The blackbook was guarded. The platform is, too.
Blackbook Engine runs SOC 2 controls across a per-tenant deployment on Microsoft Azure. The account intel your team guards closest stays protected and reviewed on a calendar.
self-attestation covering Security, Availability, and Confidentiality, all controls validated green
encrypted in transit and at rest, secrets in Azure Key Vault
every customer's data isolated; on the dedicated tier, your own Azure subscription
Held to a standard, not a promise.
SOC 2, exercised and validated
We maintain a SOC 2 self-attestation covering Security, Availability, and Confidentiality. Controls are checked by automated tooling against the service as it runs. Every control is green.
Encrypted in transit and at rest
Traffic is encrypted end to end, and stored data is encrypted at rest. Secrets live in Azure Key Vault, never in code or configuration files.
Least-privilege access, reviewed
Sign-in runs through Microsoft Entra ID. Access is least-privilege by default, with no standing administrative access, and it is reviewed quarterly.
Your data stays yours
Each customer's data is isolated in its own tenant. Payments run through Stripe, so we never see or store card numbers. We do not sell data, and we do not share it for advertising.
Access, vendors, and backups run on a schedule.
Quarterly
- Access review of Azure identity and repository collaborators
- Vendor and subprocessor review
- Backup restore test: recovery proven, not assumed
Annual and continuous
- Policy review each year, against the controls they support
- Microsoft Azure auto-patching and routine updates
- Incident log maintained and reviewed