Data Security & Privacy
This page focuses on the security specific questions.
By Company
Does the BDB Platform allow the admin to configure user access at the company level?

By Department/Division
Does the BDB Platform allow the admin to configure user access at the department or division level?

By Menu
Does the BDB Platform allow the admin to configure user access by Menu?

By Function
Does the BDB Platform allow the admin to configure user access by Function?

By Dimension
Does the BDB Platform allow the admin to configure user access by Dimension?

By Dimension Value
Does the BDB Platform allow the admin to configure user access by Dimension Value?

By Measure
Does the BDB Platform allow the admin to configure user access by Measure?

Describe the user audit logging capabilities of the system. For example, can audit logs be configured to show user logins, queries, data sources accessed, modifications to reports/dashboards, etc?

Is the BDB Platform equipped with security features at the visualization, functional, and data levels?
Does the system support user based data access control? Please describe how the system can support creation of a single dashboard where the data presented is based on the access granted to the individual, logged in, user.
How can data access be regulated in a multi-tenant deployment to ensure full data privacy among tenants?
How does the system support SSO?
Does the system have the ability to share certain dashboards based on role / user profile, ability to provide read only access, ability to share dashboards with external users?
Does the system have any tools/capabilities that will assist in supporting privacy standards (GDPR, CCPA, HIPAA, ISO 27001, HITRUST, PCI Level 1/2, SOC2)? Please describe the certifications supported and related privacy risk assessment practices.
What security vulnerability scanning tools were utilized during product development, and how often are the rules and checks updated?
Please describe if the system has been impacted in any recent Global Security Vulnerabilities? If yes, what was the turn around time to fix and provide an updated release to address the vulnerabilities?
What certifications does The BDB data centres that host customer data have (SOC2, ISO, etc.)?
What PII data lives within the BDB Platform?
What type of roles does the BDB platform have for the users?
How are secrets managed by the BDB Platform application?
Does the BDB platform have a concept of admin user?
Does the BDB platform have a concept of service principal for service-to-service integration?
Does the BDB platform provide a console where all users & service principals can be managed?

How often does the BDB Platform perform sec-pen testing of its solution?
Can BDB Platform share an attestation from system last run?
Last updated