1. Scope and contract priority
A signed MSA, SOW, BAA, or DPA controls where it conflicts with this summary. The Data Processing Agreement governs Client Data processed on your instructions; the Privacy Policy describes Website Data and account data.
This summary describes controls for Bitscaled-operated portals and services. Customer-owned systems and vendor infrastructure follow their own configuration and contracted controls. Service-specific requirements belong in the MSA, SOW, or DPA.
2. Tenant and authorization boundaries
Client Workspace uses authenticated company membership, role-based permissions, and tenant-scoped application queries. Server-side membership checks establish the company context; a company identifier supplied by a caller does not itself grant access.
Admin, Intranet, and Workspace have distinct authorization scopes. Intranet CRM supports Bitscaled internal operations; it is not a separate customer-isolated CRM instance for each Workspace company.
3. Database row-level security
Selected database tables define PostgreSQL row-level security (RLS) policies. RLS coverage is not universal: core identity and CRM access rely on application authorization and tenant filters. Table-owner connections can bypass ordinary RLS, and privileged service-role policies allow broader server access.
Tenant isolation therefore depends on the complete request path: authentication, company membership, permissions, and query scope. An RLS policy in a database schema is not a guarantee that every application connection is constrained by that policy.
4. Encryption and session protection
- Public websites and portals use TLS at the Vercel edge. Remote access that Bitscaled controls over public networks uses TLS.
- Portal session cookies carry an opaque session identifier and use HTTP-only protection, SameSite restrictions, and the Secure flag in production.
- Stored Workspace AI provider credentials use AES-256-GCM application encryption with keys supplied through server configuration.
- Infrastructure encryption at rest follows the contracted hosting and database services. Credential encryption does not establish a separate cryptographic key for every tenant or imply customer-managed keys for all records.
5. Audit records and operational monitoring
Bitscaled records relevant authentication, access, legal-signature, and workflow events for service operation and investigation. Record contents and retention depend on the feature and applicable agreement. This summary does not promise an immutable record of every action or a single retention period across all services.
Monitoring providers are listed in the subprocessor directory. Public-site Datadog browser monitoring and optional session replay require analytics consent. AI prompt and workflow retention is described in AI Data Governance.
6. Assurance and customer evidence
Bitscaled does not claim SOC 2, ISO 27001, PCI DSS, CMMC, or HIPAA certification. Vendor certifications and reports apply only to their stated services, scope, and period; they do not certify Bitscaled or every customer deployment.
Customer-specific evidence belongs in authenticated Workspace or an agreed confidential review. Contact legal@bitscaled.tech for procurement review, or security@bitscaled.tech to report a security issue. The Security Trust Center provides the wider operational overview.