STAR Registry Listing for
BPS CA
BPS CA
BPS CA is a cloud-native, multi-tenant SaaS platform built for secure enterprise resource planning (ERP) and accounting. Designed with a defense-in-depth approach to tenant isolation, it provides businesses with high-performance financial tooling backed by rigorous data residency and encryption controls.
Core Security Capabilities:
Strict Tenant Isolation: Data segregation is enforced at the database layer via PostgreSQL Row-Level Security (RLS) and at the object storage layer via strict programmatic prefix boundaries.
Resilient Infrastructure: Primary workloads are hosted on Oracle Cloud Infrastructure (OCI) in Hyderabad. Disaster recovery archives are AES-256-CBC encrypted and stored offsite in AWS S3 to meet rigorous RPO (≤24h) and RTO (≤8h) targets.
Identity & Access Management: Application access is secured using Argon2id password hashing and email OTP, with mandatory Time-Based One-Time Password (TOTP) Authenticator MFA enforced for all administrative and elevated access roles.
Network Security: Backend data services (PostgreSQL and MinIO) are bound to loopback interfaces and strictly isolated within internal container networks behind host-level firewalls.
Continuous Validation: Code releases are gated by automated CI/CD pipelines incorporating dependency vulnerability blocking, automated tenant-isolation integration tests, and end-to-end assertions.

Listed Since: 09/14/2026
STAR Level 1

CAIQ Self-assessment v4.0.3
Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No/NA questions and space to justify the response a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM).
Created or renewed about 18 hours ago, on September 14, 2026.