BIChart Logo
BIChart

Supplier Code of Ethics

Aligned with BIChart's SOC 2 Type II Security Trust Services Criteria

Owner: BIChart Inc.

1. Purpose

BIChart maintains a SOC 2 Type II audited control environment designed to protect customer systems, data, and operations.

This Code of Ethics establishes mandatory standards of conduct supporting BIChart's obligations under the SOC 2 Trust Services Criteria for:

  • Security
  • Confidentiality
  • Governance
  • Risk Management
  • Accountability

All individuals and organizations acting on behalf of BIChart are required to comply with this Code.

2. Commitment to Integrity and Ethical Values

SOC 2 Alignment: CC1.1

BIChart operates under principles of honesty, integrity, and ethical business conduct.

Personnel and partners must:

  • Conduct business truthfully and transparently.
  • Avoid fraud, deception, or misrepresentation.
  • Accurately represent BIChart products, services, and capabilities.
  • Comply with contractual and legal obligations.

Unethical conduct may result in disciplinary or contractual action.

BIChart requires acknowledgment of ethical standards as part of onboarding and continued engagement.

3. Governance and Responsible Authority

SOC 2 Alignment: CC1.2, CC1.3

BIChart maintains defined organizational roles, responsibilities, and oversight mechanisms.

Individuals representing BIChart must:

  • Operate only within authorized responsibilities.
  • Follow approved engagement and contracting processes.
  • Escalate risks or concerns through designated management channels.
  • Avoid unauthorized commitments on behalf of BIChart.

Management oversight ensures ethical and operational accountability across all business activities.

4. Information Security and Confidentiality

SOC 2 Alignment: CC2.2, CC6

Protection of information assets is a core BIChart control requirement.

All personnel and partners must:

  • Protect customer and BIChart confidential information.
  • Access systems only when authorized.
  • Follow least-privilege access principles.
  • Safeguard credentials, tokens, and authentication mechanisms.
  • Prevent unauthorized disclosure or system access.

Confidential information includes:

  • Customer environments
  • Technical documentation
  • Pricing and commercial information
  • Product architecture
  • Migration artifacts and metadata

Security incidents or suspected compromise must be reported immediately.

BIChart maintains organization-wide information security policies governing system and data protection.

5. Data Protection and Acceptable Use

SOC 2 Alignment: CC6 Logical Access Controls

Users must:

  • Use BIChart systems solely for authorized business purposes.
  • Maintain secure handling of uploaded or processed data.
  • Avoid downloading, copying, or transferring data unnecessarily.
  • Follow approved access provisioning procedures.

Access privileges are granted based on role and revoked upon termination or role change.

6. Risk Management and Incident Reporting

SOC 2 Alignment: CC3, CC7

BIChart performs formal risk assessments and security monitoring processes.

All personnel and partners must:

  • Report suspected security, compliance, or ethical violations promptly.
  • Cooperate with investigations.
  • Support remediation activities when requested.
  • Avoid concealment of incidents or operational risks.

BIChart maintains defined incident response and escalation procedures supporting system security objectives.

7. Professional Conduct and Workplace Standards

SOC 2 Alignment: Control Environment

Individuals must maintain professional conduct including:

  • Respectful communication.
  • Non-discriminatory behavior.
  • Responsible collaboration with customers and partners.
  • Compliance with applicable laws and regulations.

Harassment, intimidation, or retaliation is prohibited.

BIChart promotes open communication and protection against retaliation for good-faith reporting.

8. Accountability and Enforcement

SOC 2 Alignment: CC1.5

BIChart holds individuals accountable for internal control responsibilities.

Violations of this Code may result in:

  • Corrective action
  • Suspension of access
  • Termination of employment or partnership
  • Contract termination
  • Legal action when necessary

Compliance with ethical and security policies is periodically reaffirmed.

9. Third-Party and Supplier Responsibilities

SOC 2 Complementary Controls

Suppliers, affiliates, and partners are considered complementary participants within BIChart's SOC 2 control environment.

Third parties must:

  • Maintain equivalent ethical and security standards.
  • Protect BIChart and customer data.
  • Follow contractual confidentiality obligations.
  • Notify BIChart of incidents affecting shared systems or data.

Failure to comply may result in termination of the business relationship.

10. Reporting Ethics or Security Concerns

Concerns may be reported to:

BIChart Compliance
support@bichart.ai

Reports made in good faith will not result in retaliation.

11. Acknowledgment

By working with or representing BIChart, individuals and organizations acknowledge adherence to this Code of Ethics and Business Conduct and agree to operate in alignment with BIChart's SOC 2 Type II control environment.