Compliance & Security

Last updated July 13, 2026

We build PilotBPM for teams that care about governance and auditability. This page summarizes our security practices and how we handle data protection and regulatory obligations.

Security practices

  • Encryption in transit. All traffic is served over TLS (HTTPS).
  • Credential protection. Passwords are stored only as salted hashes; secrets such as API keys are encrypted at rest.
  • Tenant isolation. Every record is scoped to a tenant, and access is enforced on every request through role- and permission-based controls.
  • Least privilege & RBAC. Granular roles, custom roles, department scoping, and explicit allow/deny rules limit access to what each user needs.
  • Audit trail. An append-only changelog records who did what, when, and why across the platform.
  • File storage. Customer files are stored with encryption at rest (cloud object storage SSE and, where enabled, application-layer envelope encryption for File Cabinets). Downloads are authorized and proxied by the application.
  • Secure development. Code review, dependency management, environment separation, and ongoing internal security review.

Certifications & independent audits

We do not currently hold SOC 2 or ISO 27001 certification. We maintain security practices consistent with those frameworks and can share a security overview, subprocessors list, and Data Processing Addendum with customers under NDA. Independent audit timeline updates will be posted here when kickoff and report dates are set.

We are not a HIPAA covered entity or business associate by default, and we do not claim PCI DSS certification for cardholder data (payment cards are handled by our payment subprocessor).

Data protection (GDPR / UK GDPR)

  • We act as a processor for Customer Content and as a controller for account and marketing data.
  • A Data Processing Addendum (DPA) is available to customers on request at legal@pilotbpm.com.
  • We support data subject requests (access, correction, deletion, export) and assist customers in responding to requests from their own users.
  • International transfers, where applicable, rely on Standard Contractual Clauses.

CCPA / CPRA

We do not sell personal information or share it for cross-context behavioral advertising. California residents can exercise their privacy rights as described in our Privacy Notice.

Data retention & deletion

Customer Content is retained until deleted by a workspace administrator or until the account is closed, after which it is removed within a commercially reasonable period, subject to backups and legal requirements. Administrators control form-submission retention and can delete records at any time.

Subprocessors

We use a small set of vetted subprocessors to operate the Service. Current categories include:

CategoryPurpose
Cloud hostingApplication and database hosting
Object storageEncrypted file blobs (when cloud storage is enabled)
Transactional emailDelivery of account, notification, and billing emails
Payment processingSubscription billing for paid plans
AI providers (optional)AI features, only when enabled — OpenAI, Anthropic, Google (Gemini), or Microsoft Azure OpenAI

A current list of named subprocessors is available to customers on request. We provide notice of material changes so customers can object where they have the right to do so.

AI & your data

AI features are optional and configurable per workspace. Prompts and outputs are not used to train models, and a workspace can run AI in an offline mode that makes no external calls. Administrators control who can use AI and which provider/key is used. The supported external providers are OpenAI, Anthropic (Claude), Google (Gemini), and Microsoft Azure OpenAI; when one is used, submitted content is processed under that provider's terms and privacy policy. AI output is generated automatically and may be inaccurate, so it should be reviewed before being relied upon — see the Terms of Service.

Self-hosted (Enterprise) deployments

For self-hosted Enterprise installations, the customer operates the software in their own environment and is responsible for hosting, backups, and infrastructure security. We provide the software, security guidance, and updates. In that model the customer is the controller and processor for their own data.

Reporting a vulnerability

If you believe you've found a security issue, please email security@pilotbpm.com. We appreciate responsible disclosure and will work with you to investigate and remediate.

Questions

For DPAs, security questionnaires, or compliance documentation, contact legal@pilotbpm.com.