5 MCP servers live now What’s live ›
Real Biz Digital logo Real Biz Digital

Security & Trust · Reviewed 20 August 2026

Barzel sits between an agent and your systems. Here is exactly what that means.

This page is written for the person who has to sign off. It states our certification status without softening it, describes how credentials and data are handled, and says who answers when something breaks. If a question you need answered is not here, ask and we will answer it in writing.

Certification status

We are not certified against any of these standards today

Real Biz Digital is a young company shipping infrastructure. Our products are engineered around the control objectives these frameworks describe, and we have not paid for an audit that would let us claim more than that. The distinction matters to you, so we draw it ourselves.

Framework Status today What is actually true
SOC 2 Type II Not certified No examination has been performed and no report exists. BarzelVault and Barzel Central Gateway are built around the same control objectives an audit would test — least-privilege access, change control, append-only audit logging, monitoring and alerting — and we can walk a reviewer through each one. That is evidence of design, not an attestation.
ISO 27001 Not certified No certificate. Our internal information-security practices are organised along ISO 27001 lines so that a future certification is an audit rather than a rebuild. Certification is on the roadmap and is not funded yet.
GDPR Compliant posture We act as a data processor for customer content and as a controller for our own business records. Lawful basis, data-subject rights, breach notification and subprocessor disclosure are documented in the privacy policy, and a signed data processing agreement is available on request.
OWASP MCP / LLM Top 10 Design checklist Used as an engineering checklist rather than a badge. Prompt injection, tool poisoning, excessive agency, supply-chain risk in third-party MCP servers and insecure output handling each map to a specific control in BarzelVault, and each is written up publicly in our Insights guides.

If your procurement process requires a completed SOC 2 Type II report or an ISO 27001 certificate to proceed, we do not meet that bar yet and will tell you so on the first call rather than the fifth.

Corroboration

We have no badges. Here is what you can check without us.

A page like this one is a company vouching for itself, which is worth exactly nothing on its own. So rather than ask you to trust the paragraphs above, here are the things a reviewer can verify from outside — on infrastructure we do not control, without a call with us, and without our permission.

Call one yourself, now A public endpoint, no signup Barzel Scripture Intelligence is live at scripture-intelligence-server.mcpize.run with no account and no key. Point a client at it, call tools/list, and compare the 54 tools it reports against the number we publish. That is the cheapest possible test of whether this company ships what it says.
Third-party hosted Five listings on a marketplace we do not run Every product is published on MCPize, whose pages we cannot edit at will, and those listings are in turn indexed by third-party MCP directories we have no control over. Surface counts, tiers and prices are stated there and repeated here; if the two ever disagree, the listing is right and we are wrong.
Primary sources Standards claims link to the standard Where we describe protocol or framework behaviour — MCP, JSON-RPC 2.0, the OWASP top tens — we cite the source rather than paraphrase it, so you can check our reading against theirs. Our developer docs hold the technical detail.
Written record Dated, and previous versions on request This page carries a review date and changes before any marketing page claims a new status. Ask for what it said six months ago and we will send it. A vendor whose security claims quietly improve without a diff is telling you something.

What you will not find here

No logos, no testimonials, no manufactured proof

This page carries no customer logos, no pull-quotes and no analyst badges, and that is deliberate. Every one of those is easy to produce and impossible for you to check, which makes them worth less than the four things above that you can verify yourself in a few minutes.

If where we are with customers and references matters to your evaluation — and for a security review it reasonably might — ask on the first call. You will get a direct answer to a direct question, on the call, rather than a page engineered to leave an impression.

Credential model

Secrets are configuration, never context

The single largest risk in agent infrastructure is a credential that ends up somewhere a model can read it. Four rules govern this, and they are architectural rather than procedural.

