Draft for internal review. Not yet in force.

Security overview

Last updated: 5 October 2026

This page is a short summary. The Security Pack has the detail.

Drafts first, a human publishes

Every change that bernard or an AI assistant makes goes to a private draft. A change goes live when a person approves it, or when the owner has switched on automatic routine fixes for that site.

No unreviewed code

bernard removes new scripts from pages. The exceptions are a short list of vetted libraries that bernard permits, and the owner’s own code after the owner approves it. An AI assistant never writes JavaScript into a page.

Encryption

We encrypt data in transit with TLS. The file system that holds site history is encrypted with an AWS KMS key. Stored email bodies are encrypted with a customer-managed AWS KMS key. Published files, media and uploads in Amazon S3 are encrypted at rest with server-side AES-256 encryption. The database is held by Supabase, which encrypts all customer data at rest with AES-256.

Row-level security

Row-level security in the database limits each user to the data of their own account. One business cannot read another business’s records.

Two-step sign-in

bernard operators sign in to the admin application with a password and a second factor. Customers can turn on two-step sign-in with an authenticator app in their account settings.

What we do not claim

bernard holds no SOC 2 report, no ISO 27001 certificate and no Cyber Essentials certificate, and has not commissioned a penetration test.

made with bernard