Trust · Security
Security
Security is part of the product, not an afterthought to it. BlueCollarIntel handles information that businesses and professionals rely on, and we design our systems, our processes, and our program to keep that information protected, available, and trustworthy. This page describes how.
01Our approach
We run a security program with defined ownership and regular review. Our controls are designed around recognized industry frameworks and the principle of least privilege, and they are applied across our infrastructure, our applications, and our operations. We treat security as a continuous practice: we monitor, we test, we learn from what we find, and we improve.
02Protecting data
We encrypt data in transit using current TLS standards, and we encrypt data at rest. Access to production data is restricted to the systems and personnel that require it, and secrets and keys are managed through dedicated, access-controlled services rather than embedded in code or configuration.
03Access control
Access within the Services is governed by permissions, and a record is kept of what was accessed. Internally, access to systems and data follows least privilege: it is granted by role, scoped to what a task requires, reviewed periodically, and revoked when no longer needed. Administrative access requires strong authentication.
04Infrastructure
The Services run on established cloud infrastructure with the physical, network, and environmental protections those providers maintain. Our infrastructure is defined and provisioned as code, so that changes are reviewed, consistent, and repeatable, and deployments are automated and keyless where possible to reduce the handling of long-lived credentials.
05Evidence and record integrity
The Services are built on evidence, and the integrity of that evidence is a security concern in its own right. Each material item carries its source, its state, its known limits, the access rules that apply to it, and its history. Records are resolved to the correct business against a review threshold, ambiguous matches are routed for human review, and changes are retained so a record’s history can be examined.
No outcome is reported without evidence. Where an item is not established, it is marked as unknown rather than inferred, a safeguard against confident but unsupported conclusions.
06Monitoring and logging
We log activity across our systems and monitor for anomalies and signs of abuse. Logs support detection, investigation, and the access history that the Services depend on, and they are retained for the periods needed to operate and secure the Services.
07Vulnerability management
We keep our dependencies and systems current, apply security updates on a risk-prioritized basis, and use automated checks in our development and deployment process to catch issues before they reach production. Significant changes are reviewed before release.
08Secure development
Changes to the Services go through version control and review before deployment. Security considerations are part of how features are designed and built, and automated tests and checks run as part of our pipeline so that regressions and known weaknesses are caught early.
09Resilience and continuity
We back up the data required to operate the Services and design our systems to recover from failure. We review our continuity practices so that we can restore service and data within objectives appropriate to the Services.
10People and vendors
Our people are the first line of security. Personnel receive security guidance appropriate to their role and access, and access is tied to that role. We assess the vendors that handle data on our behalf and hold them to obligations consistent with the protections described here.
11Incident response
We maintain a process for identifying, investigating, containing, and remediating security incidents. If an incident affects personal information or your data, we will notify affected parties and the relevant authorities as required by law and applicable agreements, and we will share what is known as an investigation allows.
12Compliance
Our handling of personal information is described in our Privacy Policy at blucollarintel.com/privacy, and our practices are designed to meet the requirements of the privacy and data-protection laws applicable to our operations in the United States and Canada. Additional detail about our controls is available to prospective and current customers under a confidentiality agreement.
14Reporting a vulnerability
We welcome reports from security researchers and users. If you believe you have found a vulnerability, contact us at security@blucollarintel.com with enough detail to reproduce it. We ask that you give us a reasonable opportunity to investigate and remediate before public disclosure, that you avoid accessing or altering data that is not yours, and that you do not degrade or disrupt the Services. We will acknowledge your report, work to resolve confirmed issues promptly, and will not pursue action against researchers who report in good faith and follow these guidelines.