Compliance & Security

Last reviewed: September 1, 2026

This document describes Bitment's security architecture and control posture at a level appropriate for a vendor risk review, security questionnaire, or internal IT assessment. It is organized by control domain. Where a control is still in progress, we say so plainly. Bitment makes no certification claims in this document beyond what is explicitly stated.

1. Organization and Program

Bitment Inc. owns and operates the platform described in this document. Bitment's Chief Executive Officer is the executive owner of the security program, with day-to-day responsibility delegated to the engineering team.

SOC 2 audit in progress. Bitment is undergoing a SOC 2 audit against the AICPA Trust Services Criteria (security, availability, and related categories); the report will be available to customers on request once issued. Bitment does not represent any other third-party certification (HIPAA, ISO 27001, GDPR) unless and until a corresponding audit report exists.

Written information security policies covering acceptable use, access control, change management, vendor management, and incident response are maintained and are available to customers under NDA on request.

2. Infrastructure and Network Security

Every paying customer ("firm") is provisioned a dedicated, network-isolated AWS stack. Firms are not co-located in a shared database or application instance; each stack has its own virtual private cloud (VPC), its own database, and its own application host. Bitment also operates a shared stack of the same design for its own internal testing; it holds no customer data and no customer firm is provisioned on it.

ComponentSecurity function
Dedicated VPC per firm (2 public + 2 private subnets)Network-level isolation between customers; no shared network path between firms
Internet-facing Application Load Balancer (ALB)TLS-terminating entry point; security group restricted to accept traffic only from the CloudFront distribution in front of it
CloudFront (CDN)Public entry point for the application, providing TLS termination at the edge and absorbing traffic before it reaches the ALB
AWS WAFWeb application firewall filtering common attack patterns before requests reach the application
NAT gatewayProvides private-subnet resources with outbound internet access without exposing them to inbound connections
Private EC2 application host (no public IP)The application server cannot be reached directly from the public internet; all inbound traffic is mediated by CloudFront and the ALB
RDS PostgreSQL 16 (private subnet)Managed relational database, isolated in a private subnet, storage encrypted at rest, deletion protection enabled, 7-day automated backup retention
Encrypted EBS data volumeBlob and file storage, encrypted at rest, with a snapshot lifecycle for recovery
AWS Secrets ManagerApplication and per-user/per-firm secrets are stored and retrieved from a dedicated secrets service rather than configuration files or source code
VPC Flow LogsNetwork flow logs sent to CloudWatch, retained 30 days, supporting network-level monitoring and investigation

No inbound SSH. No stack accepts direct SSH connections. Operational shell access, when needed, is performed exclusively through AWS Systems Manager Session Manager, which is identity-based, requires AWS IAM authorization, and is logged by AWS.

Segregation between customers. Because each firm's stack is a fully separate VPC, database instance, and application host, there is no shared compute or shared database boundary between customers to misconfigure. Segregation is structural (separate AWS resources), not solely logical (row-level access control within a shared database).

3. Data Protection

4. Identity and Access Management

Sign-in methods. Email and password, secure single-use email link ("magic link"), Google sign-in, and Microsoft sign-in. A single account may hold multiple verified email addresses.

Two-factor authentication. Coming soon. Time-based one-time password (TOTP) authenticator apps and SMS-based codes are planned as the supported second factors; until release, the secure email link provides inbox-verified sign-in.

Provisioning. Accounts are provisioned by invitation: firms and their members are staged and invited rather than self-registering, with the exception of the self-serve bookkeeping product and accepting a pending team invitation, both of which support self-serve sign-up.

Firm roles and permissions. Each firm defines roles for its team members, with per-resource sharing grants layered on top so specific clients, files, or projects can be scoped to specific people beyond their base role. Every firm is required to retain at least one owner at all times.

Least privilege for AI agents. AI agents do not have standing write access. Actions that change data are represented as proposals that a human team member must approve before they take effect. A time-limited "elevation" exists for specific, trusted, pre-approved flows, scoped in time and function rather than granted permanently.

Client portal isolation. Client and contact sessions are locked to a single client record. A client portal user can see only the files, signature requests, forms, and bookkeeping data their firm has explicitly shared with them, and cannot browse other clients' data or the firm's internal workspace.

Group-less operator model. An operator who works across multiple firms does not "switch workspaces" with a single session-scoped permission set. Instead, every request is checked server-side against that individual's actual current memberships, so access reflects real-time membership rather than a session that could go stale.

Engineer access. Bitment engineers do not have standing SSH access to any customer environment. Operational access, when required, is through AWS Systems Manager Session Manager only, and is bounded by AWS IAM policy.

Diagnostics / impersonation. By accepting the Terms of Service and using the Services, a customer authorizes Bitment support and engineering personnel to access the customer's account and workspace, including by viewing the Services as a specific Authorized User, solely to diagnose and resolve issues, provide support, and maintain security. Bitment limits this access to what is necessary for those purposes. An individual user may additionally control this access through the in-product Diagnostics setting in their account, and may revoke it at any time. Current limitation, stated honestly: this access does not currently generate its own dedicated audit log entry. This is a known gap and is on our roadmap to close.

