Security Overview
The controls that protect the data this business holds, stated openly — and, where a control is not yet in place, said so rather than implied.
1. What This Page Is, And Why It Is Not Behind A Form
This page is published in full and openly. Nothing on it sits behind a sign-in, a questionnaire or a non-disclosure agreement, because a security position a reader cannot read is a security position that has not been published. Our calculator records that distinction about other organisations, so it would be indefensible to hide our own.
It describes the controls that are in place today. Section 11 states what is not, because an overview that lists only strengths is marketing rather than an overview.
2. What We Hold
The data we hold is small and deliberately kept that way. It is described in full in our Privacy Notice: server logs, calculator events and results, sign-up and access records, correspondence, and professional contact information published by the individuals themselves.
We hold no payment card data on this website, no government identifiers, no health data and no special category data. We apply a data classification to each category we hold and the smallest amount that answers the purpose is what is kept.
3. Encryption
Personal data is encrypted in transit and encrypted at rest.
- In transit: TLS 1.2 or above on every connection to this website, to the BSI Calculator and to the database. HTTP Strict Transport Security is enabled, so a browser refuses an unencrypted connection after its first visit.
- At rest: full-disk encryption on the managed database and on object storage, and on every workstation used to do this work.
- Backups are encrypted with the same protection as the systems they protect.
4. Access Control
Access is role-based, granted on a need-to-know basis and on the principle of least privilege. Access controls are reviewed whenever a role changes, and access is removed on the day an engagement ends rather than at the next review.
Multi-factor authentication is enforced on every administrative account: the hosting platform, the database platform, the source code repository, the domain registrar and the model provider accounts. Administrative access to production data is limited to the founder.
Secrets and API keys are held in the platform's encrypted secret store. They are not committed to source control, and a scan of the change runs before every push.
5. Hosting And Segregation
This website, the BSI Calculator and the records behind them are hosted in Ireland. The application runs in the Dublin region and the database runs in the Ireland region.
The platforms are named on our Sub-Processors page. Both are managed services, so operating system patching, network isolation and physical security at the data centres are performed by the platform rather than by us — which is a control we rely on and therefore state, rather than claim as our own.
Development and production are separate environments. Production data is not copied into development.
6. The Calculator's Own Safety
The BSI Calculator fetches pages from addresses a user types. That is a request-forgery risk if it is built carelessly, so it is constrained: it resolves each address before connecting and refuses private, loopback, link-local and internal ranges; it follows a limited number of redirects and re-checks the destination at each one; it fetches over HTTPS only; and it caps the number of pages and the size of each response.
It signs in to nothing, submits no form, executes no JavaScript from the pages it reads, and stores no credential. It reads what an organisation has published to anyone.
7. Monitoring And Logging
Platform access logs and application request logs are retained for 90 days. Administrative actions on the hosting and database platforms are logged by those platforms and are reviewable.
Our own agent tooling runs behind a runtime guard that records tool activity and blocks classes of action outright, including reads of the system credential store. That is how a control is proven rather than asserted: it produced a blocked event, and the event is on record.
8. Vulnerability Handling
Dependencies are monitored for known vulnerabilities and updated on a scheduled cycle, and out of cycle where a vulnerability is being exploited. Platform-level patching is performed by the managed platforms named above.
If you believe you have found a vulnerability in this website or in the BSI Calculator, write to ror@blacksnowintel.com with enough detail to reproduce it. We will acknowledge within 3 business days and tell you what we intend to do. We will not pursue you for a good-faith report that stays within the law, does not access another person's data and does not degrade the service.
9. Incident Response
Data breach notification: where a breach is likely to result in a risk to the rights and freedoms of individuals, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and notify affected individuals without undue delay where the risk to them is high. Where we hold data for a client, we notify that client within 24 hours, on the terms in our Data Processing Terms.
The response sequence is: contain, establish what was affected, notify, remediate, and record what changed as a result. The record is kept whether or not the incident was notifiable.
10. Government And Law Enforcement Requests
We have received no law enforcement or government request for data, and no national security request. We will publish a transparency report if that changes.
Where such a request arrives we will require it in writing, satisfy ourselves that it is lawful and binding on us, disclose no more than it compels, and tell the affected party unless we are prohibited from doing so.
11. What Is Not In Place
This section exists because the absence of a control and the absence of a claim are different things, and a reader deserves to be told which one they are looking at.
- BlackSnow Intelligence holds no ISO/IEC 27001 certification and no ISO/IEC 42001 certification. The founder holds qualifications in those standards; the company is not certified against them, and we do not present the qualification as a certification.
- We hold no SOC 2 report and no Cyber Essentials certification.
- We have not commissioned an independent penetration test of this website. We will commission one before the platform accepts client data at scale, and we will say here when it has been done.
- We operate no 24-hour security operations centre. This is a small business and incident response is human and business-hours, with alerting outside them.
Each of these is a decision proportionate to what we hold today, and each is revisited as that changes.
12. Changes To This Overview
This is version 1.0, published on 17 August 2026. When a control changes we publish the new version at this address with a new version number and date, and we move an item out of section 11 only when it is genuinely done.
13. How To Reach Us
Write to ror@blacksnowintel.com. Our other published documents are indexed on the Legal page.