Bizora is designed to protect sensitive tax, financial, and client information. We apply security and privacy controls across our platform, infrastructure, development practices, and vendor relationships.
For additional detailed information, please contact admin@bizora.ai.
We are actively working towards SOC 2 Security audit readiness. Our program covers security policies, risk management, vendor oversight, and control implementation and testing.
To learn about current progress, please contact admin@bizora.ai.
Customer data is encrypted in transit using current TLS protocols and at rest using AES 256 or equivalent controls. These protections also apply to OAuth tokens and other sensitive credential material.
Encryption is implemented across storage systems, backups, and communication channels to minimize the risk of unauthorized access or data exposure throughout the data lifecycle.
We use role based access controls, least privilege permissions, authentication controls, and logical separation of customer data. Personnel authorized to access customer data are subject to confidentiality obligations.
Bizora supports SAML based Single Sign On with Microsoft Entra ID through Auth0. Organizations requiring SSO can enable it during onboarding.
We do not use customer prompts, responses, documents, accounting data, or other customer content to train AI models.
We require third party AI providers processing customer data on our behalf not to use that data for model training. We do not sell customer data or use it for advertising, marketing, or resale.
For security questionnaires, vendor assessments, responsible disclosures, or additional supporting documentation, contact our team at admin@bizora.ai.
Sensitive security documentation may be provided subject to appropriate confidentiality protections.
Our security program includes continuous monitoring and alerting, vulnerability management, secure software development practices, change management, incident response, backup and recovery planning, and periodic reviews of security controls.
Security events are monitored to identify potential threats, while vulnerabilities are assessed and remediated based on risk and severity.
Customers control the documents they store in Bizora and may delete them at any time. Upon deletion, customer data is removed from active production systems in accordance with our deletion processes.
Residual encrypted copies may remain in access restricted backups until the applicable backup retention period expires.