Security & Trust

Business Friendly, Inc.  ·  Last Updated: September 17, 2026

This page explains how Business Friendly, Inc. ("Business Friendly," "we," "our") protects the data our customers and their business communities trust us with on the BusinessFriendly.ai platform (the Business Friendly Index). It is a plain-language companion to our Privacy Policy and Terms of Service, not a replacement for either.

On this page

Access controls

Every organization on the platform is isolated from every other organization; server-side authorization checks run on every request, not just in the interface.

Encryption

Data & AI trust

Our full Data & AI Trust Standard covers source provenance, confidence, human approval and confidentiality levels in detail. In short:

Backup & disaster recovery

Our database runs on Cloudflare D1, which provides Time Travel: point-in-time restore of the database to any point in the preceding 30 days. We rely on this platform capability for disaster recovery of application data. Uploaded files (documents, recordings, images) are stored in Cloudflare R2.

Incident response

If you believe you have found a security issue affecting BusinessFriendly, or you are a customer reporting a suspected incident, contact consulting@businessfriendly.ai. We investigate reported incidents, and where a confirmed security incident affects a customer's data, we notify the affected customer without undue delay with the details we have and what we are doing about it.

Vulnerability disclosure

We welcome good-faith reports of security vulnerabilities in BusinessFriendly.

Our machine-readable disclosure contact is published at /.well-known/security.txt per RFC 9116.

Data retention, export & deletion

Subprocessors

We use a limited set of subprocessors — companies that process data on our behalf to provide the service. See the current list, with what each one does and what data it sees, on our Subprocessors page.

Certification status

Business Friendly, Inc. is not SOC 2 certified, and we do not hold ISO 27001, HIPAA, or any other formal security certification today. We are working through an internal SOC 2 readiness program — tracking access review, change management, incident response, backups, vendor management, vulnerability management, logging, security policies, and staff access controls — as a step toward a future independent audit. We will update this page if and when that changes.

Questions about anything on this page? Contact us at consulting@businessfriendly.ai.