New from Bead: The Audit Leader’s Guide to AI for SOX TestingRead the book

Our approach

Our customers rely on Bead AI to process their most sensitive audit data. We treat every piece of evidence as if it were our own: with encryption, isolation, and access controls designed for the most demanding enterprise environments.

Our platform is managed, standardized, externally audited, and built on the principle that security is never an afterthought.

Your Data, Your Control

No Model Training
Customer data is never used to train or improve any AI model. Period.
Never Sent to Model Providers
Your evidence is never sent to the companies that build the models. Inference runs on Amazon Bedrock and Google Cloud Vertex AI inside our own cloud account under zero-data-retention terms, with only the minimum context a test needs. Nothing is stored or logged for human review. On-premises, nothing leaves your network.
US Data Residency
Customer data is stored and processed in the United States by default. A dedicated deployment can run in another AWS region where the services it depends on are available.

Data Protection

Encryption in transit and at rest
TLS 1.2+ in transit. AES-256 at rest via AWS KMS. All backups encrypted and versioned
Tenant Isolation
Each customer environment is logically isolated with dedicated resources and unique credentials.
SSO, MFA & RBAC
SAML 2.0 single sign-on, multi-factor authentication, and role-based access control.
Secure Deletion
NIST-compliant sanitization on termination. Data export available prior to deletion upon request.

Controls at a glance

Every row below is a commitment in ourSecurity Addendum, which forms part of the contract.

Audit and attestationSOC 2 Type II, audited annually
Data locationData centres in the United States
EncryptionTLS 1.2+ in transit, AES-256 at rest, keys in HSMs and rotated at least annually
Vulnerability remediationCritical within 7 days, high within 30, medium within 90
Independent testingPenetration test and OWASP web application assessment, each at least annually
Breach notificationWithin 48 hours of Bead AI becoming aware
Audit log retentionBetween 1 and 10 years, protected against tampering
Access revocation on separationCritical systems within 1 day, all systems within 3
Your security reviewsUp to 100 questionnaire questions a year, answered at our cost

Certifications and attestations

Frameworks we build to

Common questions

Is Bead AI SOC 2 Type II certified?
Yes, and independently audited. The report, the subprocessor list and the security FAQs are available through our Trust Center at trust.usebead.ai.
Is our audit evidence used to train AI models?
No, and it never reaches the companies that build the models. Inference runs inside Bead’s own cloud account on Amazon Bedrock and Google Cloud Vertex AI, neither of which passes inputs or outputs to the model provider behind the model, or keeps them after the request. Your evidence trains no model, ours or anyone else’s. On-premises, nothing leaves your network.
Which services process our data?
Amazon Bedrock, in the same AWS account and US region as the workload, and Google Gemini through Google Cloud Vertex AI. Both are our subprocessors, both run under zero-data-retention terms, and neither forwards your evidence to the model provider behind the model or trains on it. The current list is in our Privacy Policy.
Where is our data stored?
In data centres in the United States by default. A dedicated single-tenant deployment can run in another AWS region instead, wherever the services it depends on — including the inference services — are available there. Ask us about a specific region before you commit to it.
How quickly are vulnerabilities fixed, and how fast would we hear about a breach?
Critical vulnerabilities within 7 days, high within 30 and medium within 90. You would be notified of a security incident within 48 hours of us becoming aware of it. Both commitments are contractual, in our Security Addendum.
Can we have a dedicated environment rather than a shared one?
Yes. Large customers run in a dedicated single-tenant AWS account with its own network and infrastructure isolation, across three availability zones. Shared deployments separate tenants at the database level with row-level security.
Can our security team audit Bead AI?
Yes. On request we provide the SOC 2 Type II report, penetration test summaries and data flow diagrams at no cost, and once a year we answer up to 100 security questionnaire questions at our own cost.

Talk to us about your review

We answer security questionnaires at our own cost, and can walk your team through the SOC 2 report, ourdeployment options and theSecurity Addendum on a call.

Book a security review →Or visit the Trust Center

Reporting

If you’ve identified a potential security flaw in our infrastructure or software, please let us know atsecurity@usebead.ai. We’ll triage the issue and get back to you.