Access & Security
Authentication Policy
How Before the Call authenticates users, manages account access, and supports secure identity verification — so only authorized individuals reach Department information.
- Document ID
- SEC-001
- Version
- 1.0.0
- Status
- Active
- Classification
- Public
- Owner
- Big Bull Technologies, LLC
- Effective
- 20 July 2026
- Next review
- July 2027
01 Purpose
Big Bull Technologies, LLC (“Big Bull Technologies,” “BBT,” “we,” “our,” or “us”) is committed to protecting Customer accounts and administrative information through secure authentication practices.
This Authentication Policy explains how Before the Call (“B4C”) authenticates users, manages account access, and supports secure identity verification.
Authentication is one component of our broader security program and should be read together with our Security Overview and Data Security documentation.
02 Authentication Philosophy
Authentication exists to ensure that only authorized individuals are able to access Department information.
Our authentication controls are designed to:
- Verify user identity
- Protect Customer accounts
- Reduce unauthorized access
- Support role-based security
- Improve overall platform integrity
Authentication methods may evolve as technology and security practices advance.
03 Authorized Users
Access to Before the Call is limited to Authorized Users approved by a subscribing organization.
Each Authorized User is responsible for maintaining the confidentiality of their account credentials.
Departments are responsible for managing user access within their organization.
04 Individual Accounts
Each Authorized User should maintain an individual account.
Shared accounts are discouraged except where specifically authorized by organizational policy and supported by the platform. Individual accounts improve:
- Accountability
- Audit history
- Security
- Administrative reporting
- User management
05 Authentication Methods
Depending on platform capabilities and organizational settings, authentication may include:
- Email and password
- Magic links
- One-time verification codes
- Multi-Factor Authentication (MFA)
- Device authentication
- Enterprise authentication providers (future)
- Other approved authentication methods
Available authentication options may vary by subscription level and platform capabilities.
06 Session Management
To protect Customer information, B4C may implement controls such as:
- Secure session tokens
- Automatic session expiration
- Session renewal
- Device recognition
- Session revocation
- Re-authentication for sensitive administrative actions
Session behavior may vary depending on the application, device, and organizational configuration.
07 Role-Based Access
Authentication identifies the user. Authorization determines what that user is permitted to access.
Departments manage permissions through role-based access controls that may include:
- Department Administrators
- Board Members
- Chiefs
- Officers
- Training Officers
- Members
- Read-only users
- Other Department-defined roles
Authentication does not grant unrestricted access. Permissions are governed separately through organizational role assignments.
08 Account Security
Authorized Users are responsible for:
- Protecting login credentials
- Using strong passwords
- Enabling Multi-Factor Authentication when available
- Reporting suspected unauthorized access
- Updating recovery information when necessary
- Logging out of shared or public devices
Departments should promptly remove access for individuals who no longer require it.
09 Suspicious Activity
Big Bull Technologies may implement reasonable measures to detect and respond to suspicious authentication activity, including:
- Repeated failed sign-in attempts
- Unusual login behavior
- Access from unfamiliar devices
- Geographic anomalies
- Session irregularities
- Other indicators of potential unauthorized access
To protect Customers, we may require additional verification, temporarily restrict access, or take other reasonable security measures when warranted.
10 Account Recovery
Users who lose access to their accounts may recover access using supported recovery methods.
Recovery procedures may include identity verification or confirmation of account ownership before access is restored.
Big Bull Technologies may decline recovery requests that cannot be reasonably verified.
11 Future Authentication Capabilities
As Before the Call evolves, additional authentication capabilities may become available, including:
- Enterprise Single Sign-On (SSO)
- Security keys
- Passkeys
- Federated identity providers
- Additional Multi-Factor Authentication options
- Other emerging authentication technologies
New authentication methods will be evaluated based on security, usability, and customer needs.
12 Security
Authentication is only one layer of our security program. Additional safeguards include:
- Role-based authorization
- Data protection measures
- Session management
- Platform monitoring
- Audit logging
- Administrative controls
Additional information is available in:
13 Changes to This Policy
Big Bull Technologies may update this Authentication Policy periodically.
Material changes will become effective on the published Effective Date after reasonable notice has been provided through the Services, our website, email, or another appropriate communication method.
14 Contact
Questions regarding authentication or account security may be directed to Big Bull Technologies.
Big Bull Technologies, LLC
Email: ashlea@bigbulltech.io
15 Related Documents
16 Revision History
| Version | Date | Description |
|---|---|---|
| 1.0.0 | July 2026 | Initial publication. |