Security & trust
We tell you exactly where every standard stands — what's evidence-mapped, what's in progress, and how your data is handled. We never claim a certification we don't hold.
Compliance standing
Our controls are evidence-mapped to ISO 27001, 45001 and 22301, plus SOC 2 and PCI DSS v4 — shown here as evidence mapping, never as certifications.
- ISO/IEC 27001Live
Information-security controls evidence-mapped to ISO/IEC 27001.
- ISO 45001Live
Occupational health-and-safety controls evidence-mapped to ISO 45001.
- ISO 22301Live
Business-continuity controls evidence-mapped to ISO 22301.
- SOC 2Live
Trust-services controls evidence-mapped to SOC 2.
- PCI-DSSLive
Cardholder-data controls evidence-mapped to PCI DSS v4.
Security architecture
- Tokens signed with RS256; passwords hashed with Argon2id.
- Data encrypted with AES-256-GCM at rest.
- Integration credentials sealed with KMS envelope encryption.
- SSO (SAML/OIDC) and SCIM provisioning with location-scoped roles.
- Tamper-evident e-signature and right-to-erasure handling.
Data handling & residency
Encrypted in transit and at rest
All traffic is served over TLS; data is encrypted at rest with AES-256-GCM.
Regional data residency
Production data is hosted in-region where required; residency options are confirmed during enterprise onboarding.
Right to erasure
Tenant and personal data can be erased on request, with retention floors applied only where the law requires them.
Least-privilege access
Access is governed by SSO, SCIM provisioning and location-scoped roles, with every privileged action recorded.
Subprocessors
Third parties that process data on our behalf. The full product list is maintained in our Data Processing Agreement.
- Vercel
Hosting and content delivery for this marketing site.
- Resend
Transactional email delivery for demo and contact requests.
Responsible disclosure
Found a vulnerability? Report it to our security team and we'll acknowledge your report, keep you updated, and credit you once it's resolved. Please give us reasonable time to remediate before any public disclosure.
security@belrald.comBring your assets and operations onto one platform
Request early access — and we'll help you onboard when it's your turn, or see it on your own assets in a 30-minute walkthrough first.
We review every request and email approved teams an invite.

