Trust center
What your security reviewer will ask. Answered.
Where is my data?
The product is self-hosted: it runs inside your environment, and your cloud credentials and infrastructure data never leave it. This website stores contact-form submissions in Google Cloud Firestore, and its content is served from Sanity’s Content Lake. Demo bookings are handled by Cal.com.
Who processes it?
Sub-processors for this website and the product: Google Cloud / Firebase (Firestore — form submissions), Sanity (Content Lake — site content), Cal.com (demo scheduling), Anthropic (product AI). The product itself is self-hosted, so production infrastructure data is not processed by Bugz.
Security posture
Role-based access with four roles (viewer, developer, approver, admin), separation of duties — the requester is never the approver — and an audit trail on every step. Deployment is self-hosted, so the trust boundary is yours. SOC 2 and ISO 27001 are planned; no certification is claimed today.
Which frameworks does the product check?
CIS Azure Benchmark, NIST 800-53, PCI DSS, SOC 2 Trust Services Criteria, RBI IT Framework and CERT-In guidelines. Checks run on every proposed change. The live framework list and control counts on this site are synced from the product repository, not typed by hand.
How do you handle AI?
Agents propose; humans approve. No AI output reaches your cloud without passing the procedure’s checks and a human approval — approving a change is never automated. Product AI uses Anthropic models, and we never train models on customer data.
Accessibility (WCAG 2.2 AA)
This site targets WCAG 2.2 AA — contrast checked on both dark and paper surfaces, visible focus rings, 44px touch targets and full keyboard operation. Accessibility feedback: support@bugzidna.com.
DORA supplier pack
For FIN-FSA and other DORA-supervised buyers we are preparing the supplier pack: a Legal Entity Identifier, the Article 30 contractual clause set (audit, exit, subcontracting) and the data you need for your register of information. In preparation — ask us for the current status.
NIS2 supplier questionnaire
Answers to the supplier-assessment questions under Implementing Regulation 2024/2690, including our secure development procedures and our update and continuity commitments. In preparation.
EU representative and data-transfer terms
Bugz is headquartered in India, which has no EU adequacy decision. A GDPR Article 27 EU representative, a data-processing agreement and the 2021 Standard Contractual Clauses are being put in place; until then, contact support@bugzidna.com.
Cyber Resilience Act
As a manufacturer of self-hosted software sold into the EU, Bugz honours the CRA reporting obligations that apply from 11 September 2026. A software bill of materials is available on request, our vulnerability-disclosure contact is published in security.txt, and the full conformity work for December 2027 is planned.
Region · EU
EU
| Regulation | What it means | Bugz position | Status |
|---|---|---|---|
| Cyber Resilience Act | EU-wide security requirements for products with digital elements, including secure-by-default design and vulnerability handling. | Self-hosted deployment and a published disclosure policy (security.txt) today; a full CRA conformity assessment is planned. | planned |
| NIS2 | Supply-chain security duties for EU essential and important entities — your vendors, including Bugz, become part of your NIS2 scope. | A NIS2 supplier pack (security posture, sub-processors, incident contact) is planned; answers to reviewer questionnaires available on request. | planned |
| DORA | Digital operational resilience rules for EU financial entities and their ICT third-party providers. | Self-hosted deployment keeps Bugz out of the critical ICT path by default; DORA-specific contractual terms are planned. | planned |
| EU AI Act | Risk-based obligations for AI systems placed on the EU market, including transparency and human-oversight requirements. | Human oversight is the product’s core mechanic — agents propose, humans approve. A formal AI Act classification is planned. | planned |
| GDPR | EU data-protection law covering any personal data we process — for this website, that is contact and lead form submissions. | DPA with SCCs available on request; sub-processor list published on this page. EU contact: support@bugzidna.com (an Art. 27 EU representative is not yet appointed). | partial |
Region · US
US
| Regulation | What it means | Bugz position | Status |
|---|---|---|---|
| SOC 2 Type II | Independent audit of security, availability and confidentiality controls, commonly required by US buyers. | Planned; no certification is claimed today. | planned |
| NIST AI RMF · SP 800-53 | US federal risk-management frameworks for AI systems and information-system security controls. | The product ships NIST 800-53-derived checks today; a mapped AI RMF profile is planned. | planned |
| CISA Secure by Design | CISA’s voluntary commitments for software vendors on secure defaults and vulnerability transparency. | Secure defaults and a published security.txt today; pledge status is under review. | planned |
| FedRAMP | US federal authorisation programme for cloud services sold to government agencies. | Not applicable to self-hosted deployment; will be assessed if a managed US-government offering ships. | planned |
Agent-gateway security
How the MCP gateway maps to the OWASP Agentic Top 10
| ID | Risk | Control |
|---|---|---|
| ASI01 | Goal hijack | Agents can only invoke registered procedures through the gateway; free-form execution against the cloud is not exposed. |
| ASI02 | Tool misuse | Every tool call is scoped by role and validated against the procedure’s declared steps before it runs. |
| ASI08 | Cascading failures | Blast-radius calculation gates automatic plan execution; human approval stops propagation beyond the threshold. |
| ASI10 | Rogue agents | Per-agent identity and authorisation: every agent acts under its own authenticated identity and role. |