Security & Data Practices
Protecting connected service operations
This page describes BG Flow’s current security and data-handling approach during closed beta. It is a practical overview, not a security certification or a promise that every risk can be eliminated.
Access and company separation
BG Flow uses authenticated accounts, company membership, role-based permissions, and company-level data controls to limit access to authorized people and the company records they are permitted to use. Subscriber companies manage their own active employees, roles, and Field access.
BG Flow does not intentionally expose one subscriber company’s records to another subscriber company. Platform access used for onboarding or support is restricted to authorized BG Flow personnel and is intended to be auditable.
Technical and operational safeguards
Current safeguards include encrypted transport, restricted server-side credentials, protected connected-service tokens, authorization checks, security and audit records, and controls for account suspension and session revocation. Sensitive server credentials are not shipped to the public browser application.
BG Flow relies on established cloud infrastructure to host and operate the service. Access rules and product security are reviewed as the platform changes. No internet-connected service can guarantee absolute security or uninterrupted availability.
Connected services
A company Owner or Admin must authorize supported connected services such as QuickBooks Online. BG Flow stores only the provider identifiers, encrypted authorization material, synchronization status, and audit information needed to maintain the connection and perform deliberate supported actions.
Connected services remain governed by their own terms, security practices, and availability. Authorized users can disconnect a supported integration through BG Flow.
Data continuity and exports
BG Flow maintains subscriber records and protected backups as described in the Privacy Policy. Retention and recovery needs can vary by record type and service provider. During closed beta, companies should continue retaining any independent records required for legal, accounting, safety, or business-continuity purposes.
Authorized subscriber Owners may request assistance with supported data access, correction, or export. Identity and company authority may need to be verified before account-level requests are fulfilled.
Subscriber responsibilities
Companies are responsible for choosing authorized users, assigning appropriate roles, removing access when employment or duties change, protecting their devices and passwords, and entering business and customer information lawfully. Users should never share passwords or send passwords, access tokens, or payment-card numbers to BG Flow by email.
Security concerns and incidents
Suspected unauthorized access, exposed credentials, or other security concerns should be reported promptly to customer.support@bgflowsystems.com. Include the company name, affected account or record reference, and a concise description, but do not email secrets or payment-card data.
