Data minimization
We seek the smallest data set needed to test or operate a workflow. Public-data prototypes are kept separate from customer-provided information.
Security
BZ Labs designs pilots and software systems to minimize unnecessary data collection, restrict access, and make operational assumptions explicit. Specific controls are documented for each engagement before access to customer systems or confidential data.
Working principles
We seek the smallest data set needed to test or operate a workflow. Public-data prototypes are kept separate from customer-provided information.
Access to customer information and production systems is limited to authorized operators involved in the relevant engagement.
Public web applications are served over HTTPS. Integrations and data transfers should use encrypted channels supported by the relevant provider.
Secrets must remain in server-side environment or secret-management systems and must not be exposed in browser code, repositories, logs, or screenshots.
Logging should support reliability and security without collecting unnecessary personal or confidential data. Retention periods are defined according to the purpose of the engagement.
When a pilot relies on hosting, model, email, analytics, or data providers, the relevant dependencies and material data flows should be documented.
Responsible reporting
Security concerns related to BZ Labs websites or systems may be reported to support@bz-labs.com.
BZ Labs does not claim SOC 2, ISO 27001, HIPAA, PCI DSS, or another formal certification unless that certification is explicitly documented on this site.
Security and data-handling requirements should be part of pilot scoping before systems or confidential data are accessed.