Security

The blackbook was guarded. The platform is, too.

Blackbook Engine runs SOC 2 controls across a per-tenant deployment on Microsoft Azure. The account intel your team guards closest stays protected and reviewed on a calendar.

SOC 2

self-attestation covering Security, Availability, and Confidentiality, all controls validated green

TLS + at rest

encrypted in transit and at rest, secrets in Azure Key Vault

Per-tenant

every customer's data isolated; on the dedicated tier, your own Azure subscription

The standard

Held to a standard, not a promise.

SOC 2, exercised and validated

We maintain a SOC 2 self-attestation covering Security, Availability, and Confidentiality. Controls are checked by automated tooling against the service as it runs. Every control is green.

Encrypted in transit and at rest

Traffic is encrypted end to end, and stored data is encrypted at rest. Secrets live in Azure Key Vault, never in code or configuration files.

Least-privilege access, reviewed

Sign-in runs through Microsoft Entra ID. Access is least-privilege by default, with no standing administrative access, and it is reviewed quarterly.

Your data stays yours

Each customer's data is isolated in its own tenant. Payments run through Stripe, so we never see or store card numbers. We do not sell data, and we do not share it for advertising.

On a calendar

Access, vendors, and backups run on a schedule.

Quarterly

  • Access review of Azure identity and repository collaborators
  • Vendor and subprocessor review
  • Backup restore test: recovery proven, not assumed

Annual and continuous

  • Policy review each year, against the controls they support
  • Microsoft Azure auto-patching and routine updates
  • Incident log maintained and reviewed
Straight answers

Questions security teams ask.

Is Blackbook Engine SOC 2 certified?
We maintain a SOC 2 self-attestation covering Security, Availability, and Confidentiality, validated by automated tooling with all controls green. It is a self-attestation, not a third-party certified report. If your review requires an auditor-certified report, tell us and we will scope one for your timeline.
Where does our data live?
On Microsoft Azure, in your tenant. On the dedicated tier, your instance runs on your own Azure subscription, inside your compliance boundary.
Who can access our data?
Only the systems that need it, under least-privilege access reviewed quarterly. No standing administrative access, and no access for advertising purposes.
Can we review the security documentation?
Yes. The attestation and its evidence are available to qualified customers on request. Book a call and we will walk through it.

See your blackbook in action.

The account intel a rep guards closest, built and scaled by AI, held securely.

Book a demo