Security overview
This page describes controls that can be supported for the current website and inquiry workflow. It does not claim an independent certification or define controls for every future dataset.
Website transport and browser controls
Production traffic is served over HTTPS. BGraph sends HTTP Strict Transport Security, Content Security Policy, frame restrictions, content-type protection, referrer controls, and a restricted browser permissions policy.
Static assets use explicit caching rules. Administrative access is controlled through the hosted platform account rather than a public website interface.
Inquiry form protection
The data request endpoint accepts same-origin JSON requests, limits request size, validates required fields and allowed options, and uses a hidden bot field. Responses containing inquiry information are marked not to be cached.
Repeated submissions are limited to five per hour when the hosting network provides a connecting IP. The application converts that IP into a salted, hourly changing SHA-256 hash. The raw IP is not stored in the application rate-limit record, and expired records are removed during later form activity.
Storage and encryption
Provider-specific storage, encryption, retention, and logging claims are published only after the production deployment is confirmed. BGraph does not treat a temporary development or preview platform as permanent product infrastructure.
The current website does not intentionally use advertising cookies or third-party analytics. Confirmed providers that process business correspondence are listed on the service providers page.
Data product boundaries
Synthetic samples are public and contain no production records. Security, access, delivery, retention, deletion, geographic controls, and incident duties for a customer dataset must be specified in the applicable written agreement and product documentation.
BGraph does not represent the current website controls as authorization to process sensitive data, credentials, private conversations, regulated health data, or other information outside an approved scope.
Vulnerability reporting
Send a concise report to hello@bgraph.io with the affected URL, reproduction steps, potential impact, and safe supporting evidence. Do not access other users' information, disrupt the service, or include live personal data.
BGraph does not currently advertise a bug bounty or promise a specific reward. The canonical machine-readable contact is available at /.well-known/security.txt.
Current assurance status
BGraph does not currently claim SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP, or an independent penetration-test attestation. Provider certifications do not automatically become BGraph certifications.
Customers requiring formal assurance should identify the required control framework during scoping so that available evidence, gaps, and contractual requirements can be reviewed before delivery.
Security contact
Security and privacy questions can be sent to hello@bgraph.io. Include the topic in the subject line so the request can be routed correctly.