Blackprint Legal

Blackprint Security Measures

Summary of technical and organisational measures protecting Customer Data.

Version 1.0·Effective 2026-06-14
Draft for legal review. These terms are structured for publication but must be reviewed by qualified counsel before your first client signature. Replace entity placeholders in lib/legal/meta.ts.

1. Overview

Blackprint applies a proportionate security programme appropriate for a B2B workflow and automation platform handling business operational data.

This page summarises key measures. Detailed security documentation may be provided under NDA for enterprise customers.

2. Access control

  • Role-based access within customer workspaces (admin, manager, contributor)
  • Tenant separation at the application and database layer
  • Least-privilege access for Blackprint personnel
  • Strong authentication for platform accounts

3. Encryption and transmission

  • TLS for data in transit between clients and the platform
  • Encrypted storage provided by infrastructure providers where supported
  • Secrets and API keys stored server-side, not exposed to end users

4. Operations and monitoring

  • Logging of authentication and administrative actions
  • Backups via managed database infrastructure
  • Controlled deployment pipeline for application changes
  • Incident response process for suspected security events

5. AI and automation security

  • Customer Data is not used to train public foundation models
  • AI requests are made server-side; API keys are not exposed in the browser
  • Automations run with permissions granted by the customer
  • Human approval expected before production reliance on high-impact outputs

6. Customer responsibilities

Customers control user provisioning, role assignment, uploaded content, and third-party integrations. Customers should use strong passwords, limit admin access, and revoke integrations that are no longer required.