Trust is not a badge.
It’s how the platform runs.

Bitlyne ships access control, activity audit, retention, legal holds, and messaging consent inside Configuration — the same engine that runs your business packages. Built for international buyers who need governed operations, not improvised apps.

Org isolation Activity audit Retention & holds Channel consent Agent write confirm

Access & Security

Who can see and change what

Each organization is a hard tenant boundary. Profiles, positions, hierarchy, and record shares decide capability — the same model every installed package inherits.

  • Tenant separation — business data stays in the workspace you enter.
  • Profiles & permissions — module CRUD plus meta (schema) rights.
  • Positions & seats — active seat validation on platform requests.
  • Record shares — grant specific records without opening whole modules.
  • Marketplace rights — who may install vs publish packages.

Activity audit

A readable trail of what changed

The engine writes activity for business records and for module/field schema changes. Admins review it in Configuration → Compliance — filtered to what their permissions already allow them to see.

Records

Creates, updates, and deletes on live business data — with field-level change detail when available.

Schema (meta)

Module and field create / update / delete — so structural changes are not invisible.

  • Permission-aware read — audit never becomes a backdoor past ownership.
  • Attribution — user action, rules, operations, schedulers, and package metadata can be distinguished.

Retention & legal hold

Keep what you must. Delete what you shouldn’t.

Retention policies define how long records stay after an anchor date — then purge through the normal delete path. Legal holds freeze specific records so purge and delete cannot quietly erase evidence.

  • Policy-driven TTL — target module, optional match criteria, anchor field, retention days.
  • Scheduled purge — disciplined, capped batches so the org drains safely over time.
  • Legal hold gate — held records are blocked at the engine on delete.
  • Same writers — retention uses the real delete pipeline, so shares, refs, and holds still apply.

Bitlyne Agent

AI that authors — humans that approve

Agent works under the signed-in user’s grants. Mutating tool calls can require confirmation before invoke — so AI accelerates meta without silently rewriting production.

  • User JWT & grants — tools run as the person, not a shadow superuser.
  • Write confirmation — optional HITL for mutating agent actions.
  • Reviewable meta — modules, rules, and ops remain inspectable in Configuration.

Why this is different

Compliance on the same engine as your apps

Improvised products bolt on logging later. Bitlyne packages install into an org that already has seats, shares, audit, retention, and consent. Your Desk, CRM, or industry app doesn’t reinvent trust — it inherits it.

Records-firstBehavior as configuration, not hard-coded branches.
Marketplace-safeInstall stays inside one security model.
Operator-readyCompliance surfaces live next to Access & Security.

Honest roadmap

What ships next for trust

We don’t claim certifications on this page. Product capabilities above are in the platform; formal audits, DPAs, and Trust Center artifacts are process work we walk through with buyers.

  • SSO & MFA — enterprise identity and session multi-factor (designed next).
  • Trust Center — DPA / SCC templates, subprocessors, and review packs.
  • Accessibility — ongoing WCAG hardening of the product SPA.

Questions teams ask

Are you GDPR / SOC 2 certified?

Certifications and legal documents are separate from the product engine. Bitlyne ships the operational controls reviewers expect to see — isolation, access, audit, retention, holds, consent — and we support diligence with clear mapping.

Does audit cover schema changes?

Yes. Module and field create / update / delete are audited as meta activity, alongside business record changes.

Can retention delete a record under legal hold?

No. Legal holds hard-gate delete — including retention purge — so held records stay until released.

Who sees audit rows?

Activity audit is permission-aware. You only see activity for modules and records you’re already allowed to read — so audit does not bypass ownership or shares.

Map Bitlyne to your review checklist

Start with the one-page Security summary, then we’ll walk Access, Compliance, and Agent controls during a free trial — with your IT or security lead on the call.

Security summary Trust Center Leave a lead Email sales