Big Bull Technologies, LLC v1.0.0 · Effective 20 July 2026

Access & Security

Authentication Policy

How Before the Call authenticates users, manages account access, and supports secure identity verification — so only authorized individuals reach Department information.

Document control

Document ID
SEC-001
Version
1.0.0
Status
Active
Classification
Public
Owner
Big Bull Technologies, LLC
Effective
20 July 2026
Next review
July 2027

01 Purpose

Big Bull Technologies, LLC (“Big Bull Technologies,” “BBT,” “we,” “our,” or “us”) is committed to protecting Customer accounts and administrative information through secure authentication practices.

This Authentication Policy explains how Before the Call (“B4C”) authenticates users, manages account access, and supports secure identity verification.

Authentication is one component of our broader security program and should be read together with our Security Overview and Data Security documentation.

02 Authentication Philosophy

Authentication exists to ensure that only authorized individuals are able to access Department information.

Our authentication controls are designed to:

  • Verify user identity
  • Protect Customer accounts
  • Reduce unauthorized access
  • Support role-based security
  • Improve overall platform integrity

Authentication methods may evolve as technology and security practices advance.

03 Authorized Users

Access to Before the Call is limited to Authorized Users approved by a subscribing organization.

Each Authorized User is responsible for maintaining the confidentiality of their account credentials.

Departments are responsible for managing user access within their organization.

04 Individual Accounts

Each Authorized User should maintain an individual account.

Shared accounts are discouraged except where specifically authorized by organizational policy and supported by the platform. Individual accounts improve:

  • Accountability
  • Audit history
  • Security
  • Administrative reporting
  • User management

05 Authentication Methods

Depending on platform capabilities and organizational settings, authentication may include:

  • Email and password
  • Magic links
  • One-time verification codes
  • Multi-Factor Authentication (MFA)
  • Device authentication
  • Enterprise authentication providers (future)
  • Other approved authentication methods

Available authentication options may vary by subscription level and platform capabilities.

06 Session Management

To protect Customer information, B4C may implement controls such as:

  • Secure session tokens
  • Automatic session expiration
  • Session renewal
  • Device recognition
  • Session revocation
  • Re-authentication for sensitive administrative actions

Session behavior may vary depending on the application, device, and organizational configuration.

07 Role-Based Access

Authentication identifies the user. Authorization determines what that user is permitted to access.

Departments manage permissions through role-based access controls that may include:

  • Department Administrators
  • Board Members
  • Chiefs
  • Officers
  • Training Officers
  • Members
  • Read-only users
  • Other Department-defined roles

Authentication does not grant unrestricted access. Permissions are governed separately through organizational role assignments.

08 Account Security

Authorized Users are responsible for:

  • Protecting login credentials
  • Using strong passwords
  • Enabling Multi-Factor Authentication when available
  • Reporting suspected unauthorized access
  • Updating recovery information when necessary
  • Logging out of shared or public devices

Departments should promptly remove access for individuals who no longer require it.

09 Suspicious Activity

Big Bull Technologies may implement reasonable measures to detect and respond to suspicious authentication activity, including:

  • Repeated failed sign-in attempts
  • Unusual login behavior
  • Access from unfamiliar devices
  • Geographic anomalies
  • Session irregularities
  • Other indicators of potential unauthorized access

To protect Customers, we may require additional verification, temporarily restrict access, or take other reasonable security measures when warranted.

10 Account Recovery

Users who lose access to their accounts may recover access using supported recovery methods.

Recovery procedures may include identity verification or confirmation of account ownership before access is restored.

Big Bull Technologies may decline recovery requests that cannot be reasonably verified.

11 Future Authentication Capabilities

As Before the Call evolves, additional authentication capabilities may become available, including:

  • Enterprise Single Sign-On (SSO)
  • Security keys
  • Passkeys
  • Federated identity providers
  • Additional Multi-Factor Authentication options
  • Other emerging authentication technologies

New authentication methods will be evaluated based on security, usability, and customer needs.

12 Security

Authentication is only one layer of our security program. Additional safeguards include:

  • Role-based authorization
  • Data protection measures
  • Session management
  • Platform monitoring
  • Audit logging
  • Administrative controls

Additional information is available in:

13 Changes to This Policy

Big Bull Technologies may update this Authentication Policy periodically.

Material changes will become effective on the published Effective Date after reasonable notice has been provided through the Services, our website, email, or another appropriate communication method.

14 Contact

Questions regarding authentication or account security may be directed to Big Bull Technologies.

Big Bull Technologies, LLC
Email: ashlea@bigbulltech.io

15 Related Documents

16 Revision History

VersionDateDescription
1.0.0July 2026Initial publication.