Skip to content

Trust & Security

How we protect your business data

This page is maintained by God Plus Goals Inc. d/b/a Xcellant Apps to answer common security and privacy questions about BizAnywhere. It describes controls that are in place today — it is not a certification or an independent audit.

Last reviewed August 2, 2026

Controls in place

Authentication

  • Email and password or Google sign-in, with hosted session management.
  • Sessions are token-based and refreshed automatically; you can sign out of the app at any time.
  • Anonymous sign-ups are disabled.

Data access controls

  • Row-level security is enabled on application tables, so records are scoped to the owning account in the database itself.
  • Roles are stored in a dedicated table and checked server-side, never inferred from the browser.
  • Sensitive identifiers such as professional license numbers are restricted to the owner and administrators.

Encryption

  • Traffic is served over HTTPS/TLS.
  • Data at rest is encrypted by our cloud database and storage providers.
  • Document downloads use short-lived signed URLs from a private storage bucket.

Document sharing

  • Uploads are private to your account by default.
  • Sharing is explicit, per-document, and tied to an accepted professional connection.
  • Any share can be revoked, and revocation removes access immediately.

Logging and monitoring

  • Sensitive events are recorded in an append-only audit log that cannot be edited or deleted by users.
  • Product analytics events are first-party and used to improve the app.

Platform and hosting

  • BizAnywhere runs on managed cloud infrastructure with a managed Postgres database, object storage, and an edge application runtime.
  • Backups and patching of the managed database and storage layers are handled by those providers.

Shared responsibility

Our platform

Secure hosting, encryption, access enforcement, audit logging, and timely fixes to reported vulnerabilities.

You, the account owner

Strong credentials, choosing who to share documents with, revoking access when an engagement ends, and keeping your business data accurate.

Professionals you connect

Handling shared documents confidentially, maintaining their own licensing and insurance, and following our Acceptable Use Policy.

Subprocessors and integrations

We use a small set of service providers to operate BizAnywhere. Each is bound by confidentiality obligations and processes data only to deliver its service.

CategoryPurpose
Managed cloud database, auth & storageApplication data, authentication, and document storage
Edge application hostingServing the web application and server functions
AI processing providerGenerating briefings, summaries, and recommendations
Email delivery providerTransactional email such as sign-in and notifications
Tools you connectOnly the tools you explicitly authorize in the Connect Hub

Retention and deletion

Your data is retained while your account is active. You can delete documents at any time. On account deletion we remove or de-identify personal information within 90 days, except records we must keep for legal, tax, or security reasons.

Privacy requests & vulnerability reports

Email support@bizanywhere.app for a data export, deletion, or to report a security issue with steps to reproduce. Please do not test against other users' accounts. We acknowledge reports within two business days.

BizAnywhere has not completed a SOC 2, ISO 27001, PCI, or HIPAA audit, and nothing on this page should be read as a certification or a guarantee against breach. For the full legal terms, see our Privacy Policy and Terms of Service.