Security FAQ
Home»Security FAQ
Security & data questions, answered directly
Straight answers, without unsupported guarantees. If your question isn't covered, ask us directly.
Where is my data stored?
BMaiKR-hosted services run on HostPowr’s European infrastructure. Exact storage locations for a given workload are documented per service — see Data Residency.
Is customer data stored in Europe?
The intended architecture stores application data, databases, and backups on European infrastructure. Some categories — such as external integrations a customer connects — depend on that provider’s own location. See Data Residency for the category-by-category breakdown.
Where are backups stored?
Backups are intended to remain on European infrastructure alongside the primary service. Exact backup architecture and retention is documented per service — see Backup & Recovery.
Who can access customer data?
Access is limited to authorized BMaiKR personnel who need it to operate or support the service, under the access controls described on the Security page.
Who operates the infrastructure?
BMaiKR’s technical operations are handled by the co-founder and core technical team. Underlying infrastructure is provided by HostPowr.
Do you use external AI providers?
Where a workflow requires AI reasoning, BMaiKR uses external AI providers. Which provider is used is a configuration decision documented per project — see AI Data Handling.
Does customer data go to AI models?
Only the specific, minimized context a task requires is passed to an AI model — not open access to a customer’s full database. See AI Data Handling for the architecture.
Can I choose whether external AI is used?
Yes — AI processing mode (controlled external AI, EU-hosted/private model, customer-approved provider, or no external AI) is a configuration decision made per project.
What happens when I terminate?
Data remains available for approximately one week after termination as a recovery/export window, after which it is deleted according to the applicable service configuration.
Can I export my data?
Yes — during the post-termination recovery window, you can request an export of your data.
How long is data retained after termination?
Approximately one week, as a recovery/export window, before deletion — see Customer Data Lifecycle.
What subprocessors do you use?
See the Subprocessors page for the current list, including HostPowr for infrastructure and any AI, email, analytics, or integration providers relevant to a given service.
Do you support DPAs?
Yes — contact us to discuss a Data Processing Agreement for your engagement. See the DPA page.
How is tenant isolation handled?
Customer data and workflows are kept separate at the application and storage layer; see the Customer Isolation section of the Security page.
How is access controlled?
Through authentication, role-appropriate authorization, and least-privilege access — see the Security page.
How are secrets handled?
Credentials and API keys are kept out of source code and managed through the application’s secrets configuration.
How are backups protected?
Backups are subject to the same access restrictions as production data.
What happens during a security incident?
A documented process covers detection, containment, investigation, remediation, communication, and post-incident review — see Incident Response.
Can you provide security documentation?
Yes — contact us to request the security or data-residency documentation relevant to your evaluation.
Can you support a security questionnaire?
Yes — reach out via Contact and we’ll work through your questionnaire directly.
