Skip to content
Create account
BBN · RC 803010

Trust Center

Who can touch your data, where it is processed, how the platform is built, and exactly which compliance claims we can and cannot make. Written by the people who operate bbnsms.com, and kept current rather than aspirational.

Subprocessors

The complete list of third parties that process customer personal data on our behalf, and the region each one processes in. We give 30 days’ notice before adding a new one — write to [email protected] to be told when this list changes.

Stripe

Subprocessor

Card top-ups and hosted Checkout

Email address, top-up amount and currency, payment reference. Card numbers are entered on Stripe's own page and never reach our servers.

Region
United States · European Union
Entity
Stripe, Inc. / Stripe Payments Europe, Ltd.

Platfone

Subprocessor

OTP activations — temporary numbers and inbound codes

Country, service and the activation identifier. No email address, no wallet balance, no payment data.

Region
Supplier infrastructure · numbers in the country you select
Entity
OTP activation supply

Telnyx

Subprocessor

Dedicated US and Canada numbers with inbound SMS

Number search filters, the E.164 number provisioned, and the inbound message bodies delivered to your account.

Region
United States · Canada
Entity
Telnyx LLC

Hetzner

Subprocessor

Infrastructure — application, PostgreSQL, Redis and logs

Everything the platform stores: accounts, the wallet ledger, order history and request logs.

Region
HEL1 · Helsinki, Finland (EU/EEA)
Entity
Hetzner Online GmbH

Primary hosting is Hetzner’s HEL1 region in Helsinki, Finland. The application, the PostgreSQL database, Redis and the request logs all stay in that region; there is no second copy of the database anywhere else. The company behind it, Browser Based Nigeria Limited (RC 803010), is registered at Plot 12 Road 6, Lekki County Homes, Ikota Villa Estate, Lekki, Lagos, Nigeria.

How the platform is built

Six properties of the system as it runs today. Each one is a statement about code in production, not an intention.

Credentials

Passwords are hashed with Argon2id and cannot be read back. Sessions ride on HttpOnly, Secure cookies with a short-lived access token and a rotating refresh token.

Transport

The site and the API are served over TLS only, with HTTP redirected to HTTPS at the edge. Certificates are issued and renewed automatically.

An append-only ledger

The wallet balance is the sum of an immutable ledger. The database itself refuses updates and deletes on those rows, so every credit and debit can be replayed and reconciled.

Idempotent money paths

Top-ups and order placement carry an idempotency key, so a retried request cannot double-charge a wallet or double-provision a number.

Isolation and secrets

Application, PostgreSQL and Redis run as separate containers on hardware we control. Secrets live in the environment on the host, never in the repository and never in a client bundle.

Abuse controls

Authentication and order endpoints are rate limited by IP and by account. Numbers we provision are for lawful verification and messaging only, as the terms set out.

Incidents and status

We do not run a public status page yet. It is on the roadmap below. Until it exists, the honest answer is that you email [email protected] and a person at BBN tells you what is happening.

If a personal data breach affects your account we notify you by email, at the address on the account, without undue delay and within 72 hours of becoming aware of it. Where we act as your processor, that notice carries what Article 33(3) requires — the nature of the breach, the categories and approximate number of records affected, the likely consequences and the measures taken — so that you can meet your own notification duty.

A degradation that is not a data breach — a supplier outage, OTP delivery failing in one country, a webhook backlog — is answered on the same mailbox, and orders affected by it settle back to the wallet.

Report a vulnerability

Send it to [email protected] with SECURITY in the subject. Tell us what you found, how to reproduce it, and the impact you believe it has. We acknowledge within two business days and tell you what we are doing about it.

Test against your own account only. No denial-of-service traffic, no accessing or modifying another customer’s data, and a reasonable window to fix the issue before you publish it. Research conducted in good faith inside those limits is welcome and we will not pursue action over it.

We do not run a paid bounty programme. We will credit you by name in the fix if you want us to.

Compliance, honestly

What we hold, what we are working on, and what we do not have. The last row is the one most vendors leave off their trust page.

  • In place

    GDPR / UK GDPR Article 28 terms

    A written processor agreement is published and applies to every account — see the DPA.

  • In place

    Standard Contractual Clauses for transfers

    The EU SCCs (Commission Implementing Decision 2021/914) and the UK International Data Transfer Addendum are incorporated by the DPA for data leaving the EEA or the UK.

  • In place

    Nigeria Data Protection Act 2023

    Browser Based Nigeria Limited is a Nigerian company and processes personal data under the NDPA.

  • In progress

    Documented internal security policies

    Access control, change management, backup and incident response written down and reviewed on a schedule, rather than held as practice.

  • Planned

    Public status page and independent penetration test

    A status page for platform and supplier incidents, and a third-party test of the API and the web application with the summary available to customers on request.

  • Not held

    SOC 2 Type II · ISO/IEC 27001

    We hold neither certification, and we do not display a badge we have not earned. If either is a procurement requirement for you today, tell us before you buy.

Certification is slow and expensive, and buying a badge early would say more about a marketing budget than about the platform. What we can give you today is this page, the data processing agreement, a named legal entity you can look up at the Corporate Affairs Commission (RC 803010), and a company that has been reachable under the same name since 2008.

Security review before you buy

Send your questionnaire, your own DPA, or a list of questions to [email protected]. We answer what is true, and say so plainly where the answer is no.