Security
How Bead AI protects your audit evidence
Audit begins and ends with trust. We built Bead AI with that principle from day one.
Our approach
Our customers rely on Bead AI to process their most sensitive audit data. We treat every piece of evidence as if it were our own: with encryption, isolation, and access controls designed for the most demanding enterprise environments.
Our platform is managed, standardized, externally audited, and built on the principle that security is never an afterthought.
Your Data, Your Control
- No Model Training
- Customer data is never used to train or improve any AI model. Period.
- Never Sent to Model Providers
- Your evidence is never sent to the companies that build the models. Inference runs on Amazon Bedrock and Google Cloud Vertex AI inside our own cloud account under zero-data-retention terms, with only the minimum context a test needs. Nothing is stored or logged for human review. On-premises, nothing leaves your network.
- US Data Residency
- Customer data is stored and processed in the United States by default. A dedicated deployment can run in another AWS region where the services it depends on are available.
Data Protection
- Encryption in transit and at rest
- TLS 1.2+ in transit. AES-256 at rest via AWS KMS. All backups encrypted and versioned
- Tenant Isolation
- Each customer environment is logically isolated with dedicated resources and unique credentials.
- SSO, MFA & RBAC
- SAML 2.0 single sign-on, multi-factor authentication, and role-based access control.
- Secure Deletion
- NIST-compliant sanitization on termination. Data export available prior to deletion upon request.
Controls at a glance
Every row below is a commitment in ourSecurity Addendum, which forms part of the contract.
| Audit and attestation | SOC 2 Type II, audited annually |
|---|---|
| Data location | Data centres in the United States |
| Encryption | TLS 1.2+ in transit, AES-256 at rest, keys in HSMs and rotated at least annually |
| Vulnerability remediation | Critical within 7 days, high within 30, medium within 90 |
| Independent testing | Penetration test and OWASP web application assessment, each at least annually |
| Breach notification | Within 48 hours of Bead AI becoming aware |
| Audit log retention | Between 1 and 10 years, protected against tampering |
| Access revocation on separation | Critical systems within 1 day, all systems within 3 |
| Your security reviews | Up to 100 questionnaire questions a year, answered at our cost |
Certifications and attestations
- SOC 2 Type II, independently audited. The report is available through our Trust Center.
- Penetration testing by an independent third party at least annually, plus an annual OWASP-based web application assessment. Summary results are available on request.
Frameworks we build to
- We signed the CISA Secure by Design Pledge: security is built in, not added afterwards.
- Our AI development is guided by ISO/IEC 42001 and the NIST AI Risk Management Framework. We are not certified against ISO/IEC 42001. See our AI Policy.
Common questions
Is Bead AI SOC 2 Type II certified?
Is our audit evidence used to train AI models?
Which services process our data?
Where is our data stored?
How quickly are vulnerabilities fixed, and how fast would we hear about a breach?
Can we have a dedicated environment rather than a shared one?
Can our security team audit Bead AI?
Talk to us about your review
We answer security questionnaires at our own cost, and can walk your team through the SOC 2 report, ourdeployment options and theSecurity Addendum on a call.
Reporting
If you’ve identified a potential security flaw in our infrastructure or software, please let us know atsecurity@usebead.ai. We’ll triage the issue and get back to you.
