Skip to content
BizLink

Security

How we protect your business and your customers.

Security is built into how BizLink works, not added on later. This page describes the controls in place today.

Controls

What’s in place

Hashed passwords

Passwords are never stored. We store a PBKDF2-SHA256 hash with a unique random salt per password, and comparisons run in constant time.

Secure sessions

Session cookies are HttpOnly and SameSite=Lax, marked Secure over HTTPS, and can be revoked. Sensitive actions require recent re-authentication.

Encrypted transport

All traffic is served over HTTPS (TLS), with HTTP Strict Transport Security enabled in production.

Content Security Policy

Pages are served with a strict CSP that allows scripts only from our own origin and approved payment/captcha providers, plus nosniff, frame and referrer protections.

CSRF protection

Every state-changing API request requires a custom request header and an origin check, on top of SameSite cookies.

Rate limits

Sign-in, sign-up, password reset, public forms, uploads and AI usage are rate limited to slow down abuse and brute-force attempts.

Tenant isolation & roles

Every request is authorised on the server for the specific business it touches. Team members get role-based capabilities, and records from another business are never returned.

Audit logs

Consequential actions — publishing, team and billing changes, deletions and administrative access — are recorded in an audit log.

Upload checks

Uploads are size-limited and their file type is verified from the file contents, not just the name. Originals stay private until you publish them.

Privacy-minded analytics

Public page analytics use a daily-rotating anonymous identifier and salted IP hashes. Form contents are never sent to analytics.

Principles we follow

  • AI proposes; owners decide what gets published.
  • Plan limits and permissions are enforced on the server, never only in the browser.
  • Third-party providers sit behind adapters and never receive more data than they need.
  • Errors never expose stack traces or internal details.

Certifications

BizLink does not currently hold third-party security certifications. We describe our controls here as they are, and will update this page if that changes.

Reporting a vulnerability

If you believe you have found a security issue, please contact us at [security contact email]. Please do not access other people’s data or disrupt the service while testing.