Skip to content

Security

Security

How Bhogar protects your data: identity and access controls, tenant isolation, encryption, data handling and retention, deployment options, and compliance status.

Bhogar workspace Guardrails page listing active guardrails such as Token Limit, Per-Request Cost Cap, PII Protection, Content Moderation, and Healthcare PHI Redaction.

Controls

Security controls

Identity and access

  • Microsoft Entra OAuth with PKCE; SAML and OIDC for other providers
  • Company and workspace scoping on every request, enforced server-side
  • Role-based access plus per-module entitlement checks
  • MFA with WebAuthn and session revocation

Tenant isolation and data handling

  • Tenant identifiers in queries, embeddings, and vector-search filters
  • Retrieval filtered by the requesting user’s permissions, not a service account
  • Encryption in transit and at rest with managed cloud KMS
  • Secrets in a managed vault - never in config or prompts

AI-specific controls

  • Guardrails for sensitive-data detection and policy enforcement on input and output
  • Model gateway with per-workspace budgets, quotas, and fallbacks
  • Evaluation suites that gate changes on quality and safety
  • Human approval steps on consequential workflows

Operations and audit

  • Execution traces covering retrieval, tool calls, model calls, and cost
  • Administrative and access audit history
  • OpenTelemetry with pluggable providers, including Azure Monitor
  • Container deployment, environment-scoped config, least-privilege identity

Data handling

Data storage and retention

CategoryPurposeResidencyRetention
Connected source contentRetrieval and groundingYour tenant database and vector store, in your regionWhile the source is connected; removed on disconnect or deletion
Embeddings and indexesSemantic searchSame tenant scoping as the sourceRebuilt on re-index; deleted with the knowledge base
Conversation and execution historyContinuity, traceability, cost attributionPlatform database in the deployment regionConfigurable per company to your policy
Model inference payloadsGenerating a response or actionThe model provider you configureGoverned by provider terms; BYO keys keep it under your control
Telemetry and logsReliability, performance, security investigationYour observability backend or the platform defaultTime-bounded by your telemetry configuration
Credentials and secretsAuthenticating to connected systems and providersManaged secret store, referenced by ID onlyUntil you rotate or revoke the connection

Deployment

Deployment options

  • Managed cloud

    Tenant isolation, regional placement, platform-operated upgrades.

  • Your cloud subscription

    Your Kubernetes; data and model traffic stay inside your network and compliance boundary.

  • Your model providers

    Bring Azure OpenAI, OpenAI, Anthropic, Google, or Bedrock credentials. Inference runs under your agreements.

Compliance

Compliance status

Current status for each framework. Status is confirmed in writing during your security review.

  • SOC 2 Type II

    Certified

    Annual audits by independent CPA firms for security, availability, and confidentiality controls.

  • ISO 27001

    Aligned

    Information security management system aligned with international security best practices.

  • GDPR

    Compliant

    Built for EU General Data Protection Regulation compliance including data subject rights.

  • CCPA

    Compliant

    California Consumer Privacy Act compliance with consumer rights protections.

  • HIPAA Ready

    Available

    Healthcare data protection with Business Associate Agreement (BAA) available.

  • EU-US DPF

    Compliant

    EU-US Data Privacy Framework compliant for cross-border data transfers.

Responsible disclosure

Report a vulnerability

Email security@bhogar.ai with reproduction detail. We acknowledge receipt, work the fix, and coordinate disclosure timing with you. Privacy and data-subject requests go to privacy@bhogar.ai.

Security reviews and questionnaires

Most answers are on this page, in the DPA, and in the SOC 2 alignment document. Send us your questionnaire and we complete the rest in writing.