Trust, security + compliance
Last reviewed: 26 May 2026
Everything procurement, legal, and security teams need to evaluate BIGM, in one place. Only what is shipping today + the dated roadmap. No marketing-grade compliance claims.
Compliance posture
| Standard | Status | Target / Notes |
|---|---|---|
| GDPR | Compliant | DPA + sub-processor list available below. EU data residency on request. |
| GDPR Article 28 (Processor) | Attestation available | Self-attested today. Independent audit attestation post-SOC 2. |
| CCPA | Compliant | Forget-me endpoint live. See privacy policy. |
| SOC 2 Type I | Customer-driven | Audit engagement starts when the first paid pilot's procurement requires it. Estimated 6-8 weeks to point-in-time report once scoped with Vanta or Drata. |
| SOC 2 Type II | Customer-driven | Observation period starts after Type I sign-off (12 months minimum). Gates Enterprise tier. |
| ISO 27001 | Active | Accelerates with first EU Enterprise customer requirement. |
| Saudi PDPL | DPA addendum available | Standard PDPL controller-processor mapping + cross-border (Art. 29) terms on request from oguz@bigm.live. |
| UAE PDPL + ADGM/DIFC | DPA addendum available | UAE Federal PDPL + ADGM Data Protection 2021 / DIFC DP Law addenda on request. Free zone data residency active. |
| Saudi NDMO | Active | Data classification + handling guidance for Open / Restricted tiers in active development. Accelerates with first KSA Enterprise interest. |
| HIPAA / FedRAMP | Not pursuing | Out of scope for current ICP. Tell us if this changes the decision. |
Regional compliance — GCC (UAE + Saudi)
BIGM serves UAE + Saudi B2B lead-gen agencies and Turkish manufacturers selling into the Gulf. We have specific compliance posture for the region rather than treating "global" as a default.
- Saudi PDPL DPA addendum: standard processor terms + Article 29 cross-border transfer clauses, signable PDF
- UAE Federal PDPL DPA addendum: processor terms + DIFC / ADGM-specific clauses available per zone
- EU residency: Supabase eu-west-1 (Frankfurt) for any GCC customer who prefers EU over US
- Arabic + RTL content: persona engine handles MSA + Khaleeji register for outbound (see Arabic evidence on agency page)
- Sender warm-up + cooldown calendars: Sunday-Thursday default for GCC pools, Friday-Saturday suppression
- GCC data residency (AWS me-south-1, Bahrain): active development, accelerates with first Saudi government-adjacent Enterprise interest. Tell us if hard requirement now.
- Saudi NDMO data classification handling: Open / Restricted tier handling guidance in active development.
- ADGM / DIFC free-zone data residency: demand-driven, ships with first regulated customer.
- SDAIA AI-system registration: shipped on first SDAIA-regulated client signing.
- Government-domain exclusion lists (.gov.sa, .gov.ae, .mil.sa): available today, default on for Saudi pools.
If your client is government-adjacent (Vision 2030 contractor, KSA ministry vendor, ADNOC supplier, etc.) and the procurement questionnaire requires NDMO data classification handling or KSA-region hosting today, send the questionnaire to oguz@bigm.live before pilot. We'll answer truthfully against current posture and commit to specific delivery dates for any gap.
Q: Where does BIGM host Saudi-resident PII today? A: Until AWS me-south-1 (Bahrain) deployment lands (on the roadmap; contractual ETA available on request for procurement teams that need a signed commitment), Saudi-resident PII sits in Supabase eu-west-1 (Frankfurt, Germany) for customers who opt out of the US-East default. Documented in the PDPL DPA addendum under Article 29 cross-border transfer clauses with EU SCCs (2021, modules 2 and 3) applied as supplementary measures. Customers requiring strict in-region hosting before me-south-1 lands can request priority provisioning or pilot on a non-PDPL-scope dataset.
If a roadmap item is a hard requirement for you to sign, email oguz@bigm.live before pilot. We'll commit to a specific ETA in writing or refer you elsewhere. We'd rather lose the deal honestly than ship you something we don't have.
Data Processing Agreement (DPA)
BIGM acts as Data Processor under GDPR Article 28 for customer data (lead lists, reply transcripts, attribution events). The standard DPA terms below apply to every customer by default regardless of tier. Redacted, signable PDF (PDPL + GDPR Article 28 Annex III with all GCC addenda) available via the form below.
Standard DPA terms (summary)
- Roles: Customer = Data Controller. BIGM = Data Processor. Sub-processors (listed below) = Sub-processors under BIGM's responsibility.
- Purpose limitation: Customer data processed solely to deliver outbound sequences, persona generation, reply triage, and attribution reporting per the Master Services Agreement. No secondary use, no model training on customer data without explicit opt-in.
- Confidentiality: All BIGM personnel and sub-processors are under written confidentiality obligations.
- Security measures: Encryption in transit (TLS 1.2+) and at rest (AES-256). Role-based access controls. Audit logs retained 12 months. See "Security measures" section below.
