Home / Trust Center / Summary
For IT & security reviews
Security summary
Product controls overview · Updated 23 July 2026
A concise map of Bitlyne’s in-product controls. This is a product capability summary — not a certification claim. Use it to prepare diligence calls.
Honest scope.
Controls below ship in the platform engine and Configuration UI.
Formal certifications, DPAs, and Trust Center packs are process work we walk through with buyers.
1. Tenant & access
- Hard organization (tenant) boundary
- Profiles & module/meta permissions
- Positions / seats validated on platform requests
- Record shares for selective access
- Marketplace install vs publish rights
2. Activity audit
- Business record create / update / delete
- Module & field (schema) create / update / delete
- Permission-aware read — not an ownership bypass
- Attribution across user, rules, ops, schedulers
3. Retention & legal hold
- Policy-driven TTL from an anchor date
- Scheduled purge via normal delete path
- Legal hold hard-gates delete & purge
- Holds target specific records
4. Messaging consent
- Channel + purpose consent ledger
- Outbound send paths assert permission
- STOP / unsubscribe can append opt-out evidence
- Shared channel foundation (not provider-forked engine code)
5. Agent (HITL)
- Runs under signed-in user JWT & grants
- Optional confirmation before mutating tools
- Meta remains reviewable in Configuration
6. Packaging model
- Business apps install as versioned packages
- Same security model for every install
- No need for publishers to host customer data stores
Reviewer checklist
| Question | Bitlyne today | Where to look |
|---|---|---|
| Is customer data isolated by organization? | Yes — tenant boundary + access model | Access |
| Can admins see who changed records and schema? | Yes — activity audit (records + meta) | Audit |
| Can we keep data for N days then purge? | Yes — retention policies + scheduled purge | Retention |
| Can purge be blocked for investigations? | Yes — legal hold gates delete | Legal hold |
| Are outbound messages consent-aware? | Yes — channel consent ledger + send gates | Consent |
| Can AI silently rewrite production meta? | Mitigated — grants + optional write confirmation | Agent |
| GDPR / SOC 2 certified? | Not claimed on this page — diligence supported | Roadmap |
Next step
Bring this page to your review call. We’ll map each row to Configuration in a trial organization.