Trust & Security
How we protect your business data
This page is maintained by God Plus Goals Inc. d/b/a Xcellant Apps to answer common security and privacy questions about BizAnywhere. It describes controls that are in place today — it is not a certification or an independent audit.
Last reviewed August 2, 2026
Controls in place
Authentication
- Email and password or Google sign-in, with hosted session management.
- Sessions are token-based and refreshed automatically; you can sign out of the app at any time.
- Anonymous sign-ups are disabled.
Data access controls
- Row-level security is enabled on application tables, so records are scoped to the owning account in the database itself.
- Roles are stored in a dedicated table and checked server-side, never inferred from the browser.
- Sensitive identifiers such as professional license numbers are restricted to the owner and administrators.
Encryption
- Traffic is served over HTTPS/TLS.
- Data at rest is encrypted by our cloud database and storage providers.
- Document downloads use short-lived signed URLs from a private storage bucket.
Document sharing
- Uploads are private to your account by default.
- Sharing is explicit, per-document, and tied to an accepted professional connection.
- Any share can be revoked, and revocation removes access immediately.
Logging and monitoring
- Sensitive events are recorded in an append-only audit log that cannot be edited or deleted by users.
- Product analytics events are first-party and used to improve the app.
Platform and hosting
- BizAnywhere runs on managed cloud infrastructure with a managed Postgres database, object storage, and an edge application runtime.
- Backups and patching of the managed database and storage layers are handled by those providers.
Shared responsibility
Our platform
Secure hosting, encryption, access enforcement, audit logging, and timely fixes to reported vulnerabilities.
You, the account owner
Strong credentials, choosing who to share documents with, revoking access when an engagement ends, and keeping your business data accurate.
Professionals you connect
Handling shared documents confidentially, maintaining their own licensing and insurance, and following our Acceptable Use Policy.
Subprocessors and integrations
We use a small set of service providers to operate BizAnywhere. Each is bound by confidentiality obligations and processes data only to deliver its service.
| Category | Purpose |
|---|---|
| Managed cloud database, auth & storage | Application data, authentication, and document storage |
| Edge application hosting | Serving the web application and server functions |
| AI processing provider | Generating briefings, summaries, and recommendations |
| Email delivery provider | Transactional email such as sign-in and notifications |
| Tools you connect | Only the tools you explicitly authorize in the Connect Hub |
Retention and deletion
Your data is retained while your account is active. You can delete documents at any time. On account deletion we remove or de-identify personal information within 90 days, except records we must keep for legal, tax, or security reasons.
Privacy requests & vulnerability reports
Email support@bizanywhere.app for a data export, deletion, or to report a security issue with steps to reproduce. Please do not test against other users' accounts. We acknowledge reports within two business days.
BizAnywhere has not completed a SOC 2, ISO 27001, PCI, or HIPAA audit, and nothing on this page should be read as a certification or a guarantee against breach. For the full legal terms, see our Privacy Policy and Terms of Service.