This page covers two things: how this website itself is built and secured, and how we approach security as part of client engagements. It is not a compliance certification — see the note on that below.
This website
- Served over HTTPS only, hosted on Cloudflare Pages.
- Both public forms (discovery-call request and checklist download) are protected by Cloudflare Turnstile bot verification, server-side token validation, and a hidden honeypot field, rejecting unverified or automated submissions before any data is accepted.
- Server-side secrets (API tokens, verification keys) are never exposed to the browser or committed to source control; see our Privacy Policy for what's collected and how it's handled.
- This is a static site with no database of its own, which limits its attack surface.
How we approach security in engagements
Security work we do for clients — network policy, admission control, runtime detection, secrets management — is described on ourZero-Trust Security & DevSecOps service page. In short: we build security into the platform as part of how it operates day to day, rather than treating it as a pre-audit checklist exercise.
What we don't claim
BPMBI does not claim SOC 2, ISO 27001, or any other third-party security certification for itself. Those come from an accredited external auditor assessing an organization as a whole, not from a statement on a website. If your engagement requires us to meet a specific compliance framework, that's a scoping conversation for the discovery call, not something we'll assert here.
Reporting a security issue
If you believe you've found a security issue with this website, email[email protected] with details. Please don't test for vulnerabilities against this site beyond what's needed to demonstrate an issue, and give us a reasonable window to respond before public disclosure.