Our Approach to Security
Security is integrated into every aspect of our operations. We maintain SOC 2 aligned security controls and continuously evaluate our practices against industry standards. Our commitment extends beyond compliance to building genuine trust with every client we serve.
Data Handling and Storage
- •Client data is processed only for the purposes outlined in service agreements
- •Data is stored in secure, access-controlled environments
- •We minimize data collection to what is necessary for service delivery
- •Data segregation practices ensure client information remains isolated
Access Control and Authentication
- •Role-based access controls limit data access to authorized personnel
- •Multi-factor authentication is required for access to sensitive systems
- •Access permissions are reviewed regularly and revoked promptly when no longer needed
- •Principle of least privilege is applied across all systems
Encryption Practices
- •Data is encrypted in transit using TLS 1.2 or higher
- •Sensitive data at rest is encrypted using industry-standard algorithms
- •Encryption keys are managed according to security best practices
Vendor and Third-Party Management
- •Third-party vendors are evaluated for security practices before engagement
- •We work with vendors who maintain their own security certifications where applicable
- •Vendor access is limited and monitored
- •Regular review of vendor relationships and security posture
Incident Response
- •Defined incident response procedures are in place
- •Security events are logged and monitored
- •Clients are notified of security incidents that affect their data in accordance with applicable requirements
- •Post-incident reviews are conducted to improve defenses
Business Continuity and Backups
- •Regular backups are performed to protect against data loss
- •Disaster recovery procedures are documented
- •Business continuity plans ensure service availability
- •Recovery procedures are tested periodically
Security Inquiries
For security-related questions or to request security documentation, please contact us:
Email: info@bafmin.com
Phone: (813) 419-6002
Security documentation is available to qualified prospects and clients under NDA. Visit our Trust Center for more information about our compliance posture.