Security
Security Posture
BGScreen handles consumer identifying information and consumer reports on behalf of FCRA customers. This page describes how that data is protected. It is a summary for technical and compliance reviewers evaluating the platform. A more detailed security questionnaire response is available on request to security@limelyte.com.
1. Hosting and data residency
The platform runs on enterprise cloud infrastructure operated in the United States. Customer and applicant data does not leave the U.S. region in the normal course of operation. Application services and background workers run on managed compute, the primary database is a managed relational store with encryption at rest, and files are held in encrypted, durable object storage. We do not publish details of the specific underlying services, so as not to enlarge the surface available to an attacker doing reconnaissance.
2. Encryption
In transit: all network connections use TLS 1.2 or higher. HSTS is enforced on the marketing and application origins. Internal traffic between services is also TLS-encrypted.
At rest: databases, object storage, and backups are encrypted with managed cloud encryption keys (AES-256). Applicant identifiers such as Social Security numbers and dates of birth are encrypted at the application layer as well. Secrets and credentials are stored in a managed secrets service, not in source code or in files committed to a repository.
3. Authentication and access control
People sign in with a session. Supported methods include email and password, and single sign-on. Multi-factor authentication is supported and may be required by the customer’s administrator. Software signs in with a short-lived access token issued under OAuth client credentials. API clients do not hold bureau or vendor passwords.
Authorization is role-based and scoped to the customer’s account. A user or API client can only see data that belongs to that account. Entitlement to products and permissible purpose are checked before any vendor call is made. Administrative actions are gated by role; sensitive actions are logged.
Limelyte personnel access to production systems is restricted to a small number of named operators, requires multi-factor authentication, is logged, and is reviewed quarterly. Access to customer or applicant data by Limelyte personnel is limited to incident response and support cases requested by the customer.
4. Multi-tenancy and data isolation
Every applicant file, order, report, and vendor exchange belongs to a single customer. Isolation is enforced at the data layer, not only in the application, so a query without a customer context cannot return data. Tenant identity is taken from the authenticated request, never from a field the caller supplies. There is no cross-customer sharing of applicant information or reports.
5. Vendor exchanges and audit logging
Every outbound call to a data vendor is recorded when the exchange finishes. The record includes the customer, the actor, the product, the permissible purpose, and timestamps. Once written, that record is not edited. It is the compliance trail for who pulled what, when, and why.
The application also records an audit log of meaningful user actions: sign-in, order placement, configuration change, and similar events, with actor, timestamp, and the resource affected. Audit logs are retained for the lifetime of the customer’s account and are available to administrators on request.
6. Vulnerability and dependency management
Production dependencies are scanned for known vulnerabilities on every build. High-severity findings are tracked and remediated according to severity. Operating-system base images for production containers are refreshed regularly. We follow responsible-disclosure practice with researchers who report findings to security@limelyte.com.
7. Backups and durability
The primary database is backed up daily with point-in-time recovery for the most recent retention window. Files are held in highly durable, cross-zone-replicated object storage. Backups are encrypted at rest and stored in the same U.S. region as the primary data.
8. Incident response
We maintain an incident-response procedure that defines severity levels, roles, communication paths, and customer-notification timelines. Confirmed incidents that affect a customer’s data are reported to the affected customer’s account administrator without undue delay, and in any event within the timeline required by applicable law.
9. Business continuity
Application services are deployed across multiple availability zones within a single region. Database backups support point-in-time recovery; file storage uses cross-zone-replicated object storage. Recovery procedures are exercised periodically.
10. People and process
Limelyte personnel sign confidentiality obligations on hire and complete security-awareness orientation. Access provisioning and de-provisioning follow a documented process. Changes to production systems flow through code review and a controlled deploy pipeline; production access is monitored and logged.
11. Subprocessors
The platform relies on a small number of subprocessors for hosting, email, and payments. A current list of subprocessors and their roles is available on request. We will notify account administrators of material changes to the subprocessor list.
12. Contact
Security reports, questionnaire requests, or vulnerability disclosures:
security@limelyte.com
Limelyte Technology Group, Inc.