Trust & security

How Bowtie Risk Engine handles your data, and what we do — and don't — do for security. We aim to be specific and honest rather than vague and reassuring.

Where your work lives

Authentication & access

The web editor requires sign-in with a licensed account, so work is tied to a named user and isolated to that account. Access to each account's data is enforced server-side: a user can only read and write their own workspace. Passwords are handled by the identity provider and are never stored or seen by us.

Transport & hardening

What we do not (yet) do

We are a focused team and we are honest about our posture.

If your procurement needs any of the above, get in touch — we're happy to scope what's possible.

Reporting a vulnerability

If you believe you've found a security issue, email [email protected] with a clear description, steps to reproduce, and any proof-of-concept material. We aim to acknowledge within five business days. Please don't publicly disclose before we've had a reasonable chance to fix it.

For procurement

We're glad to complete reasonable security questionnaires for organisations evaluating a licence. Reach out via the contact page with the questionnaire attached and your timeline.

Questions from your security team?

Send them our way — we answer questionnaires and disclosure reports directly.