions, content-type protection, referrer controls, and a restricted browser permissions policy.

Static assets use explicit caching and compression rules. Administrative access is restricted at the server level rather than exposed through a public website interface.

Inquiry form protection

The prepared data request service accepts same-origin JSON and native form submissions, limits request size, validates required fields and allowed options, and uses a hidden bot field. Responses are marked not to be cached.

The public delivery path is temporarily disabled while mail relay authorization is completed. The current endpoint returns a service-unavailable response and directs buyers to data@bgraph.io. When the service is enabled, repeated submissions will be limited to five per hour for each running process. The connecting IP will be converted into a salted, hourly changing SHA-256 hash for the in-memory counter. The raw IP and inquiry content will not be stored by the form service.

Storage and encryption

The public site is served from production hosting infrastructure that may process technical request and security logs. Provider-specific storage, encryption, retention, and logging details are reviewed during customer diligence and updated here when confirmed for publication.

The current website does not intentionally use advertising cookies or third-party analytics. Confirmed providers that process business correspondence are listed on the service providers page.

Data product boundaries

Synthetic samples are public and contain no production records. Security, access, delivery, retention, deletion, geographic controls, and incident duties for a customer dataset must be specified in the applicable written agreement and product documentation.

BGraph does not represent the current website controls as authorization to process sensitive data, credentials, private conversations, regulated health data, or other information outside an approved scope.

Vulnerability reporting

Send a concise report to hello@bgraph.io with the affected URL, reproduction steps, potential impact, and safe supporting evidence. Do not access other users' information, disrupt the service, or include live personal data.

BGraph does not currently advertise a bug bounty or promise a specific reward. The canonical machine-readable contact is available at /.well-known/security.txt.

Current assurance status

BGraph does not currently claim SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP, or an independent penetration-test attestation. Provider certifications do not automatically become BGraph certifications.

Customers requiring formal assurance should identify the required control framework during scoping so that available evidence, gaps, and contractual requirements can be reviewed before delivery.

Security contact

Security and privacy questions can be sent to hello@bgraph.io. Include the topic in the subject line so the request can be routed correctly.