Skip to content

Trust center

What your security reviewer will ask. Answered.

Where is my data?

The product is self-hosted: it runs inside your environment, and your cloud credentials and infrastructure data never leave it. This website stores contact-form submissions in Google Cloud Firestore, and its content is served from Sanity’s Content Lake. Demo bookings are handled by Cal.com.

Who processes it?

Sub-processors for this website and the product: Google Cloud / Firebase (Firestore — form submissions), Sanity (Content Lake — site content), Cal.com (demo scheduling), Anthropic (product AI). The product itself is self-hosted, so production infrastructure data is not processed by Bugz.

Security posture

Role-based access with four roles (viewer, developer, approver, admin), separation of duties — the requester is never the approver — and an audit trail on every step. Deployment is self-hosted, so the trust boundary is yours. SOC 2 and ISO 27001 are planned; no certification is claimed today.

Which frameworks does the product check?

CIS Azure Benchmark, NIST 800-53, PCI DSS, SOC 2 Trust Services Criteria, RBI IT Framework and CERT-In guidelines. Checks run on every proposed change. The live framework list and control counts on this site are synced from the product repository, not typed by hand.

How do you handle AI?

Agents propose; humans approve. No AI output reaches your cloud without passing the procedure’s checks and a human approval — approving a change is never automated. Product AI uses Anthropic models, and we never train models on customer data.

Accessibility (WCAG 2.2 AA)

This site targets WCAG 2.2 AA — contrast checked on both dark and paper surfaces, visible focus rings, 44px touch targets and full keyboard operation. Accessibility feedback: support@bugzidna.com.

DORA supplier pack

For FIN-FSA and other DORA-supervised buyers we are preparing the supplier pack: a Legal Entity Identifier, the Article 30 contractual clause set (audit, exit, subcontracting) and the data you need for your register of information. In preparation — ask us for the current status.

NIS2 supplier questionnaire

Answers to the supplier-assessment questions under Implementing Regulation 2024/2690, including our secure development procedures and our update and continuity commitments. In preparation.

EU representative and data-transfer terms

Bugz is headquartered in India, which has no EU adequacy decision. A GDPR Article 27 EU representative, a data-processing agreement and the 2021 Standard Contractual Clauses are being put in place; until then, contact support@bugzidna.com.

Cyber Resilience Act

As a manufacturer of self-hosted software sold into the EU, Bugz honours the CRA reporting obligations that apply from 11 September 2026. A software bill of materials is available on request, our vulnerability-disclosure contact is published in security.txt, and the full conformity work for December 2027 is planned.

Region · EU

EU

RegulationWhat it meansBugz positionStatus
Cyber Resilience ActEU-wide security requirements for products with digital elements, including secure-by-default design and vulnerability handling.Self-hosted deployment and a published disclosure policy (security.txt) today; a full CRA conformity assessment is planned.planned
NIS2Supply-chain security duties for EU essential and important entities — your vendors, including Bugz, become part of your NIS2 scope.A NIS2 supplier pack (security posture, sub-processors, incident contact) is planned; answers to reviewer questionnaires available on request.planned
DORADigital operational resilience rules for EU financial entities and their ICT third-party providers.Self-hosted deployment keeps Bugz out of the critical ICT path by default; DORA-specific contractual terms are planned.planned
EU AI ActRisk-based obligations for AI systems placed on the EU market, including transparency and human-oversight requirements.Human oversight is the product’s core mechanic — agents propose, humans approve. A formal AI Act classification is planned.planned
GDPREU data-protection law covering any personal data we process — for this website, that is contact and lead form submissions.DPA with SCCs available on request; sub-processor list published on this page. EU contact: support@bugzidna.com (an Art. 27 EU representative is not yet appointed).partial

Region · US

US

RegulationWhat it meansBugz positionStatus
SOC 2 Type IIIndependent audit of security, availability and confidentiality controls, commonly required by US buyers.Planned; no certification is claimed today.planned
NIST AI RMF · SP 800-53US federal risk-management frameworks for AI systems and information-system security controls.The product ships NIST 800-53-derived checks today; a mapped AI RMF profile is planned.planned
CISA Secure by DesignCISA’s voluntary commitments for software vendors on secure defaults and vulnerability transparency.Secure defaults and a published security.txt today; pledge status is under review.planned
FedRAMPUS federal authorisation programme for cloud services sold to government agencies.Not applicable to self-hosted deployment; will be assessed if a managed US-government offering ships.planned

Documents

  • DPA + SCCson-request
  • Sub-processor listpublicView
  • Disclosure policy · security.txtpublicView
  • Accessibility statementon-request
  • SBOMon-request
  • Pen-test summaryon-request

Agent-gateway security

How the MCP gateway maps to the OWASP Agentic Top 10

IDRiskControl
ASI01Goal hijackAgents can only invoke registered procedures through the gateway; free-form execution against the cloud is not exposed.
ASI02Tool misuseEvery tool call is scoped by role and validated against the procedure’s declared steps before it runs.
ASI08Cascading failuresBlast-radius calculation gates automatic plan execution; human approval stops propagation beyond the threshold.
ASI10Rogue agentsPer-agent identity and authorisation: every agent acts under its own authenticated identity and role.

We use one analytics cookie to understand traffic. Nothing loads until you accept.