Security overview
Last updated: 5 October 2026
This page is a short summary. The Security Pack has the detail.
Drafts first, a human publishes
Every change that bernard or an AI assistant makes goes to a private draft. A change goes live when a person approves it, or when the owner has switched on automatic routine fixes for that site.
No unreviewed code
bernard removes new scripts from pages. The exceptions are a short list of vetted libraries that bernard permits, and the owner’s own code after the owner approves it. An AI assistant never writes JavaScript into a page.
Encryption
We encrypt data in transit with TLS. The file system that holds site history is encrypted with an AWS KMS key. Stored email bodies are encrypted with a customer-managed AWS KMS key. Published files, media and uploads in Amazon S3 are encrypted at rest with server-side AES-256 encryption. The database is held by Supabase, which encrypts all customer data at rest with AES-256.
Row-level security
Row-level security in the database limits each user to the data of their own account. One business cannot read another business’s records.
Two-step sign-in
bernard operators sign in to the admin application with a password and a second factor. Customers can turn on two-step sign-in with an authenticator app in their account settings.
What we do not claim
bernard holds no SOC 2 report, no ISO 27001 certificate and no Cyber Essentials certificate, and has not commissioned a penetration test.