Bitscaled LLC · Tampa, Florida
Bitscaled is a Tampa Bay AI-native managed service provider for healthcare, manufacturing, logistics, and legal SMBs. This page is our public Trust Center — how we run our own platform, how we protect customer environments, and where to report a vulnerability. It is not a service catalog, not a legal policy, and not a live “all systems secure” badge. Named owners run security operations. We do not sell SOC theater we cannot evidence.
Last reviewed August 18, 2026
Keep these surfaces distinct. Prospects looking for “Security” here want trust, not a catalog item.
Delivery SKUs — what we implement for clients (cybersecurity, consulting, hardening programs).
View security servicesClient Workspace product module for authenticated customers. Evidence stays in the portal, not on this public page.
Workspace governanceControls for our company and this platform — not a dump of infrastructure identifiers.
Bitscaled portals use cookie-based sessions (HTTP-only, SameSite=strict, Secure in production) plus JWT for API calls. Staff sign in with our custom auth stack. Google Workspace SSO is available for Bitscaled Intranet and Admin when enabled — it is not a customer-facing enterprise SSO product. Multi-factor authentication is required on Bitscaled accounts used to deliver services.
Public site and portals terminate TLS at the Vercel edge. Remote access we control over public networks uses TLS. Session cookies are encrypted. We do not publish key-management internals here.
Admin, Intranet, and Client Workspace are separate portals with RBAC. Client Workspace is organization-scoped. Intranet CRM is Bitscaled’s internal tenant, not a public multi-tenant CRM.
We monitor the public website, Client Workspace, VaultTools, and related platform health. Live component status is published on the system status page — this Trust Center does not invent an “all systems secure” banner.
System statusReport product or platform issues to security@bitscaled.tech. We do not run a paid bug bounty. Discord and GitHub alert pipelines are internal operations, not a public intake channel.
Vulnerability disclosure policyWe maintain backups and a recovery process for Bitscaled-operated systems. Customer immutable-backup evidence, when contracted, is shown to authenticated Workspace users. We do not publish bucket names, account IDs, or infrastructure identifiers on this site.
Managed services positioning plus Client Workspace evidence for authenticated tenants.
We operate security monitoring and response as part of managed services — with named engineers, not an anonymous 24/7 theater. Scope is defined in the MSA and SOW.
Cybersecurity servicesDMARC, BIMI, and spoof-lab testing (VaultSandbox) so clients can see whether attackers can impersonate their domain. Start with the free tools or a scoped engagement.
Email spoof testTenant baseline reviews and ongoing administration when contracted. The public M365 snapshot tool is a starting point, not a substitute for tenant-scoped work.
M365 snapshotWe run HIPAA-ready operations and CMMC-oriented programs for clients who need them. That is delivery work under contract — not a claim that Bitscaled is CMMC certified or “HIPAA certified.”
Security consultingAuthenticated clients can review Trust & Governance in Client Workspace. Customer Workspace evidence is available to authenticated clients — we do not dump attestation JSON, vault names, or account identifiers on the public site.
Governance moduleWhen immutable backup is in scope, evidence is presented inside the client portal. Sign in to Workspace to view your company’s controls. Public pages never render raw attestation payloads.
Workspace sign inVaultTools public checks and the VaultSandbox email lab. These are starting points, not a substitute for a scoped engagement.
Honest language for healthcare, legal, and defense-adjacent SMBs. No certificates we do not hold.
Bitscaled does not claim SOC 2, ISO 27001, PCI DSS, CMMC, or independent pentest certification on this page. If we complete an audit later, this module will be updated by a human reviewer — not by an unattended AI generator.
We operate HIPAA-ready processes for contracted healthcare work and execute Business Associate Agreements when PHI is in scope. Individual customer BAA status is not published here.
Processor terms, technical measures (TLS, encrypted session cookies, least privilege, MFA on Bitscaled accounts), and subprocessor references live in the DPA.
Read the DPAWhat we collect on the public site, in Workspace, and in VaultTools is described in the Privacy Policy. This Trust Center does not replace that policy.
Privacy PolicyEmail security@bitscaled.tech with enough detail to reproduce the issue. Do not exfiltrate customer data to prove a finding. We do not offer a bug bounty. Coordinated disclosure terms are on the vulnerability disclosure page.
Disclosure policyHigh-level names already published in legal docs. The full inventory lives on the subprocessors page.
Website and application hosting, edge TLS, and related platform delivery.
Transactional and marketing email (Twilio SendGrid; Resend when configured). See the subprocessor list for the current inventory.
Public security assessment APIs at vaulttools.bitscaled.tech (Namecheap VPS). VaultSandbox email-lab testing is a separate hostname when deployed.
The canonical public list — including optional analytics, databases, and AI providers — is on the subprocessors page. We do not list secret or internal hostnames here.
SubprocessorsComponent health for the public website, Client Workspace, VaultTools, and related surfaces is on the system status page. Subscribe there, or contact us if you need incident updates for a contracted service.
System status