Security is part of the product.
Berma designs, builds and operates applied AI systems with practical controls appropriate to each product and client engagement.
Security principles
- Least-privilege access for people, services and integrations.
- Encryption in transit and at rest where supported by the hosting provider.
- Secrets stored outside source code and rotated when exposure is suspected.
- Production changes reviewed, logged and designed for safe rollback.
- Customer data access limited to the people and systems required to deliver the service.
Vulnerability reporting
If you believe you found a security issue in a Berma-operated product, email [email protected]. Include the affected product, a clear description, reproduction steps and potential impact. Please do not access, modify or download data that does not belong to you.
Response
We acknowledge valid reports, investigate impact, contain active risk and coordinate remediation. Timelines depend on severity and the affected system. We do not claim a certification or audit unless it is stated explicitly for the relevant product.
Scope
This page describes Berma's baseline security approach. Product-specific terms, data processing obligations and client agreements may add stricter requirements.