Security FAQ - BMaiKR
Skip to content

Security FAQ

Home»Security FAQ

Security & data questions, answered directly

Straight answers, without unsupported guarantees. If your question isn't covered, ask us directly.

  • Where is my data stored?

    BMaiKR-hosted services run on HostPowr’s European infrastructure. Exact storage locations for a given workload are documented per service — see Data Residency.

  • Is customer data stored in Europe?

    The intended architecture stores application data, databases, and backups on European infrastructure. Some categories — such as external integrations a customer connects — depend on that provider’s own location. See Data Residency for the category-by-category breakdown.

  • Where are backups stored?

    Backups are intended to remain on European infrastructure alongside the primary service. Exact backup architecture and retention is documented per service — see Backup & Recovery.

  • Who can access customer data?

    Access is limited to authorized BMaiKR personnel who need it to operate or support the service, under the access controls described on the Security page.

  • Who operates the infrastructure?

    BMaiKR’s technical operations are handled by the co-founder and core technical team. Underlying infrastructure is provided by HostPowr.

  • Do you use external AI providers?

    Where a workflow requires AI reasoning, BMaiKR uses external AI providers. Which provider is used is a configuration decision documented per project — see AI Data Handling.

  • Does customer data go to AI models?

    Only the specific, minimized context a task requires is passed to an AI model — not open access to a customer’s full database. See AI Data Handling for the architecture.

  • Can I choose whether external AI is used?

    Yes — AI processing mode (controlled external AI, EU-hosted/private model, customer-approved provider, or no external AI) is a configuration decision made per project.

  • What happens when I terminate?

    Data remains available for approximately one week after termination as a recovery/export window, after which it is deleted according to the applicable service configuration.

  • Can I export my data?

    Yes — during the post-termination recovery window, you can request an export of your data.

  • How long is data retained after termination?

    Approximately one week, as a recovery/export window, before deletion — see Customer Data Lifecycle.

  • What subprocessors do you use?

    See the Subprocessors page for the current list, including HostPowr for infrastructure and any AI, email, analytics, or integration providers relevant to a given service.

  • Do you support DPAs?

    Yes — contact us to discuss a Data Processing Agreement for your engagement. See the DPA page.

  • How is tenant isolation handled?

    Customer data and workflows are kept separate at the application and storage layer; see the Customer Isolation section of the Security page.

  • How is access controlled?

    Through authentication, role-appropriate authorization, and least-privilege access — see the Security page.

  • How are secrets handled?

    Credentials and API keys are kept out of source code and managed through the application’s secrets configuration.

  • How are backups protected?

    Backups are subject to the same access restrictions as production data.

  • What happens during a security incident?

    A documented process covers detection, containment, investigation, remediation, communication, and post-incident review — see Incident Response.

  • Can you provide security documentation?

    Yes — contact us to request the security or data-residency documentation relevant to your evaluation.

  • Can you support a security questionnaire?

    Yes — reach out via Contact and we’ll work through your questionnaire directly.