Permission audit limitation, stated honestly: Bitment currently records who granted each specific permission at the time it was granted. A complete, queryable history of every permission change over time (a full "who changed what, when" audit log) is a planned enhancement, not yet available. We do not represent that Bitment maintains a full audit trail of every data interaction today.

5. AI Governance

6. Application Security

7. Logging and Monitoring

8. Backup and Recovery

9. Vulnerability and Incident Management

10. Vendor and Subprocessor Management

The table below lists services that may process data on Bitment's or a firm's behalf, the category of data involved, and the hosting region where known. Entries marked "firm-connected" are used only if and when a specific firm chooses to connect them.

SubprocessorData categoryRegionTrigger
Amazon Web ServicesAll hosted infrastructure, application data, storageUnited StatesAlways (core infrastructure)
GoogleEmail, calendar, task dataUnited States / Google's global infrastructureFirm-connected
MicrosoftEmail, calendar dataUnited States / Microsoft's global infrastructureFirm-connected
SlackTeam messagesUnited StatesFirm-connected
SignalLinked-device messagesNot applicable (end-to-end messaging service)Firm-connected
TelegramLinked messagesTelegram's global infrastructureFirm-connected
TwilioCall and SMS content, recordings, transcripts, carrier registration dataUnited StatesUsed when the firm uses a Bitment-provisioned phone number
Quo (OpenPhone)Call and SMS contentUnited StatesFirm-connected, firm's own account
Fireflies.aiMeeting audio and transcriptsUnited StatesFirm-connected, firm's own account
AsanaProject and task dataUnited StatesFirm-connected
Intuit QuickBooks OnlineAccounting dataUnited StatesFirm-connected
Wolters Kluwer CCH AxcessTax software dataUnited StatesFirm-connected, firm's own account
PlaidBank transaction and statement dataUnited StatesFirm-connected
AnthropicAI prompts and attachmentsUnited StatesFirm-connected, firm's own credential
AWS BedrockAI prompts and attachmentsUnited StatesFirm-connected, firm's own credential
OpenRouterAI prompts and attachmentsUnited StatesFirm-connected, firm's own credential
Amazon TranscribeAudio for transcriptionUnited StatesUsed with voice-to-text and transcription features
TavilySearch queriesUnited StatesFirm-connected, optional
People Data LabsProspecting/contact dataUnited StatesFirm-connected, firm's own key
StripeBilling and payment data for AI usageUnited StatesUsed with paid AI usage
Whop, Zaprite, Maverick PaymentsPayment processing dataUnited StatesFirm-connected
Apple Push Notification serviceDevice push tokensUnited States / Apple's global infrastructureUsed to deliver push notifications
Web Push services (browser vendors)Device push tokensVaries by browser vendorUsed to deliver push notifications
AWS SESTransactional email contentUnited StatesAlways (platform email delivery)
AWS SNSSMS content for 2FA codesUnited StatesWill be used with SMS two-factor authentication once released

Vendor-specific compliance documentation is available on request.

11. Business Continuity

12. Data Lifecycle

13. Compliance Mapping

Bitment's controls map to the following frameworks and regulatory concerns. SOC 2 audit in progress; the other rows describe how Bitment supports a customer's own compliance program and are not certifications.

Control areaRelated SOC 2 Trust Services CriteriaNotes
Network isolation, WAF, encrypted transport and storageSecurityPer-firm dedicated stacks, TLS, encryption at rest
Automated backups, snapshot lifecycleAvailability7-day RDS backups, EBS snapshots
Role-based access, resource grants, client portal isolationConfidentiality, SecurityLeast-privilege access model
AI proposal/approval workflow, permission-gated toolsProcessing IntegrityHuman-in-the-loop for data-changing AI actions
Customer-controlled deletion, firm deletion cascadePrivacyUser- and firm-initiated data lifecycle controls

For accounting and tax firms specifically: Bitment's architecture, including per-firm network isolation, encryption practices, and access controls, is intended to support a customer firm's own compliance obligations, including those arising under the Gramm-Leach-Bliley Act Safeguards Rule and the practices described in IRS Publication 4557 (Safeguarding Taxpayer Data). Bitment does not itself certify compliance with GLBA or Publication 4557 on a firm's behalf; each firm remains responsible for its own compliance program, of which Bitment's platform is one component.

14. Responsible Disclosure

If you believe you have discovered a security vulnerability affecting Bitment, please report it to contact@bitment.co. Please include enough detail to reproduce the issue and avoid accessing or modifying data beyond what is necessary to demonstrate it. We ask that you give us a reasonable period to investigate and remediate before any public disclosure.

Bitment will not pursue legal action against researchers who act in good faith, avoid privacy violations and service disruption, and give Bitment reasonable time to remediate a reported issue. We will acknowledge a report within 5 business days.

Contact

For security or compliance questions related to this document, contact:

Bitment Inc. contact@bitment.co 1521 Concord Pike, Suite 201, Wilmington, DE 19803