01 Never in the model context Credentials for connected systems are held as server-side configuration. They are not placed in prompts, tool descriptions, resource bodies or anything else a model can read, so no prompt-injection payload can exfiltrate what the model was never shown.
02 Never in the audit record Audit entries reference a credential by identifier and scope, not by value. A complete audit export can be handed to a reviewer without rotating a single secret.
03 Scoped to the action, not the agent Permission is evaluated per requested action against the policy set, so an agent holding a broad token still cannot execute an operation outside the policy that matched. Authorisation is a decision at call time, not a grant at setup time.
04 Yours to rotate and revoke You supply the credentials and you can rotate or withdraw them at any time without our involvement. Revocation takes effect on the next call; there is no cached grant that outlives it.

Data handling and retention

What we hold, why, and for how long

Data Purpose Retention
Connected-system credentials To execute the calls you authorise Held until you rotate or delete them. Removed on account closure.
Policy and approval configuration To evaluate what agents may do Held for the life of the account, versioned so a past decision can be explained.
Action and approval audit records Evidence of what was requested, decided and executed Append-only. Retained for the period you configure; default twelve months, exportable at any time.
Operational logs and metrics Availability, debugging, abuse prevention Thirty days, then deleted. No customer payloads are written to operational logs.
Contact and enquiry details To answer you Held while the conversation is live and for twenty-four months after, then deleted. Never sold or shared.
Training Your data does not train anything We do not train models on customer content, and we do not sell, rent or share it. Barzel governs calls to model providers you choose; it does not build a corpus of its own.
GDPR Processor, with a DPA on request For customer content we act as processor and you remain controller. A signed data processing agreement, including subprocessor list and international transfer terms, is available before you send us anything. See also the privacy policy.
Deletion Ask and it goes Write to us and we will delete your configuration, credentials and audit records within thirty days, and confirm in writing when it is done. Audit records can be exported first so your own retention obligations survive the deletion.

Availability and support

Who answers at three in the morning

The honest answer is a small team, not a follow-the-sun rota. Here is what that means in practice, and what happens if we are unreachable.

Support Email, answered by the people who built it Every enquiry reaches the founder and the engineer responsible for the product concerned. Target first response is one business day, and same-day for anything blocking production. Paid tiers carry the response commitments stated on their marketplace listing; we do not promise a tighter number here than we can hold.
Failure mode Barzel fails closed If the governance layer cannot reach its policy set, it denies rather than permits. An outage stops sensitive agent actions; it does not silently wave them through. That is the correct default for a product whose job is to say no, and it is the design decision we would defend hardest.
Subprocessors Named, and you are told before they change The current subprocessor list — hosting, transactional email and the marketplace that handles billing — is provided with the data processing agreement. Additions are notified in advance, and a material objection is grounds to terminate without penalty.
Transport TLS in flight, encrypted at rest All product traffic is served over HTTPS. Barzel speaks MCP over Streamable HTTP using JSON-RPC 2.0, so it drops into an existing client without a bespoke transport. Configuration and audit stores are encrypted at rest by the hosting platform.

Coordinated disclosure

Found something? We would rather hear it from you.

Good-faith research on our own products and this website is welcome. We have no bug bounty budget; we do have credit, a fast reply and a written fix timeline.

In scope Our five published MCP servers, this website, and any Real Biz Digital endpoint you reached from them.
Out of scope Denial of service, social engineering of our people or customers, physical access, and third-party platforms we merely list on.
Our commitment Acknowledgement within two business days, a triage verdict within five, no legal action for research within scope, and credit if you want it.
Where to send it securityrealbizdigital.net Reproduction steps, affected endpoint, and how you would like to be credited.

For your reviewer

Questions we will answer in writing, in one business day

Send your own questionnaire if you have one. If you do not, these are the questions worth asking any vendor in this position, and we will answer them specifically rather than in marketing language.

  • Which of our systems would Barzel hold credentials for, and at what scope?
  • What exactly is written to an audit record, and can we see a real example?
  • Where is our configuration and audit data hosted, in which region?
  • What happens to in-flight agent actions during an outage or a rollback?
  • How do we export everything and leave, and how long does that take?
  • Who is the named human accountable for a security incident?

This page is reviewed quarterly and dated at the top. When our certification status changes, this table changes first — before any marketing page claims it.