Our Commitment
Security is foundational to the trust our customers — and the consumers in our database — place in us. Below is a summary of how we protect data across our platform.
Data Protection
- Encryption in Transit. All traffic to and from the BuyerBeacon Pro platform is encrypted using TLS 1.2 or higher with modern cipher suites.
- Encryption at Rest. Production data stores are encrypted at rest using AES-256.
- Hashing & Truncation. Where feasible, identifiers (e.g., email addresses) are hashed (SHA-256) or truncated before storage and transmission.
- Tokenization. Sensitive customer credentials and API keys are tokenized and stored in a secrets manager separate from application data.
Infrastructure
- Hosting. Production infrastructure runs on tier-1 cloud providers (AWS, GCP) located in the United States, in facilities with SOC 2 / ISO 27001-aligned controls.
- Network Segmentation. Production, staging, and corporate networks are isolated. Access to production is restricted to a small group of vetted personnel via VPN with multi-factor authentication.
- Web Application Firewall. Edge traffic is filtered through a managed WAF with DDoS mitigation, bot management, and rate-limiting.
- Backups. Encrypted, versioned, off-site backups with documented restoration runbooks.
Identity & Access
- Least Privilege. Access to systems and data follows the principle of least privilege, with quarterly access reviews.
- MFA. Multi-factor authentication is required for all employee accounts and any administrative system access.
- SSO. Administrative access to internal systems is brokered through SSO with audit logging.
- Offboarding. Departing personnel are deprovisioned within one (1) business day.
Application Security
- Secure Development Lifecycle (SDLC). Code is peer-reviewed, scanned with static analysis tools, and tested before release.
- Dependency Management. Open-source dependencies are scanned for known vulnerabilities (CVE) and patched on a defined cadence.
- Penetration Testing. Annual third-party penetration testing of customer-facing surfaces.
- Vulnerability Management. Critical vulnerabilities are remediated within 7 days of disclosure; high-severity within 30 days.
Monitoring & Incident Response
- Audit Logging. Administrative access and sensitive data operations are logged and retained for at least 12 months.
- 24/7 Monitoring. Anomalous activity in production triggers automated alerts to the on-call engineer.
- Incident Response Plan. We maintain a documented incident-response playbook with defined roles, communication paths, and post-mortem requirements.
- Customer Notification. In the event of a confirmed security incident affecting customer or consumer data, we notify affected customers without undue delay, as required by applicable law.
People & Process
- Background Checks. Background screening for personnel with access to production systems.
- Security Training. Annual security and privacy training for all employees and contractors with access to customer or consumer data.
- Confidentiality. All personnel and contractors are bound by written confidentiality obligations.
- Vendor Diligence. Sub-processors are reviewed for security posture before onboarding and audited periodically.
Compliance Alignment
While certifications evolve, our internal controls are designed to align with the following frameworks:
- SOC 2 Type II (in progress)
- ISO/IEC 27001 (target)
- NIST Cybersecurity Framework
- GDPR Article 32 (security of processing)
- CCPA / CPRA security obligations
Responsible Disclosure
We welcome reports from security researchers. If you believe you've identified a vulnerability in BuyerBeacon Pro:
- Email admin@buyerbeacon.pro with the subject "Security Disclosure"
- Provide reproduction steps, impact assessment, and any proof-of-concept
- Allow us a reasonable window (typically 30–90 days) before public disclosure
We will respond within five (5) business days and work in good faith toward remediation. We do not pursue legal action against researchers who follow this responsible disclosure process in good faith.
Contact