Access model
- Every record is scoped to the account that owns it and enforced in the database, not just the interface.
- Roles are stored separately from profiles and checked server-side.
- Sensitive identifiers such as license numbers are readable only by their owner and administrators.
- Sharing is explicit, per-document, and revocable.
What you can do
- Review recent activity and shares in the Security Center.
- Revoke document shares and end relationships at any time.
- Manage notification preferences per channel.
- Request an export or deletion of your data from Settings or by emailing support.
Reporting a vulnerability
Email support@bizanywhere.app with steps to reproduce. Please do not test against other users' accounts or data. We acknowledge reports within two business days.