Skip to main content

Bitscaled LLC · Tampa, Florida

Security and Trust Center

Bitscaled is a Tampa Bay managed service provider for healthcare, legal, and defense-adjacent SMBs. This page is our public Trust Center — how we run our own platform, how we protect customer environments, and where to report a vulnerability. It is not a service catalog, not a legal policy, and not a live “all systems secure” badge. Named owners run security operations. We do not sell SOC theater we cannot evidence.

Last reviewed August 18, 2026

This is not a service SKU

Keep these surfaces distinct. Prospects looking for “Security” here want trust, not a catalog item.

Security services

Delivery SKUs — what we implement for clients (cybersecurity, consulting, hardening programs).

View security services

Workspace Trust & Governance

Client Workspace product module for authenticated customers. Evidence stays in the portal, not on this public page.

Workspace governance

Legal instruments

Contracts and policies: Privacy, Terms, AUP, Cookies, and the DPA.

Legal hub

How we protect Bitscaled

Controls for our company and this platform — not a dump of infrastructure identifiers.

Identity and staff access

Bitscaled portals use cookie-based sessions (HTTP-only, SameSite=strict, Secure in production) plus JWT for API calls. Staff sign in with our custom auth stack. Google Workspace SSO is available for Bitscaled Intranet and Admin when enabled — it is not a customer-facing enterprise SSO product. Multi-factor authentication is required on Bitscaled accounts used to deliver services.

Encryption in transit

Public site and portals terminate TLS at the Vercel edge. Remote access we control over public networks uses TLS. Session cookies are encrypted. We do not publish key-management internals here.

Role-based portals

Admin, Intranet, and Client Workspace are separate portals with RBAC. Client Workspace is organization-scoped. Intranet CRM is Bitscaled’s internal tenant, not a public multi-tenant CRM.

Monitoring and status

We monitor the public website, Client Workspace, VaultTools, and related platform health. Live component status is published on the system status page — this Trust Center does not invent an “all systems secure” banner.

System status

Vulnerability intake

Report product or platform issues to security@bitscaled.tech. We do not run a paid bug bounty. Discord and GitHub alert pipelines are internal operations, not a public intake channel.

Vulnerability disclosure policy

Backup and recovery

We maintain backups and a recovery process for Bitscaled-operated systems. Customer immutable-backup evidence, when contracted, is shown to authenticated Workspace users. We do not publish bucket names, account IDs, or infrastructure identifiers on this site.

How we protect customers

Managed services positioning plus Client Workspace evidence for authenticated tenants.

Managed detection and response

We operate security monitoring and response as part of managed services — with named engineers, not an anonymous 24/7 theater. Scope is defined in the MSA and SOW.

Cybersecurity services

Email security

DMARC, BIMI, and spoof-lab testing (VaultSandbox) so clients can see whether attackers can impersonate their domain. Start with the free tools or a scoped engagement.

Email spoof test

Microsoft 365 hardening

Tenant baseline reviews and ongoing administration when contracted. The public M365 snapshot tool is a starting point, not a substitute for tenant-scoped work.

M365 snapshot

CMMC and HIPAA programs

We run HIPAA-ready operations and CMMC-oriented programs for clients who need them. That is delivery work under contract — not a claim that Bitscaled is CMMC certified or “HIPAA certified.”

Security consulting

Workspace Trust & Governance

Authenticated clients can review Trust & Governance in Client Workspace. Customer Workspace evidence is available to authenticated clients — we do not dump attestation JSON, vault names, or account identifiers on the public site.

Governance module

Immutable backup evidence

When immutable backup is in scope, evidence is presented inside the client portal. Sign in to Workspace to view your company’s controls. Public pages never render raw attestation payloads.

Workspace sign in

Compliance posture

Honest language for healthcare, legal, and defense-adjacent SMBs. No certificates we do not hold.

What we do not claim

Bitscaled does not claim SOC 2, ISO 27001, PCI DSS, CMMC, or independent pentest certification on this page. If we complete an audit later, this module will be updated by a human reviewer — not by an unattended AI generator.

HIPAA-ready operations and BAAs

We operate HIPAA-ready processes for contracted healthcare work and execute Business Associate Agreements when PHI is in scope. Individual customer BAA status is not published here.

Data Processing Agreement

Processor terms, technical measures (TLS, encrypted session cookies, least privilege, MFA on Bitscaled accounts), and subprocessor references live in the DPA.

Read the DPA

Privacy

What we collect on the public site, in Workspace, and in VaultTools is described in the Privacy Policy. This Trust Center does not replace that policy.

Privacy Policy

Responsible disclosure

Responsible disclosure

Email security@bitscaled.tech with enough detail to reproduce the issue. Do not exfiltrate customer data to prove a finding. We do not offer a bug bounty. Coordinated disclosure terms are on the vulnerability disclosure page.

Disclosure policy

Subprocessors and data map

High-level names already published in legal docs. The full inventory lives on the subprocessors page.

Vercel

Website and application hosting, edge TLS, and related platform delivery.

Email provider

Transactional and marketing email (Twilio SendGrid; Resend when configured). See the subprocessor list for the current inventory.

VaultTools host

Public security assessment APIs at vaulttools.bitscaled.tech (Namecheap VPS). VaultSandbox email-lab testing is a separate hostname when deployed.

Full inventory

The canonical public list — including optional analytics, databases, and AI providers — is on the subprocessors page. We do not list secret or internal hostnames here.

Subprocessors

Status and incidents

Status and incident communications

Component health for the public website, Client Workspace, VaultTools, and related surfaces is on the system status page. Subscribe there, or contact us if you need incident updates for a contracted service.

System status

Questions we hear from prospects

Is Bitscaled SOC 2 or ISO 27001 certified?
No. We do not claim SOC 2, ISO 27001, PCI DSS, or CMMC certification. We describe the controls we actually operate and will update this page if that changes after a human review.
Where do I report a security issue?
Email security@bitscaled.tech. There is no paid bug bounty. See the vulnerability disclosure policy for scope and expectations.
How is this different from Security services?
This Trust Center explains how Bitscaled protects itself and its clients. /services/security is the catalog of work we sell. Client evidence lives in authenticated Workspace, not here.
Can I see backup or vault evidence without logging in?
No. Customer Workspace evidence is available to authenticated clients. Public pages never include vault identifiers or attestation payloads.