Security & Trust · Reviewed 20 August 2026
Barzel sits between an agent and your systems. Here is exactly what that means.
This page is written for the person who has to sign off. It states our certification status without softening it, describes how credentials and data are handled, and says who answers when something breaks. If a question you need answered is not here, ask and we will answer it in writing.
Certification status
We are not certified against any of these standards today
Real Biz Digital is a young company shipping infrastructure. Our products are engineered around the control objectives these frameworks describe, and we have not paid for an audit that would let us claim more than that. The distinction matters to you, so we draw it ourselves.
| Framework | Status today | What is actually true |
|---|---|---|
| SOC 2 Type II | Not certified | No examination has been performed and no report exists. BarzelVault and Barzel Central Gateway are built around the same control objectives an audit would test — least-privilege access, change control, append-only audit logging, monitoring and alerting — and we can walk a reviewer through each one. That is evidence of design, not an attestation. |
| ISO 27001 | Not certified | No certificate. Our internal information-security practices are organised along ISO 27001 lines so that a future certification is an audit rather than a rebuild. Certification is on the roadmap and is not funded yet. |
| GDPR | Compliant posture | We act as a data processor for customer content and as a controller for our own business records. Lawful basis, data-subject rights, breach notification and subprocessor disclosure are documented in the privacy policy, and a signed data processing agreement is available on request. |
| OWASP MCP / LLM Top 10 | Design checklist | Used as an engineering checklist rather than a badge. Prompt injection, tool poisoning, excessive agency, supply-chain risk in third-party MCP servers and insecure output handling each map to a specific control in BarzelVault, and each is written up publicly in our Insights guides. |
If your procurement process requires a completed SOC 2 Type II report or an ISO 27001 certificate to proceed, we do not meet that bar yet and will tell you so on the first call rather than the fifth.
Corroboration
We have no badges. Here is what you can check without us.
A page like this one is a company vouching for itself, which is worth exactly nothing on its own. So rather than ask you to trust the paragraphs above, here are the things a reviewer can verify from outside — on infrastructure we do not control, without a call with us, and without our permission.
scripture-intelligence-server.mcpize.run with no account and no key. Point a client at it, call tools/list, and compare the 54 tools it reports against the number we publish. That is the cheapest possible test of whether this company ships what it says.
What you will not find here
No logos, no testimonials, no manufactured proof
This page carries no customer logos, no pull-quotes and no analyst badges, and that is deliberate. Every one of those is easy to produce and impossible for you to check, which makes them worth less than the four things above that you can verify yourself in a few minutes.
If where we are with customers and references matters to your evaluation — and for a security review it reasonably might — ask on the first call. You will get a direct answer to a direct question, on the call, rather than a page engineered to leave an impression.
Credential model
Secrets are configuration, never context
The single largest risk in agent infrastructure is a credential that ends up somewhere a model can read it. Four rules govern this, and they are architectural rather than procedural.
Data handling and retention
What we hold, why, and for how long
| Data | Purpose | Retention |
|---|---|---|
| Connected-system credentials | To execute the calls you authorise | Held until you rotate or delete them. Removed on account closure. |
| Policy and approval configuration | To evaluate what agents may do | Held for the life of the account, versioned so a past decision can be explained. |
| Action and approval audit records | Evidence of what was requested, decided and executed | Append-only. Retained for the period you configure; default twelve months, exportable at any time. |
| Operational logs and metrics | Availability, debugging, abuse prevention | Thirty days, then deleted. No customer payloads are written to operational logs. |
| Contact and enquiry details | To answer you | Held while the conversation is live and for twenty-four months after, then deleted. Never sold or shared. |
Availability and support
Who answers at three in the morning
The honest answer is a small team, not a follow-the-sun rota. Here is what that means in practice, and what happens if we are unreachable.
Coordinated disclosure
Found something? We would rather hear it from you.
Good-faith research on our own products and this website is welcome. We have no bug bounty budget; we do have credit, a fast reply and a written fix timeline.
For your reviewer
Questions we will answer in writing, in one business day
Send your own questionnaire if you have one. If you do not, these are the questions worth asking any vendor in this position, and we will answer them specifically rather than in marketing language.
- Which of our systems would Barzel hold credentials for, and at what scope?
- What exactly is written to an audit record, and can we see a real example?
- Where is our configuration and audit data hosted, in which region?
- What happens to in-flight agent actions during an outage or a rollback?
- How do we export everything and leave, and how long does that take?
- Who is the named human accountable for a security incident?
This page is reviewed quarterly and dated at the top. When our certification status changes, this table changes first — before any marketing page claims it.