Welcome to the bCloud AI Trust Center
You can trust us with your data
From architecture to user interface, security and privacy are designed in from the very first line of code — never bolted on as an afterthought.
Your data belongs to you
Security by design
Full transparency
How we protect your data
Infrastructure security
- All data centres comply with or exceed SOC 2 security requirements
- CCTV surveillance, on-site security personnel, and key card access
- Redundant power, cooling, and network connectivity
- AES-256 encryption for data at rest across all storage systems
Access control & privilege management
- Centralised access management system for all production servers
- SSO, LDAP, and SSH certificate-based authentication
- Role-based access control (RBAC) with granular permissions
- Access policies audited regularly by independent third-party auditors
- SAML SSO and two-factor authentication for all dashboard accounts
Encryption & data protection
- TLS 1.2+ encryption for all data in transit
- AES-256 encryption for all data at rest
- API keys encrypted and stored securely with hardware security modules
- Customer data logically segregated in the cloud with strict isolation
Continuous security testing
- Continuous vulnerability scanning across all production systems
- Regular third-party penetration testing by accredited firms
- Public bug bounty programme to incentivise responsible disclosure
- Mandatory security training for all employees at onboarding
- Background checks conducted for all personnel to the extent permitted
Compliant. Secure. Award-winning.
Data privacy commitments
We believe privacy is a fundamental right. Here’s how we honour that principle across every aspect of our platform.
No user tracking
Our services do not track your end users beyond what you explicitly configure. We never sell, share, or monetise user data. User identity and behavioural data remain entirely under your control at all times.
Data minimisation
We apply data minimisation techniques across all services, collecting and processing only the minimum data necessary to deliver the functionality you've configured.
Data residency control
Choose where your data is processed and stored. With data centres spanning multiple regions, you can select the geographic location that meets your regulatory and compliance requirements.
Sub-processor oversight
We conduct thorough security and privacy audits of all sub-processors prior to onboarding, ensuring they maintain adequate security practices and data protection standards aligned with our own commitments.
AI model security & governance
How we protect AI models and your data within them
Shared responsibility model
bCloud AI is responsible for
- Securing physical and virtual infrastructure end-to-end
- Maintaining compliance with SOC 2, ISO 27001, ISO 27017, and GDPR
- Implementing API keys with access control lists (ACL) and 2FA
- Providing SAML SSO and AES-256 encryption for Enterprise customers
- Ensuring sub-processors follow equivalent security standards
- Delivering continuous security training to all employees
- Storing and encrypting your API keys securely
- Maintaining and patching open-source API clients and UI libraries
You are responsible for
- Managing user access and permissions in your organization
- Integrating bCloud AI securely into your applications
- Monitoring usage and detecting suspicious activity
- Complying with your internal security policies and applicable laws
- Backing up and securing your data
- Ensuring your users follow security best practices
- Reporting security incidents related to your use of bCloud AI
- Protecting your API keys and credentials
