Skip to content

Security

Security controls should match the actual workflow and data.

BZ Labs designs pilots and software systems to minimize unnecessary data collection, restrict access, and make operational assumptions explicit. Specific controls are documented for each engagement before access to customer systems or confidential data.

Working principles

Controls are documented, scoped, and reviewed.

Data minimization

We seek the smallest data set needed to test or operate a workflow. Public-data prototypes are kept separate from customer-provided information.

Access control

Access to customer information and production systems is limited to authorized operators involved in the relevant engagement.

Transport security

Public web applications are served over HTTPS. Integrations and data transfers should use encrypted channels supported by the relevant provider.

Secrets and credentials

Secrets must remain in server-side environment or secret-management systems and must not be exposed in browser code, repositories, logs, or screenshots.

Logging and retention

Logging should support reliability and security without collecting unnecessary personal or confidential data. Retention periods are defined according to the purpose of the engagement.

Third-party providers

When a pilot relies on hosting, model, email, analytics, or data providers, the relevant dependencies and material data flows should be documented.

Responsible reporting

Report a concern directly.

Security concerns related to BZ Labs websites or systems may be reported to support@bz-labs.com.

Certification status

BZ Labs does not claim SOC 2, ISO 27001, HIPAA, PCI DSS, or another formal certification unless that certification is explicitly documented on this site.

Discuss the controls your workflow requires.

Security and data-handling requirements should be part of pilot scoping before systems or confidential data are accessed.