---
title: "BluBees Trust Center — Governing Index (BB-GOV-001)"
canonical: "https://doc.blubees.ai/space/blubeesdoc/191791105/BluBees%20Trust%20Center%20%E2%80%94%20Governing%20Index%20(BB-GOV-001)"
format: markdown
---
> Macro (toc)

| Field | Detail |
| --- | --- |
| Document ID | BB-GOV-001 |
| Version | 6.0.1 |
| Status | [Published] |
| Effective Date | 23 Mar 2026, as amended 27 Aug 2026 |
| Owner | BluBees LLC — Security / Compliance |
| Classification | Public |
| Applies To | BluBees Cloud and BluBees AGC |
| Trust Center | [https://blubees.ai/trustcenter/](https://blubees.ai/trustcenter/) |

## 1. Purpose and Structure

This document is the **governing index** of the BluBees compliance document family. The family follows a **single-statement principle**: each fact is stated once, in exactly one canonical document, and every other document refers to that canonical source rather than reproducing it.

The current version of every document listed below is published at [https://blubees.ai/trustcenter/](https://blubees.ai/trustcenter/). **The complete document family was published effective 27 Aug 2026.**

## 2. Overview

BluBees LLC provides an AI-powered workflow automation application operating within the Atlassian ecosystem as a Forge-based application, offered in two deployment editions — **BluBees Cloud** and **BluBees AGC**. The service's Pass-Through Data architecture, the categories of data BluBees does and does not store, and all data-handling commitments are defined in the Data Processing Addendum.

## 3. Fact Ownership Map

| Topic | Canonical Source |
| --- | --- |
| Deployment editions (definitions, hosting environments, AGC availability) | Terms of Service §1.5 and §27 |
| Plan tiers, entitlements, limits, pricing, support entitlements | Editions Comparison and Pricing |
| Technical support process, channels, and incident priority classification | Terms of Service §1.3 and Annex A |
| Umbrella privacy notice; controller-capacity processing; no-website/no-tracking statement | Privacy Policy |
| Data categories stored and not stored (incl. Pass-Through Data) | Data Processing Addendum §§1, 3 |
| Purpose of processing; processing requirements, documented instructions, records of processing; controller/processor roles | Data Processing Addendum §§4–6 |
| Subprocessors (list, notice, objection process, full liability) | Data Processing Addendum §7 |
| Data subject request assistance (SLAs) | Data Processing Addendum §11 |
| Audit rights and conditions (paid Subscribers) | Data Processing Addendum §13 |
| Data retention, deletion, and disposal; return election (paid Subscribers) | Data Processing Addendum §§16–17 |
| International data transfers (SCC Module Two; UK IDTA; AGC no-transfer covenant) | Data Processing Addendum §12 |
| Technical and organizational security measures (contractual) | Data Processing Addendum Schedule 2 |
| Liability for data processing claims (Art. 82; Supervisory Authority fines; Remaining-Term Cap; free-tier rule) | Data Processing Addendum §21 (routed from Terms of Service §15.4) |
| Countersigned-DPA policy (U.S. Government customers) | Terms of Service §32.4 (execution instrument: DPA Countersign Template) |
| Government-customer modifications (renewal, indemnities, publicity, law/venue/fees) | Government Customer Addendum (incorporated per Terms of Service §1.6) |
| Security architecture, infrastructure, encryption, logging, vulnerability management, reliability/status page, data residency, Atlassian trust programs, shared responsibility | Security Overview |
| AGC technical content (FedRAMP context, GovCloud residency, NIST SP 800-53 alignment, AGC architecture, AGC support channels) | Security Overview §12 |
| Access control lifecycle (approval, review, revocation) | Access Control Policy |
| Incident response process and all notification timelines (72-hour customer; FedRAMP IR-6 federal) | Security Incident Response Outline |
| Recovery Time / Recovery Point Objective commitments | Security Incident Response Outline §5 |
| Backup and disaster recovery detail (layered architecture; cadence; retention) | Backup & Disaster Recovery Overview |
| Vulnerability reporting scope and channels, researcher safe harbour, response timelines, coordinated disclosure | Responsible Disclosure Policy |
| GDPR commitments, lawful bases, data subject rights and request process | GDPR Compliance and Privacy Policy |
| U.S. state privacy rights | U.S. Privacy Notice |
| CCPA/CPRA commitments and applicability assessment | CCPA Compliance Statement; CCPA Non-Applicability Notice |
| AI-Enabled Features, the current AI provider list, and the AI no-training commitment | Terms of Service §5.5 |
| Publicity and logo use (incl. opt-out and government-customer carve-out) | Terms of Service §10 |
| Assignment; refund upon provider breach; material-change termination right | Terms of Service §§29–31 |
| Government use, AGC eligibility, FISMA/ATO, federal law supremacy | Terms of Service §32 |
| Security research authorization (contractual carve-out) | Terms of Service §4.2 and Annex B (framework: Responsible Disclosure Policy) |
| Legal terms (license, fees, term, warranty, liability, governing law, defined terms) and company contact/address | Terms of Service (contact: §33) |
| Acceptable use | Terms of Service Annex B |

