Security

Security policy

This page describes the controls BD AI actually runs and how to report a security problem to us.

  1. 01Controls in place

    Authentication and session handling are provided by the platform's managed auth service; passwords are never stored by the application.

    Authorization is server-side. Every privileged operation re-checks the caller's permission on the server; the interface never grants access on its own.

    Row-level security is enabled on every application table, so a record is only readable by its owner or by staff holding an explicit permission.

    Administrative actions are written to an append-only audit log protected by database triggers that block updates and deletes.

    AI answers are grounded in reviewed sources and defended against prompt injection. An AI model is never the authorization authority.

  2. 02Reporting a vulnerability

    Report suspected vulnerabilities privately through the BD AI contact page. Include the affected URL, the steps to reproduce and the impact.

    Please do not test against other people's accounts, do not exfiltrate data, and give us reasonable time to fix the issue before disclosing it.

  3. 03What we will not ask you for

    BD AI will never ask for your password, a one-time code, or payment to release a document or certificate. Anyone doing so is not BD AI — report it on the impersonation reporting page.

  4. 04Status of external controls

    Domain, email authentication, monitoring and backup verification are tracked internally on the launch readiness console and are reported as pending until evidence exists. We do not claim a control is in place before it is.

Questions about this policy go through the BD AI contact page or the AI Help Center. BD AI only replies from the channels listed on the Trust & Verification page.