Security at BizPilot
How we protect your business, your team and your data.
LAST UPDATED · SEPTEMBER 2026
Encryption
All traffic is encrypted in transit with TLS (HTTPS-only). Sensitive credentials and tokens are stored hashed or encrypted at rest.
Access control
Every account uses role-based permissions — owners, managers and staff each see only what their role allows. Multi-tenant isolation ensures one business can never access another's data.
Authentication
Passwords are stored using industry-standard hashing (bcrypt). Sessions use signed, expiring tokens. Brute-force protections limit repeated failed logins.
Payments
Card details are processed and stored by Stripe, a PCI-DSS Level 1 provider. BizPilot never sees or stores full card numbers.
Infrastructure
BizPilot runs on managed, access-controlled cloud infrastructure with automated monitoring, audit logging of sensitive actions, and regular backups.
Responsible disclosure
Found a vulnerability? Email security@bizpilot.com.au — we investigate every report promptly and appreciate responsible disclosure.
Questions? Contact us via the contact page.
