CBA Site Research
Security overview
Last updated: August 31, 2026 (revised)
This page summarizes current security practices for CBA Site Research. It is not a security guarantee, audit report, certification, or contractual service-level commitment. A signed customer agreement controls if it provides different security terms.
Identity and access
The Service uses authenticated accounts, time-limited sessions, and multi-factor verification flows to protect access. Administrative and other higher-risk actions may require additional verification. Company and team-workspace access is scoped to authorized memberships and roles.
Tenant isolation and data protection
Application authorization and database row-level security are designed to isolate organization data. Traffic is protected in transit with HTTPS. Project files are stored in private object storage and delivered through time-limited access mechanisms. Secrets are kept outside source control, and certain administrative and security-relevant events are recorded in an append-only audit trail.
Operations
We use structured logging, monitoring, deployment checks, dependency and code scanning to support the Service. Controls and configurations evolve with the product, risk profile, and applicable requirements.
Report a concern
Authenticated customers should use the Incident category in Support and avoid including exploit code, credentials, or sensitive client records in an initial report. For other security concerns, use the CBA contact page. CBA assesses reported incidents and provides notifications where required by applicable law or contract.
CBA Site Research is a service of Charlan, Brock & Associates, Inc.