Security
Your BBDC login is the most sensitive thing you give us, so here is exactly how it's protected.
Encryption
Your BBDC username and password are encrypted with AES-256-GCM before they're ever written to our database. The encryption key is held as a deployment secret and is never stored in the database itself — so a database read alone can never yield your plaintext credentials.
Write-only in the app
Once saved, your BBDC password is never shown back to you, or to anyone, in the Customer Portal — only a masked "saved" indicator is displayed.
Replacing your credentials
If you submit a new BBDC login (e.g. after changing your BBDC password), it's re-encrypted and re-verified from scratch — a failed replacement leaves your current verified login active, so a typo or a bad new password can never lock you out of monitoring.
Consent-gated
Your credentials are only ever submitted after you've given explicit Credential Consent for that specific submission — see the Terms of Service and Privacy Policy for what that authorizes.
Questions about this? Reach out via Contact.