Version 1.0 --- Effective 2026-10-01 · Last updated 2026-09-12
This Security Overview is the public-facing summary of the technical and organizational measures described in Annex II of the Data Processing Addendum. It should be updated whenever Annex II materially changes.
BOMSync's measures are designed in alignment with recognized security practices and principles reflected in ISO/IEC 27001 and the SOC 2 Trust Services Criteria. BOMSync does not currently claim ISO/IEC 27001 certification or a completed SOC 2 attestation.
1. Encryption and secret management
BOMSync uses TLS 1.2 or higher for supported production communications and Azure platform encryption for production data at rest. Production secrets and supported Customer-provided AI/API credentials are managed in Azure Key Vault using managed identities and role-based controls. Supported BYOK credentials are not intended to be logged or redisplayed in plaintext after storage.
BOMSync uses automated repository secret scanning and does not intentionally commit production secrets to source control.
2. Access control
BOMSync applies role-based access and least privilege to production resources. MFA is required for privileged administrative and production access. Production access is limited to named personnel for a defined purpose.
Privileged access is logged where supported by the applicable Azure or application component. BOMSync will perform documented privileged-access reviews periodically based on risk and at least annually following commercial launch.
3. Tenant isolation and data minimization
Tenant context is enforced through authenticated application and database controls. BOMSync uses identifiers in preference to directly identifying data in logs and telemetry where technically feasible.
Development and production are operationally separated. BOMSync policy prohibits copying production Personal Data or Customer Data into development, debugging, test, or AI-assisted engineering tools; synthetic or redacted data is used for those purposes.
4. Software and change controls
Production source code and configuration are maintained in version control and are subject to review appropriate to the change and team size before deployment. Input validation and parameterized queries are used in production data-access paths where applicable.
BOMSync maintains security-relevant application and platform logs for authentication, authorization, administrative, and export activity to the extent supported by the applicable component. Logs are access-restricted and retained according to operational and security requirements.
5. Availability, backups, and recovery
BOMSync is hosted on Microsoft Azure and uses Azure platform resilience and database backup capabilities appropriate to the deployed service. Primary databases use automated backup/restore capabilities.
Standard backup rotation is designed not to exceed 90 days, subject to service architecture and legal-retention requirements. A separately purchased or configured dedicated-storage retention period applies only to the storage expressly covered by that configuration.
BOMSync maintains restore procedures and will conduct documented restore testing at least annually following commercial launch. Business continuity and disaster-recovery procedures are being documented for commercial launch and will be formally reviewed at least annually thereafter.
6. Vulnerability management and penetration testing
Repository secret scanning is automated. Dependency and vulnerability scanning will be enabled in the production build/release workflow and reviewed as part of commercial launch controls. Static analysis is used where appropriate.
BOMSync will complete its first independent penetration test within twelve (12) months after commercial launch and will perform independent penetration testing at least annually thereafter. Enterprise buyers may require a current report earlier; BOMSync may accelerate the first test as a commercial requirement.
7. Identity and customer access
BOMSync supports customer-administered user provisioning and de-provisioning and provides MFA capability. Authentication and identity records are hosted in France Central.
Where enterprise SSO functionality is enabled for the applicable subscription, BOMSync may support standards such as OpenID Connect or SAML as documented for that feature.
8. Incident management
BOMSync maintains security escalation procedures and is formalizing the documented commercial incident-response plan as part of launch operations.
If BOMSync becomes aware of a Personal Data Breach affecting data processed for a Customer, notice obligations are governed by the DPA, including notice without undue delay and, in any event, within 72 hours after BOMSync becomes aware of the breach.
Security concerns may be reported to security@bomsync.com.
9. AI and engineering-tool controls
BOMSync-managed production AI providers are identified on the Subprocessor List.
Claude Data Quality is disabled by default and requires activation
by an authorized tenant administrator. Activation is recorded as a
documented Customer instruction. BOMSync minimizes the outbound payload
and excludes the AuthDB tenant company_id GUID. Detected sensitive or
personally identifying fields must be excluded from outbound Claude Data
Quality analysis by default where they cannot be safely transformed.
BOMSync's use of Cursor, Claude, ChatGPT, or similar tools for development is separate from production AI processing. BOMSync policy prohibits putting Customer Data, production extracts, or personal data into development or AI-assisted engineering tools.
Supported Customer BYOK credentials are stored in Azure Key Vault and used only to perform Customer-initiated or Customer-configured requests.
10. Subprocessor governance
BOMSync evaluates material service providers that process Customer Data, enters appropriate data-protection terms, and maintains transfer mechanisms for international transfers where required.
Current subprocessors and processing locations are published at </legal/subprocessors>.
11. Physical security and endpoints
Microsoft Azure is responsible for physical security of BOMSync's cloud processing facilities under Microsoft's own controls and certifications. BOMSync operates no data centers.
BOMSync privileged administrative and development activity is performed from managed, encrypted endpoints with screen-lock and endpoint-protection controls.
12. Current certification status
Unless BOMSync later updates this page, BOMSync does not claim:
- ISO/IEC 27001 certification;
- a completed SOC 2 Type I or Type II attestation;
- FedRAMP authorization;
- HIPAA eligibility or a signed Business Associate Agreement;
- PCI DSS service-provider certification for storage of cardholder data; or
- a completed independent penetration test.