Bizily
Security

How your data is kept

Every tenant's data is isolated in the database itself, no model can write a business record without a person approving it, and every model call is recorded with its cost, confidence and injection flags.

Model calls, tenant 0417
per tenantper call
classify inbox640 tok · 0.001 · conf 0.99 · nonemodel-b
extract QC-342 431 tok · 0.004 · conf 0.97 · nonemodel-a
match line 60 tok · 0.000 · conf 0.98 · nonerules-v1
source line 71 902 tok · 0.003 · conf 0.91 · 1 injectionmodel-a
draft quote Q-04171 210 tok · 0.002 · conf 0.95 · nonemodel-a
Model calls, per tenantprompt hash, model, tokens, cost, confidence, flags

Tenant isolation

Isolation is a database property here, not an application convention. Each operational table carries an organization id and a row-level security policy; the application connects as a least-privilege role whose grants are pinned to a reviewed manifest, and each transaction sets the tenant claim inside the transaction itself.

Every tenant table is checked in continuous integration to carry an isolation policy and a runtime-role grant, so a table cannot ship without them. Two things are staged and not yet the default: fail-closed behaviour when a request arrives with no tenant claim, and a two-organisation runtime harness that exercises the policies against a live database.

What the AI is allowed to do

Propose, never write
Extraction, matching and sourcing produce proposals. A person approves, corrects or rejects before anything becomes a record or leaves the building.
Grounded fields only
Every extracted field carries an evidence span from the source document. Ungrounded fields are dropped and counted.
Rules before models
Catalog matching runs deterministic rules first; the model only re-ranks what rules could not place, and abstains below the tenant's threshold.
Tool tiers
Untrusted text is handled by tool-less calls. Tools are available only to calls whose input is trusted, enforced in the type system.
Budgets
Per-tenant spend has hard stops. A runaway job halts instead of billing.

The ledger

Every model call writes a row: prompt hash, model, tokens, cost, confidence, injection flags, tenant and purpose. You can see what the AI did on your data, what it cost, and how sure it was — per call, not as a monthly total.

Secrets and access

Integration credentials are held in environment configuration today, never logged and never exported. Per-tenant envelope encryption — a key per secret, decrypted only inside a tenant-scoped operation — is designed and is the next migration. Support access is bounded, and the audit trail a tenant can read for itself is being added.

What is not true yet

We are pre-launch and say what is missing: no SOC 2 report, no penetration-test letter to share, single-region hosting, and a support model that is a person rather than a rota. On the list above: fail-closed tenancy and the two-organisation isolation harness are staged but not yet the default; per-tenant envelope encryption of secrets is the next migration; the evaluation set exists but does not yet gate releases; and the support audit trail is not yet visible to tenants. If any of those is a blocker for your pilot, tell us at the first call rather than after.

Questions that need a real answer, not a page: write to hello@bizily.ai.

Questions

Are you SOC 2 certified?
No. The system is designed against SOC 2 criteria and the controls are mapped to them, but there has been no audit and we do not claim a report. We will say so plainly when that changes.
Is my data used to train models?
No. Tenant content is not used to train models, ours or a provider's. Model calls run through a gateway configured for zero data retention where the provider supports it.
Can another tenant see my prices or customers?
No. Every operational table carries an organization id with a row-level security policy, and the runtime database role is least-privilege. Fail-closed behaviour when a request carries no tenant claim is staged and becomes the default before any outside tenant is onboarded.
What happens if a request contains a prompt injection?
Untrusted text is only ever passed to tool-less, structured-output calls, wrapped in a per-call random delimiter with a canary. A canary echo or delimiter breakout flags the document, forces human review and shows a banner. Injection cases are part of the release benchmark.
Who at Bizily can see my tenant?
Support access is time-bounded and granted per request, and we do not browse tenants. A per-read audit trail you can inspect yourself is being added.
Where does the data live?
Postgres on Neon, application hosting on Vercel, model calls through the Vercel AI Gateway, and Resend for the e-mail this site sends. Those four are the whole list today. Tell us if a region is a requirement for your pilot.
Can I export or delete everything?
Yes. Export is per tenant and includes the ledger; deletion removes tenant rows and secrets on request. Retention windows are set per tenant, and legal holds are explicit.