BlueCollarIntel
PlatformDataIndustriesSolutions
Log In

Trust · Security

Security

Effective 17 July 2026

Security is part of the product, not an afterthought to it. BlueCollarIntel handles information that businesses and professionals rely on, and we design our systems, our processes, and our program to keep that information protected, available, and trustworthy. This page describes how.

On this page

  1. 01Our approach
  2. 02Protecting data
  3. 03Access control
  4. 04Infrastructure
  5. 05Evidence and record integrity
  6. 06Monitoring and logging
  7. 07Vulnerability management
  8. 08Secure development
  9. 09Resilience and continuity
  10. 10People and vendors
  11. 11Incident response
  12. 12Compliance
  13. 13Who else touches your data
  14. 14Availability and uptime
  15. 15Paperwork your legal team will ask for
  16. 16Your part
  17. 17Reporting a vulnerability

01Our approach

We run a security program with defined ownership and regular review. Our controls are designed around recognized industry frameworks and the principle of least privilege, and they are applied across our infrastructure, our applications, and our operations. We treat security as a continuous practice: we monitor, we test, we learn from what we find, and we improve.

02Protecting data

We encrypt data in transit using current TLS standards, and we encrypt data at rest. Access to production data is restricted to the systems and personnel that require it, and secrets and keys are managed through dedicated, access-controlled services rather than embedded in code or configuration.

03Access control

Access within the Services is governed by permissions, and a record is kept of what was accessed. Internally, access to systems and data follows least privilege: it is granted by role, scoped to what a task requires, reviewed periodically, and revoked when no longer needed. Administrative access requires strong authentication.

04Infrastructure

The Services run on established cloud infrastructure with the physical, network, and environmental protections those providers maintain. Our infrastructure is defined and provisioned as code, so that changes are reviewed, consistent, and repeatable, and deployments are automated and keyless where possible to reduce the handling of long-lived credentials.

05Evidence and record integrity

The Services are built on evidence, and the integrity of that evidence is a security concern in its own right. Each material item carries its source, its state, its known limits, the access rules that apply to it, and its history. Records are resolved to the correct business against a review threshold, ambiguous matches are routed for human review, and changes are retained so a record’s history can be examined.

No outcome is reported without evidence. Where an item is not established, it is marked as unknown rather than inferred, a safeguard against confident but unsupported conclusions.

06Monitoring and logging

We log activity across our systems and monitor for anomalies and signs of abuse. Logs support detection, investigation, and the access history that the Services depend on, and they are retained for the periods needed to operate and secure the Services.

07Vulnerability management

We keep our dependencies and systems current, apply security updates on a risk-prioritized basis, and use automated checks in our development and deployment process to catch issues before they reach production. Significant changes are reviewed before release.

08Secure development

Changes to the Services go through version control and review before deployment. Security considerations are part of how features are designed and built, and automated tests and checks run as part of our pipeline so that regressions and known weaknesses are caught early.

09Resilience and continuity

We back up the data required to operate the Services and design our systems to recover from failure. We review our continuity practices so that we can restore service and data within objectives appropriate to the Services.

10People and vendors

Our people are the first line of security. Personnel receive security guidance appropriate to their role and access, and access is tied to that role. We assess the vendors that handle data on our behalf and hold them to obligations consistent with the protections described here.

11Incident response

We maintain a process for identifying, investigating, containing, and remediating security incidents. If an incident affects personal information or your data, we will notify affected parties and the relevant authorities as required by law and applicable agreements, and we will share what is known as an investigation allows.

12Compliance

Our handling of personal information is described in our Privacy Policy at blucollarintel.com/privacy, and our practices are designed to meet the requirements of the privacy and data-protection laws applicable to our operations in the United States and Canada. Additional detail about our controls is available to prospective and current customers under a confidentiality agreement.

13Who else touches your data

We use a small number of established providers to run the service. Each one is reviewed before we bring it in and again on a regular cycle, each is bound by a written agreement covering confidentiality and data protection, and none of them is given more access than the job requires. The current list is below. We give notice before adding a provider that would process customer data, so you have time to object.

  • Google Cloud Platform — hosting, storage and databases, United States
  • Anthropic — model processing for analysis and drafting, United States
  • Stripe — payments and billing; card numbers never reach our systems
  • Resend — transactional email, such as invitations and alerts
  • Sentry — error monitoring, scrubbed of customer content

Ask us and we will put you on the notification list for changes to this page, so a new provider reaches your team without you having to check.

14Availability and uptime

The service runs across multiple zones with automated failover and continuous health checks. We publish a live status page and we post there during an incident rather than waiting for a full explanation, with the write-up following once we have one.

Target 99.9% monthly availability for the application and the API, measured excluding maintenance we have announced in advance.

Planned maintenance Announced at least five business days ahead and scheduled outside United States business hours wherever we can.

During an incident Status updates at least hourly until the service is restored, and a written account of what happened within five business days.

15Paperwork your legal team will ask for

Most of what a review needs is on this page. The documents below cover the rest, and we will complete your own security questionnaire if your process requires it rather than ours.

  • Data processing agreement, including the standard contractual clauses, sent on request and signable electronically
  • Our answers to the standard security questionnaires, available under a mutual NDA
  • Penetration test summary from our most recent assessment, under NDA
  • Certificate of insurance, including cyber liability

Write to security@blucollarintel.com for any of these. We answer within two business days, and we do not route document requests through a sales call.

16Your part

Security is shared. Protect your account by using strong, unique credentials, enabling any additional authentication we offer, limiting access to those who need it, and keeping your own devices and software up to date. Tell us promptly if you suspect your account has been compromised.

17Reporting a vulnerability

We welcome reports from security researchers and users. If you believe you have found a vulnerability, contact us at security@blucollarintel.com with enough detail to reproduce it. We ask that you give us a reasonable opportunity to investigate and remediate before public disclosure, that you avoid accessing or altering data that is not yours, and that you do not degrade or disrupt the Services. We will acknowledge your report, work to resolve confirmed issues promptly, and will not pursue action against researchers who report in good faith and follow these guidelines.

BlueCollarIntel

See what the market misses.

Product
  • Platform
  • Data
  • Industries
  • Solutions
Company
  • FAQ
  • Contact
  • Security
Account
  • Log In
© 2026 BlueCollarIntelPrivacy · Terms