## 4. Document Family Index

**Governance:** BluBees Trust Center (this document — governing index)

**Legal:** Terms of Service (including Support Annex A and AUP Annex B) · Editions Comparison and Pricing · Government Customer Addendum

**Privacy & Compliance:** Privacy Policy · Data Processing Addendum · DPA Countersign Template (U.S. Government customers) · GDPR Compliance and Privacy Policy · U.S. Privacy Notice · CCPA Compliance Statement · CCPA Non-Applicability Notice

**Security:** Security Overview · Security & Privacy Summary (pointer index) · Access Control Policy · Security Incident Response Outline · Backup & Disaster Recovery Overview · Responsible Disclosure Policy

**Architecture & Transparency:** System Architecture and Data Flow · Data Classification & Storage Map · Data Handling Principles

**Security Review Support:** Security Questionnaire Cheat Sheet

All public documents are published at the Trust Center effective 27 Aug 2026 (the Responsible Disclosure Policy was published 20 Aug 2026). Internal documents (the Divergence & Open Items Log and the Security Incident Response Plan) are not published; the Security Incident Response Plan is available to authorized reviewers upon request via security@blubees.ai.

## 5. DORA (Digital Operational Resilience Act)

BluBees acknowledges that certain EU-based customers may be subject to DORA (Regulation (EU) 2022/2554). BluBees is prepared to cooperate with customers to support their applicable DORA obligations. Customers requiring DORA-specific documentation or contractual terms may contact privacy@blubees.ai.

## 6. Contact

Legal: legal@blubees.ai · Security: security@blubees.ai · Privacy: privacy@blubees.ai · Sales: sales@blubees.ai · Support: support@blubees.ai  
BluBees LLC | 10845 W Griffith Peak Dr, Suite 200, Las Vegas, NV 89135

## 7. Document History

| Version | Date | Changes |
| --- | --- | --- |
| 3.0 | 23 Mar 2026 | Baseline public Trust Center (BluBees Cloud only). |
| 4.0–5.5 DRAFT | 17 Jul – 20 Aug 2026 | Goldfinger family architecture; single-statement restructure; all alignment items closed. |
| 6.0 | 27 Aug 2026 | PUBLISHED per owner approval. Complete public document family (20 documents) published effective 27 Aug 2026. |
| 6.0.1 | 27 Aug 2026 | Trust Center URL updated to https://blubees.ai/trustcenter/ per owner direction. No other changes. |

> 📝 © BluBees LLC | BB-GOV-001 v6.0.1 | Effective 23 Mar 2026, as amended 27 Aug 2026 | Trust Center: [https://blubees.ai/trustcenter/](https://blubees.ai/trustcenter/)  
> 📝 BluBees LLC | 10845 W Griffith Peak Dr, Suite 200, Las Vegas, NV 89135 | Nevada, USA