Security
How we protect your business and your customers.
Security is built into how BizLink works, not added on later. This page describes the controls in place today.
Controls
What’s in place
Hashed passwords
Passwords are never stored. We store a PBKDF2-SHA256 hash with a unique random salt per password, and comparisons run in constant time.
Secure sessions
Session cookies are HttpOnly and SameSite=Lax, marked Secure over HTTPS, and can be revoked. Sensitive actions require recent re-authentication.
Encrypted transport
All traffic is served over HTTPS (TLS), with HTTP Strict Transport Security enabled in production.
Content Security Policy
Pages are served with a strict CSP that allows scripts only from our own origin and approved payment/captcha providers, plus nosniff, frame and referrer protections.
CSRF protection
Every state-changing API request requires a custom request header and an origin check, on top of SameSite cookies.
Rate limits
Sign-in, sign-up, password reset, public forms, uploads and AI usage are rate limited to slow down abuse and brute-force attempts.
Tenant isolation & roles
Every request is authorised on the server for the specific business it touches. Team members get role-based capabilities, and records from another business are never returned.
Audit logs
Consequential actions — publishing, team and billing changes, deletions and administrative access — are recorded in an audit log.
Upload checks
Uploads are size-limited and their file type is verified from the file contents, not just the name. Originals stay private until you publish them.
Privacy-minded analytics
Public page analytics use a daily-rotating anonymous identifier and salted IP hashes. Form contents are never sent to analytics.
Principles we follow
- AI proposes; owners decide what gets published.
- Plan limits and permissions are enforced on the server, never only in the browser.
- Third-party providers sit behind adapters and never receive more data than they need.
- Errors never expose stack traces or internal details.
Certifications
BizLink does not currently hold third-party security certifications. We describe our controls here as they are, and will update this page if that changes.
Reporting a vulnerability
If you believe you have found a security issue, please contact us at [security contact email]. Please do not access other people’s data or disrupt the service while testing.