Trust, security + compliance

Last reviewed: 26 May 2026

Everything procurement, legal, and security teams need to evaluate BIGM, in one place. Only what is shipping today + the dated roadmap. No marketing-grade compliance claims.

Compliance posture

StandardStatusTarget / Notes
GDPRCompliantDPA + sub-processor list available below. EU data residency on request.
GDPR Article 28 (Processor)Attestation availableSelf-attested today. Independent audit attestation post-SOC 2.
CCPACompliantForget-me endpoint live. See privacy policy.
SOC 2 Type ICustomer-drivenAudit engagement starts when the first paid pilot's procurement requires it. Estimated 6-8 weeks to point-in-time report once scoped with Vanta or Drata.
SOC 2 Type IICustomer-drivenObservation period starts after Type I sign-off (12 months minimum). Gates Enterprise tier.
ISO 27001ActiveAccelerates with first EU Enterprise customer requirement.
Saudi PDPLDPA addendum availableStandard PDPL controller-processor mapping + cross-border (Art. 29) terms on request from oguz@bigm.live.
UAE PDPL + ADGM/DIFCDPA addendum availableUAE Federal PDPL + ADGM Data Protection 2021 / DIFC DP Law addenda on request. Free zone data residency active.
Saudi NDMOActiveData classification + handling guidance for Open / Restricted tiers in active development. Accelerates with first KSA Enterprise interest.
HIPAA / FedRAMPNot pursuingOut of scope for current ICP. Tell us if this changes the decision.

Regional compliance — GCC (UAE + Saudi)

BIGM serves UAE + Saudi B2B lead-gen agencies and Turkish manufacturers selling into the Gulf. We have specific compliance posture for the region rather than treating "global" as a default.

Available today
  • Saudi PDPL DPA addendum: standard processor terms + Article 29 cross-border transfer clauses, signable PDF
  • UAE Federal PDPL DPA addendum: processor terms + DIFC / ADGM-specific clauses available per zone
  • EU residency: Supabase eu-west-1 (Frankfurt) for any GCC customer who prefers EU over US
  • Arabic + RTL content: persona engine handles MSA + Khaleeji register for outbound (see Arabic evidence on agency page)
  • Sender warm-up + cooldown calendars: Sunday-Thursday default for GCC pools, Friday-Saturday suppression
GCC roadmap (active development)
  • GCC data residency (AWS me-south-1, Bahrain): active development, accelerates with first Saudi government-adjacent Enterprise interest. Tell us if hard requirement now.
  • Saudi NDMO data classification handling: Open / Restricted tier handling guidance in active development.
  • ADGM / DIFC free-zone data residency: demand-driven, ships with first regulated customer.
  • SDAIA AI-system registration: shipped on first SDAIA-regulated client signing.
  • Government-domain exclusion lists (.gov.sa, .gov.ae, .mil.sa): available today, default on for Saudi pools.

If your client is government-adjacent (Vision 2030 contractor, KSA ministry vendor, ADNOC supplier, etc.) and the procurement questionnaire requires NDMO data classification handling or KSA-region hosting today, send the questionnaire to oguz@bigm.live before pilot. We'll answer truthfully against current posture and commit to specific delivery dates for any gap.

For a Saudi CISO questionnaire — direct answer

Q: Where does BIGM host Saudi-resident PII today? A: Until AWS me-south-1 (Bahrain) deployment lands (on the roadmap; contractual ETA available on request for procurement teams that need a signed commitment), Saudi-resident PII sits in Supabase eu-west-1 (Frankfurt, Germany) for customers who opt out of the US-East default. Documented in the PDPL DPA addendum under Article 29 cross-border transfer clauses with EU SCCs (2021, modules 2 and 3) applied as supplementary measures. Customers requiring strict in-region hosting before me-south-1 lands can request priority provisioning or pilot on a non-PDPL-scope dataset.

If a roadmap item is a hard requirement for you to sign, email oguz@bigm.live before pilot. We'll commit to a specific ETA in writing or refer you elsewhere. We'd rather lose the deal honestly than ship you something we don't have.

Data Processing Agreement (DPA)

BIGM acts as Data Processor under GDPR Article 28 for customer data (lead lists, reply transcripts, attribution events). The standard DPA terms below apply to every customer by default regardless of tier. Redacted, signable PDF (PDPL + GDPR Article 28 Annex III with all GCC addenda) available via the form below.

Request the redacted DPA PDF (PDPL + GDPR Article 28)

For procurement / legal teams. Manually delivered by Oğuz within one business day. Counter-signed PDF available on contract finalization.

