Security questionnaire
Common buyer questions mapped to what ships today. This is not a SOC 2 report. Counsel may request a fuller evidence pack under NDA.
Do you encrypt data in transit and secrets at rest?
Yes. Traffic uses TLS. Authentication secrets and connector credentials are encrypted at rest.
How is authentication enforced?
Protected session cookies; optional or required two-factor authentication; company single sign-on when enabled for your organization, with password sign-in disabled when enforce is on; directory provisioning when configured.
Is the product multi-tenant with isolation?
Yes. Each organization is isolated. Partner firms only reach clients they are linked to. Isolation is verified in our ongoing checks.
Do you have SOC 2?
We do not claim certification until an auditor report is available for diligence. Engagement status and evidence can be shared under NDA.
How do you handle incidents?
We follow a documented incident response process. Customer notice targets are on the service levels page. Status is published for customers.
Can Bacenik CIQ™ write back to our ERP?
By default, no. The product is read-first. Any future posting path requires a separate written schedule.
Where is customer data hosted?
The application runs on our cloud host; the database runs on managed Postgres (or a customer-managed database by agreement). Subprocessors are listed publicly.
How are privileged sessions controlled?
Role-based access; two-factor authentication for approvers and administrators; ability to end all sessions; platform support access is audited when used.