Security and trust

This page describes the product control model without turning plans into certifications or an unsigned target into an SLA. Deployment-specific commitments belong in the signed Security Schedule and Order Form.

IAM

Access and tenant isolation

Binta applies tenant-scoped authorization and role controls. The agreed scope and customer-specific evidence are recorded in the signed security documents.

DATA

Data protection and resilience

Transmission, secrets, backups and restore procedures are deployment controls. Regions, retention, tested recovery targets and incident commitments are stated only when verified and agreed.

AUD

Auditability

Security-relevant and business operations can create traceable records. Exact coverage, retention and evidence access depend on the contracted service and applicable law.

AI

Bounded AI actions

AI output is treated as a proposal, not authority. Input safety, allowlisted actions, role limits and approval gates constrain workflows where the product requires them.

DPA

Privacy and processors

The Privacy Notice and DPA describe roles, instructions, subprocessors, transfers, data-subject assistance and deletion. The signed documents identify the parties and processing details.

Evidence, not badges

Binta does not claim a SOC 2 or ISO 27001 certification on this page. A certification, audit report, recovery target or response time applies only when current evidence or a signed agreement expressly states it.

AI transparency

The public product chat identifies itself as AI before the conversation. AI answers can be incomplete or wrong; visitors can move to a human sales or support channel for consequential decisions.

Report a security concern

Send a concise description and safe reproduction details. Do not access, change or retain data that is not yours. Response and remediation targets apply only under an agreed policy or SLA.

Email technical support: support@binta.site