Standard DPA terms (summary)

  • Roles: Customer = Data Controller. BIGM = Data Processor. Sub-processors (listed below) = Sub-processors under BIGM's responsibility.
  • Purpose limitation: Customer data processed solely to deliver outbound sequences, persona generation, reply triage, and attribution reporting per the Master Services Agreement. No secondary use, no model training on customer data without explicit opt-in.
  • Confidentiality: All BIGM personnel and sub-processors are under written confidentiality obligations.
  • Security measures: Encryption in transit (TLS 1.2+) and at rest (AES-256). Role-based access controls. Audit logs retained 12 months. See "Security measures" section below.
  • Sub-processor changes: 30 days written notice before adding a new sub-processor. Customer may object; if BIGM cannot accommodate, customer may terminate without penalty.
  • Data subject requests: BIGM forwards any direct DSAR within 5 business days. Self-service forget-me endpoint at /api/forget-me for end-users.
  • Personal data breach notification: BIGM notifies Customer within 72 hours of confirmed breach affecting Customer data, with scope, root cause, and remediation steps.
  • International transfers: EU customer data stored in eu-west-1 (Frankfurt) on request. Standard Contractual Clauses (SCCs, 2021): module 2 applied for controller-to-processor flows (Customer to BIGM where applicable), module 3 applied for processor-to-processor flows (BIGM to extra-EEA sub-processors).
  • Audit rights: Customer may audit BIGM's compliance once per 12-month period with 30 days written notice. SOC 2 Type II report (when issued) accepted in lieu of on-site audit.
  • Return + deletion: On contract termination, BIGM returns or deletes all Customer data within 90 days. Anonymized aggregate analytics retained for sector statistics.
  • Liability: Per Master Services Agreement. Not capped below the customer's annual fees.
  • Governing law: Customer's jurisdiction by default. Negotiable.

Sub-processors

Every third party that touches your data, what they do, and where they store it. We do not add a sub-processor without 30 days' written notice. This list is the canonical source; any change updates the "Last reviewed" date at the top.

Sub-processorPurposeData locationStatus
SupabasePrimary database (leads, replies, attribution events)eu-west-1 (Frankfurt) for EU customers, us-east-1 defaultSOC 2 Type II
UnipileLinkedIn / WhatsApp / Instagram messaging APIEU (France)GDPR-compliant
ElevenLabsVoice agent for phone replies + voicemailsus-east, EU multi-regionSOC 2 Type II
ResendTransactional + nurture email deliveryus-east-1 + EU regionsSOC 2 Type II
RenderApplication hosting (Next.js, edge functions)us-west-1, EU region on requestSOC 2 Type II
CloudflareCDN, DDoS protection, Turnstile bot preventionGlobal edge (no PII at rest)ISO 27001 + SOC 2
OpenAIPer-prospect message rewriting (zero-retention API)us, no training on customer data (API tier)SOC 2 Type II
AnthropicReply triage + intent classificationus, no training on customer data (API tier)SOC 2 Type II
Plausible AnalyticsCookieless pageview analytics (no PII)EU (Germany)GDPR-compliant
CalendlyAudit-call booking (email + meeting time only)us-eastSOC 2 Type II
Microsoft ClarityAnonymized session recordings + heatmaps for UX improvement (IP-anonymized; no PII)Global (Microsoft Azure)SOC 2 + ISO 27001

Security measures

Encryption

  • TLS 1.2+ in transit (HSTS, no mixed content)
  • AES-256 at rest (Supabase, S3)
  • Secrets in environment variables, never committed
  • Per-customer encryption keys on Enterprise (post-SOC 2)

Access controls

  • Role-based access at the database row level (RLS)
  • 2FA required on all employee accounts
  • Least-privilege principle for sub-processor API keys
  • Quarterly access review (BIGM + sub-processors)

Audit + monitoring

  • Application logs retained 90 days
  • Database audit logs retained 12 months
  • Resend email-event log per customer (open/click/bounce)
  • Cloudflare WAF + anomaly alerts

Incident response

  • 72-hour breach notification per GDPR Art. 33
  • On-call rotation: Oğuz (primary), Umur (secondary)
  • Runbook + postmortem within 5 business days
  • Sub-processor incident escalation chain documented

Data lifecycle

Vendor security questionnaire

Most of what your security team asks is on this page. For everything else, BIGM responds to standard questionnaires:

Send to oguz@bigm.live with your timeline. SOC 2 Type II report (when issued) will short-circuit most of this.

Security + privacy contact

  • Security disclosures + incident reports: security@bigm.live
  • DPA + sub-processor + vendor questionnaire requests: oguz@bigm.live
  • Privacy + data-subject requests: press@bigm.live
  • Self-service deletion: POST /api/forget-me with your email + unsubscribe token