How we work, and how to reach us about security.

This page is about the company. Where a product’s data is stored, who processes it and under which agreement is on that product’s own page, because one page cannot honestly describe two products.

How we build and run

  • Every change is reviewed and passes automated tests, static analysis and a dependency vulnerability scan before it is deployed; images are built reproducibly.
  • Administrative access only through personal accounts with multi-factor authentication: no shared accounts, least privilege, and access rights reviewed at least quarterly.
  • Production, test and development are separate, and no customer data is used outside production.
  • We hold our own software to the standard we would ask of a supplier: OWASP ASVS Level 1, with evidence or a test for every requirement, reviewed before production holds customer data.
  • External monitoring outside our own infrastructure, a documented incident procedure, and runbooks whose restores are tested.

Each product’s own details

Where the data of a product is stored, who processes it, and the measures its agreement sets out.

Security of the Reporting Desk

This website

No analytics, no tracking, no cookies, and nothing loaded from another company’s servers: the fonts, the styles and the pictures all come from this domain. That is why you were not asked about cookies.

Reporting a vulnerability to us

Write to contact@bithive-it.com, the address in our security.txt. We answer within two business days, we will not take legal steps against good-faith research, and we tell you when the issue is fixed.

security.txt