Security and trust

Clear boundaries before broad assurances.

Blazorly is in private beta. This page describes current product responsibilities and avoids transferring infrastructure-provider certifications or controls to Blazorly by implication.

Private-beta trust posture

Product access is invitation-based. Exact controls, providers, data paths, and capabilities vary by product and workspace. Ask us for the current architecture relevant to your proposed use before placing sensitive or regulated work into a beta environment.

What we can say today

Security is expressed through product-specific controls.

Invitation and identity boundaries

Blazorly products use authenticated workspace or application access. Roles, project scope, and exact authorisation paths are product-specific.

Managed runtime and data services

The platform uses Cloudflare runtime services and managed PostgreSQL infrastructure. We do not claim that every app receives a dedicated physical database.

Supervision and approvals

The Conversational Client presents approval before supported data mutations. Agent and Crew can hold sensitive work at configured approval and policy boundaries.

Credential separation

Blazorly Agent owns supported provider and connector execution boundaries. Crew does not receive connected-application credentials in its product data or browser output.

Shared responsibility

Know which layer is responsible.

No single sentence can describe every Blazorly product, hosting service, customer configuration, and connected provider. The relevant trust review should separate them.

01

Blazorly product controls

Application and agent configuration, product-specific access paths, release controls, approval experiences, service boundaries, and operational procedures owned by Blazorly.

02

Infrastructure providers

Cloudflare, managed PostgreSQL providers, AI model providers, and other subprocessors operate their own infrastructure controls and may hold their own certifications.

03

Workspace configuration

Customers remain responsible for choosing suitable data, users, permissions, model providers, connections, channels, approval policy, and product usage for their risk profile.

What we do not claim

Provider compliance is not Blazorly compliance.

  • Blazorly does not currently claim SOC 2, ISO 27001, or HIPAA certification.
  • A hosting provider's certification does not automatically certify Blazorly or a customer's workspace.
  • We do not publish a blanket 99.9% uptime, 24/7 monitoring, backup, or incident-notification commitment for the private beta.
  • Approval interfaces support human control, but they do not replace correct identity, authorisation, data-boundary, and connector configuration.
Planning a serious evaluation?

Tell us the product, data, and control requirements.

We can discuss the current private-beta architecture and whether your proposed use is appropriate. Legal, privacy, and security review remains necessary for sensitive deployments.

Contact us