Skip to main content
Security & trust

Custody of your records. Held to a high bar.

Customer records, invoices, contracts, and payroll runs are operating-critical documents. Losing them, leaking them, or being unable to produce them on demand isn't a bad day; it's an existential problem. We built BusinessAdminPro accordingly.

S/01

Encryption

Records are encrypted at rest with AES-256 and in flight with TLS 1.3. Backups are encrypted with their own key. Sensitive identifiers — SSN, EIN, bank account numbers, contact details — get an additional column-level encryption layer so even an internal breach can't reveal them.

AES-256 at rest
TLS 1.3 in flight
Encrypted backups
Column-level PII fields
S/02

Identity

Staff sign in through your existing identity provider via SAML or OIDC, or with email + MFA. Permissions are per-record, not just per-module: a counter clerk can see today's transactions without seeing payroll.

SSO via SAML / OIDC for staff
WebAuthn / TOTP MFA enforced
Per-record permissions
15-min idle session timeout
S/03

Audit

Every read and every write is logged with the actor, the timestamp, and the change. Logs are append-only and tamper-evident. A complete audit export is one click away when your insurance underwriter, enterprise customer, or attorney asks.

Append-only log every read & write
Signed by user every change traceable
Tamper-evident audit chain
One-click audit export
S/04

Payments

Card data never touches our infrastructure — we tokenize through your payment processor's hosted fields. Your operation inherits the processor's PCI scope, which is the simplest position to be in. ACH and bank-account flows use the same tokenization model.

No PAN ever stored
Tokenized processor hosted
PCI scope inherits processor
ACH tokenized too
S/05

Resilience

Hourly incremental backups across multiple regions. Blue-green deploys mean zero-downtime updates. We can roll back any change inside ninety seconds. Quarterly disaster-recovery drills run end-to-end; the report goes to every customer.

Hourly incremental backups
Blue / green deploys
90-second rollback
Quarterly DR drills
S/06

Posture

Annual third-party penetration test. Every release ships with a software bill of materials. Critical patches deploy within 72 hours of disclosure. We do not sell, syndicate, or share customer data with anyone — ever, under any business model.

Annual third-party pentest
SBOM every release
≤ 72h critical patch
No data sale ever
Your data

Yours. Always. Exclusively.

Everything in BusinessAdminPro is your property. The data model is documented. Exports are one click. Your contract terminates with a single clause: we hand you a complete, encrypted dump of every record, document, photo, audit log, and configuration file — and walk away.

We do not sell, syndicate, or share customer data with anyone — ever, under any business model. We do not train AI models on it. We do not aggregate it for benchmarking. The records are yours; our job is to hold them safely.

Uptime & incidents

Status page. Real postmortems. Honest dates.

Target uptime is 99.9%, monitored independently. Status is public at status.businessadminpro.com. Any unplanned outage triggers an incident report within 24 hours and a public postmortem within 5 business days.

99.9%
Target uptime
24h
Incident report
5d
Public postmortem
Report a vulnerability

Found something? Tell us first.

We welcome reports from researchers, customers, and the public. Send a description and reproduction steps through the contact form with "Security report" in the message. We respond within 24 hours, patch critical issues within 72 hours, and operate a researcher safe-harbor policy.

Compliance & frameworks

Compliance is the floor. Not a feature.

Where we can be certified, we will be. Where the framework is a set of controls rather than a certificate, we map and document. Status is plainly stated below — never aspirational marketing.

WCAG 2.1 AA
Standard
SOC 2 Type II
In progress
PCI DSS
Tokenized through processor
NIST 800-53 r5
Control framework aligned
Ready when you are

Run the business
on one system.

Thirty-minute discovery call with the actual builders. Tell us your industry and what you're using now; we'll show you what a tailored build looks like.

No commitment · No pushy sales reps