Industry Leadership
Strategic Initiatives
CSA's strategic programs driving innovation in AI, cloud, and Zero Trust.
A public-interest 501(c)(3) dedicated to secure and trustworthy AI.




Industry Leadership
Strategic Initiatives
CSA's strategic programs driving innovation in AI, cloud, and Zero Trust.
A public-interest 501(c)(3) dedicated to secure and trustworthy AI.

CSAI FoundationChaptersEventsBlog
AI is changing fast. Behavioral security helps you keep up. Join Darktrace’s September 22 broadcast to see how →

STAR Registry Listing for

BPS CA

BPS CA

BPS CA is a cloud-native, multi-tenant SaaS platform built for secure enterprise resource planning (ERP) and accounting. Designed with a defense-in-depth approach to tenant isolation, it provides businesses with high-performance financial tooling backed by rigorous data residency and encryption controls.

Core Security Capabilities:

Strict Tenant Isolation: Data segregation is enforced at the database layer via PostgreSQL Row-Level Security (RLS) and at the object storage layer via strict programmatic prefix boundaries.

Resilient Infrastructure: Primary workloads are hosted on Oracle Cloud Infrastructure (OCI) in Hyderabad. Disaster recovery archives are AES-256-CBC encrypted and stored offsite in AWS S3 to meet rigorous RPO (≤24h) and RTO (≤8h) targets.

Identity & Access Management: Application access is secured using Argon2id password hashing and email OTP, with mandatory Time-Based One-Time Password (TOTP) Authenticator MFA enforced for all administrative and elevated access roles.

Network Security: Backend data services (PostgreSQL and MinIO) are bound to loopback interfaces and strictly isolated within internal container networks behind host-level firewalls.

Continuous Validation: Code releases are gated by automated CI/CD pipelines incorporating dependency vulnerability blocking, automated tenant-isolation integration tests, and end-to-end assertions.

Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No/NA questions and space to justify the response a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM).
Information about BPS CA
Listed Since: 09/14/2026

STAR Level 1

Cloud Controls Matrix

CAIQ Self-assessment v4.0.3

Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No/NA questions and space to justify the response a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM).

Created or renewed about 17 hours ago, on September 14, 2026.