We use essential cookies to keep the site secure and functional. With your consent, we also run session recording and analytics (Microsoft Clarity and Google Analytics 4) and load fonts from Google. See our Cookie Policy for full details.
How we protect your data and maintain the integrity of the BI Method platform.
Last updated: 24 April 2026
The BI Method platform is hosted on Supabase, which runs on Amazon Web Services infrastructure in the EU (eu-west-1). All data is stored and processed within the European Economic Area, satisfying UK GDPR and EU GDPR data residency requirements.
All communication between your browser and our servers is encrypted using TLS 1.2 or higher. HTTP connections are automatically redirected to HTTPS. We enforce HSTS (HTTP Strict Transport Security) to prevent downgrade attacks.
All database data and stored files are encrypted at rest using AES-256, managed by Supabase's underlying AWS infrastructure. Encryption keys are managed by AWS KMS and are rotated automatically.
User passwords are never stored in plaintext. They are hashed using bcrypt (via Supabase Auth) with a minimum cost factor of 10. We enforce a minimum password length and maintain a password history to prevent reuse of recent passwords.
Access to data is governed by Row Level Security (RLS) policies enforced at the database layer. No application code can bypass these policies — every query runs as the authenticated user and is subject to their permission set.
Direct database access by BI Method staff requires multi-factor authentication and is logged in an immutable audit trail. We operate on a need-to-know basis and review access rights quarterly.
The platform uses Supabase Auth, which implements industry-standard authentication practices:
In accordance with UK GDPR Article 32, we implement the following organisational measures:
We maintain a documented incident response plan. In the event of a data breach or security incident:
We welcome reports of security vulnerabilities from security researchers and the broader community. If you discover a potential vulnerability, please:
We will acknowledge your report within 72 hours and keep you informed of our progress. We do not currently offer a bug bounty programme, but we recognise responsible disclosures publicly if you consent.
Questions about our security practices? Contact us at security@behaviourintelligenceplatform.com.