SOC 2 Type II
Attestation not published
Bitscaled does not claim a SOC 2 attestation. Request a review of the controls and evidence available for your procurement process.
Bitscaled LLC · Tampa, Florida · Trust Center
Review the boundaries that protect your data. Understand our controls, inspect our infrastructure, and bring the right evidence to your next security review.
Readiness is specific to the work in scope. These disclosures distinguish our programs from independent certification.
Attestation not published
Bitscaled does not claim a SOC 2 attestation. Request a review of the controls and evidence available for your procurement process.
Contract-scoped readiness
HIPAA-ready processes and Business Associate Agreements for contracted healthcare work involving PHI. This is not a HIPAA certification.
Mapping requires review
Discuss Govern, Identify, Protect, Detect, Respond, and Recover outcomes in a scoped review. No independently assessed framework score is published here.
Certification not claimed
CMMC-oriented client programs are scoped by contract. Level 2 assessment status and applicable evidence must be confirmed for each engagement.
We monitor platform health. Live framework attestations and automated daily policy results are not published here. The review date above describes policy copy, not a passing compliance check. Check operational status.
Follow a request through the platform, review access and session controls, and inspect the providers involved.
Architecture inspection
Follow the data boundary, inspect the controls, and review the providers. Use arrow keys to move between tabs, then Enter or Space to select.
Requests move from the hosting edge through application authorization to scoped data and purpose-specific storage. Select a stage to inspect its control and review scope.
Boundary 01
Public requests use HTTPS with TLS termination at the hosting edge before reaching the application. WAF coverage and active rules depend on the deployment configuration.
Identity, transport, recovery, and operational controls for the company and platform.
Bitscaled portals use cookie-based sessions (HTTP-only, SameSite=strict, Secure in production) plus JWT for API calls. Staff sign in with our custom auth stack. Google Workspace SSO is available for Bitscaled Intranet and Admin when enabled — it is not a customer-facing enterprise SSO product. Multi-factor authentication is required on Bitscaled accounts used to deliver services.
Public site and portals terminate TLS at the Vercel edge. Remote access we control over public networks uses TLS. Session cookies carry opaque identifiers; session data stays server-side. We do not publish key-management internals here.
Admin, Intranet, and Client Workspace are separate portals with RBAC. Client Workspace is organization-scoped. Intranet CRM is Bitscaled’s internal tenant, not a public multi-tenant CRM.
We monitor the public website, Client Workspace, VaultTools, and related platform health. Live component status is published on the system status page — this Trust Center does not invent an “all systems secure” banner.
System statusReport product or platform issues to security@bitscaled.tech. We do not run a paid bug bounty. Discord and GitHub alert pipelines are internal operations, not a public intake channel.
Vulnerability disclosure policyWe maintain backups and a recovery process for Bitscaled-operated systems. Customer immutable-backup evidence, when contracted, is shown to authenticated Workspace users. We do not publish bucket names, account IDs, or infrastructure identifiers on this site.
Managed services follow your agreement. Customer-specific evidence is available through authenticated Client Workspace access.
We operate security monitoring and response as part of managed services — with named engineers, not an anonymous 24/7 theater. Scope is defined in the MSA and SOW.
Cybersecurity servicesDMARC, BIMI, and spoof-lab testing (VaultSandbox) so clients can see whether attackers can impersonate their domain. Start with the free tools or a scoped engagement.
Email spoof testTenant baseline reviews and ongoing administration when contracted. The public M365 snapshot tool is a starting point, not a substitute for tenant-scoped work.
M365 snapshotWe run HIPAA-ready operations and CMMC-oriented programs for clients who need them. That is delivery work under contract — not a claim that Bitscaled is CMMC certified or “HIPAA certified.”
Security consultingAuthenticated clients can review Trust & Governance in Client Workspace. Customer Workspace evidence is available to authenticated clients — we do not dump attestation JSON, vault names, or account identifiers on the public site.
Governance moduleWhen immutable backup is in scope, evidence is presented inside the client portal. Sign in to Workspace to view your company’s controls. Public pages never render raw attestation payloads.
Workspace sign inHelp us investigate safely. Use our security intake for vulnerabilities in Bitscaled-operated services.
For security & procurement teams
Tell us about your review to request available architecture documentation, control summaries, and vendor due-diligence materials. Our team confirms the scope and any confidentiality requirements before sharing evidence.
Your request opens our contact form with the security packet topic preselected.
Explore VaultTools and the VaultSandbox email lab before a scoped engagement.
Delivery SKUs — what we implement for clients (cybersecurity, consulting, hardening programs).
View security servicesClient Workspace product module for authenticated customers. Evidence stays in the portal, not on this public page.
Workspace governanceContracts and policies: Privacy, Terms, AUP, Cookies, and the DPA.
Legal hub