- Sub-processor changes: 30 days written notice before adding a new sub-processor. Customer may object; if BIGM cannot accommodate, customer may terminate without penalty.
- Data subject requests: BIGM forwards any direct DSAR within 5 business days. Self-service forget-me endpoint at
/api/forget-mefor end-users. - Personal data breach notification: BIGM notifies Customer within 72 hours of confirmed breach affecting Customer data, with scope, root cause, and remediation steps.
- International transfers: EU customer data stored in eu-west-1 (Frankfurt) on request. Standard Contractual Clauses (SCCs, 2021): module 2 applied for controller-to-processor flows (Customer to BIGM where applicable), module 3 applied for processor-to-processor flows (BIGM to extra-EEA sub-processors).
- Audit rights: Customer may audit BIGM's compliance once per 12-month period with 30 days written notice. SOC 2 Type II report (when issued) accepted in lieu of on-site audit.
- Return + deletion: On contract termination, BIGM returns or deletes all Customer data within 90 days. Anonymized aggregate analytics retained for sector statistics.
- Liability: Per Master Services Agreement. Not capped below the customer's annual fees.
- Governing law: Customer's jurisdiction by default. Negotiable.
Sub-processors
Every third party that touches your data, what they do, and where they store it. We do not add a sub-processor without 30 days' written notice. This list is the canonical source; any change updates the "Last reviewed" date at the top.
| Sub-processor | Purpose | Data location | Status |
|---|---|---|---|
| Supabase | Primary database (leads, replies, attribution events) | eu-west-1 (Frankfurt) for EU customers, us-east-1 default | SOC 2 Type II |
| Unipile | LinkedIn / WhatsApp / Instagram messaging API | EU (France) | GDPR-compliant |
| ElevenLabs | Voice agent for phone replies + voicemails | us-east, EU multi-region | SOC 2 Type II |
| Resend | Transactional + nurture email delivery | us-east-1 + EU regions | SOC 2 Type II |
| Render | Application hosting (Next.js, edge functions) | us-west-1, EU region on request | SOC 2 Type II |
| Cloudflare | CDN, DDoS protection, Turnstile bot prevention | Global edge (no PII at rest) | ISO 27001 + SOC 2 |
| OpenAI | Per-prospect message rewriting (zero-retention API) | us, no training on customer data (API tier) | SOC 2 Type II |
| Anthropic | Reply triage + intent classification | us, no training on customer data (API tier) | SOC 2 Type II |
| Plausible Analytics | Cookieless pageview analytics (no PII) | EU (Germany) | GDPR-compliant |
| Calendly | Audit-call booking (email + meeting time only) | us-east | SOC 2 Type II |
| Microsoft Clarity | Anonymized session recordings + heatmaps for UX improvement (IP-anonymized; no PII) | Global (Microsoft Azure) | SOC 2 + ISO 27001 |
Security measures
Encryption
- TLS 1.2+ in transit (HSTS, no mixed content)
- AES-256 at rest (Supabase, S3)
- Secrets in environment variables, never committed
- Per-customer encryption keys on Enterprise (post-SOC 2)
Access controls
- Role-based access at the database row level (RLS)
- 2FA required on all employee accounts
- Least-privilege principle for sub-processor API keys
- Quarterly access review (BIGM + sub-processors)
Audit + monitoring
- Application logs retained 90 days
- Database audit logs retained 12 months
- Resend email-event log per customer (open/click/bounce)
- Cloudflare WAF + anomaly alerts
Incident response
- 72-hour breach notification per GDPR Art. 33
- On-call rotation: Oğuz (primary), Umur (secondary)
- Runbook + postmortem within 5 business days
- Sub-processor incident escalation chain documented
Data lifecycle
- Collection: Customer uploads lead lists + ICP definition. BIGM never scrapes or buys lists on the customer's behalf.
- Processing: Per-prospect rewriting via OpenAI zero-retention API. Reply triage via Anthropic zero-retention API. No customer data used for model training.
- Retention: Active customer data retained for the contract duration. End-user forget-me requests honored within 5 business days via
/api/forget-me. - Termination: Full customer data export available on request within 30 days of contract end. Hard deletion within 90 days. Anonymized aggregate stats retained for sector benchmarks.
Vendor security questionnaire
Most of what your security team asks is on this page. For everything else, BIGM responds to standard questionnaires:
- CAIQ Lite (Cloud Security Alliance)
- SIG Lite + SIG Core
- Custom questionnaires (5-7 day turnaround)
Send to oguz@bigm.live with your timeline. SOC 2 Type II report (when issued) will short-circuit most of this.
Security + privacy contact
- Security disclosures + incident reports: security@bigm.live
- DPA + sub-processor + vendor questionnaire requests: oguz@bigm.live
- Privacy + data-subject requests: press@bigm.live
- Self-service deletion:
POST /api/forget-mewith your email + unsubscribe token