Everything a security reviewer needs, in one place.
The controls behind the platform, the frameworks we map to, who we work with, and how to reach us. No marketing fog.
Encryption, end to end.
In transit
TLS 1.2+ on every connection, with HSTS (including subdomains) and upgrade-insecure-requests once a deployment is served over HTTPS. Session cookies are HttpOnly, SameSite and Secure under TLS.
At rest
Integration credentials, provider keys and webhook tokens are sealed with authenticated encryption (AES-128-CBC with HMAC-SHA256) before they touch the database. Tampered ciphertext fails closed rather than returning garbage.
Credentials
Passwords are stored only as salted, memory-hard hashes. A 12-character complexity policy, common-password screening and breach-style checks apply at sign-up and rotation.
Hardened on every request.
- Content-Security-Policy with a per-request nonce, object-src 'none' and frame-ancestors 'none'
- Clickjacking, MIME-sniffing and referrer-leak protection on every response
- CSRF tokens on every state-changing form and API call, including sign-in
- Session rotation on login and sign-out-everywhere via a per-user session epoch
- Per-IP rate limiting and account lockout after repeated failures
- Strict open-redirect protection on post-login navigation
- Parameterised SQL throughout; no string-built queries reach the database
- Organisation-scoped queries on every tenant-owned record
- Server-side input validation and output escaping
- Least-privilege roles and attributed administrative actions
- No secrets in source — configuration comes from the environment
- Cache-Control: no-store on authenticated console pages
Frameworks we build against.
GDPR / UK GDPR
We act as processor for workspace data, offer a full Data Processing Addendum with SCCs for transfers, and honour data-subject rights including access, portability and erasure.
CCPA / CPRA
We do not sell personal information. California residents can exercise rights to know, delete, correct and opt out of sharing directly from the console or by contacting us.
SOC 2 (Type II in progress)
Controls are designed and monitored against the SOC 2 Trust Services Criteria. Our latest report and security questionnaire responses are available under NDA.
ISO/IEC 27001
Our ISMS follows ISO 27001 as the organising framework, with documented policies, risk treatment and continuous improvement.
PCI-DSS
We do not store card data. Payments, where taken, are handled entirely by a PCI-DSS certified processor.
Accessibility — WCAG 2.2 AA
We design to WCAG 2.2 Level AA. Read our accessibility statement or report a barrier any time.
We plan for the bad day.
Incident response
A written IR plan with defined severities and owners. We notify affected customers without undue delay after confirming a personal-data breach.
Logging & monitoring
Authentication events, administrative actions and data exports are attributed and logged. Anomalies — repeated failures, lockouts, mass exports — surface in the Security center.
Backups & recovery
Encrypted, monitored backups with a documented recovery objective. Backups cycle out within 35 days and are tested as part of the IR programme.
Vulnerability management
Dependency and container scanning, continuous review against published advisories (CVE/NVD), and prompt patching based on severity.
Change control
Reviewed changes, environment separation and reproducible deployments. Database migration is idempotent and non-destructive.
Data portability
Export any view as CSV, or download a fully encrypted copy of your whole workspace from the Security center at any time.
The paperwork, ready to review.
Data Processing Addendum
Controller/processor terms, SCCs, sub-processing and audit rights.
Sub-processors
Every third party that may process personal data, and where.
Cookie Policy
Essential and optional storage, and how to change your choices.
Privacy Policy
What we collect, why, how long we keep it and your rights.
Acceptable Use Policy
The ground rules that keep the platform lawful and safe.
Accessibility Statement
Our WCAG 2.2 AA commitment and how to report a barrier.
Reach the right team
- Security & disclosures: security@bluestarai.world
- Privacy & data requests: privacy@bluestarai.world
- Abuse reports: abuse@bluestarai.world
- Accessibility: accessibility@bluestarai.world
Machine-readable disclosure
Our security.txt (RFC 9116) lists contact and policy details for automated tooling.
We'll send our questionnaire responses and reports.
Tell us what your reviewer needs — SIG, CAIQ, DPIA or a live walkthrough — and we'll turn it around quickly under NDA.