Security & compliance

Your data and your customers' data deserve serious protection. Here's exactly what we do.

Active

AES-256-GCM encryption

All OAuth tokens and secrets encrypted at rest

Active

TLS 1.3 in transit

All API traffic encrypted in transit

Active

PIPEDA compliance

Data processed and stored in Canada

Active

GDPR compliance

Data export, deletion, and processing agreements available

In progress

SOC 2 Type I

Expected Q1 2027

Active

HMAC webhook verification

All inbound webhooks verified before processing

Active

RLS row-level security

Database-level tenant isolation

Vulnerability disclosure

Found a security issue? Please report it to security@bisavy.com. We acknowledge within 24 hours and resolve critical issues within 48 hours. We do not pursue legal action against good-faith researchers.