Security & Trust
Security controls in place. Independent verification underway.
BlueTies maintains active, layered safeguards for accounts, application access, billing, and operational data. Our security program is continuously maintained as we advance through formal SOC 2 readiness and independent verification. Certification has not yet been issued, and BlueTies will make certification claims only after the required controls, evidence period, and independent audit are complete.
Updated September 8, 2026
Safeguards currently in place
- Managed account authentication, email verification, and password recovery.
- Encrypted HTTPS connections and platform-managed encryption at rest.
- Stripe-hosted payment processing; BlueTies does not store full card details.
- Role and ownership controls for administrative, saved-project, and billing data.
- Validated billing requests, restricted checkout redirects, and verified Stripe webhook signatures.
Independent assurance in progress
- Formal SOC 2 control ownership, evidence collection, access reviews, vendor reviews, incident exercises, and tested recovery procedures.
- Stronger company-level data isolation and private document delivery for confidential enterprise use.
- Independent security testing and remediation verification before making certification claims.
Related frameworks
- ISO 27001 may follow the same risk-management and control foundation, but no certification is currently claimed.
- Privacy obligations such as CCPA and GDPR depend on customers, locations, data use, contracts, and completed operational processes.
- Stripe handles card processing; this does not make the BlueTies application PCI certified. HIPAA is not claimed and the service should not be used for protected health information.
Security questions
For security, privacy, vendor-review, or enterprise due-diligence questions, contact BlueTies through the Contact page. Do not send passwords, payment credentials, or confidential project files in your message.