Security

How we handle your data

Written for the person who has to approve us. If your procurement or security team needs something this page does not answer, ask and we will answer it directly rather than send a brochure.

Last updated 5 October 2026

01

You own it

Code is written in your repository under your organisation, and infrastructure runs in your cloud account, from the first commit rather than at handover. We work as collaborators on assets you already control.

This is the single most important control on this page. It means revoking our access is one action you take without asking us, and it means nothing of yours is stranded in an account we own.

  • Your source repository, your cloud account, your domain
  • Access granted per person, by you, and revocable by you at any moment
  • No shared logins. Every action is attributable to a named individual
02

Where data lives

In the region you specify. If your obligations require data to stay in a particular jurisdiction, that constraint is a design input at the start rather than a migration later.

We do not copy production data onto laptops. Where real data is needed for development, it is pseudonymised or a representative subset is generated instead.

  • Region chosen by you and enforced in infrastructure configuration
  • Production data is not downloaded to personal machines
  • Backups, retention and deletion schedules agreed before launch, not after
03

Credentials and secrets

Secrets are never committed to a repository and never sent over chat or email. They are held in the secret store of the platform the system runs on, injected at runtime, and rotated when anyone with access leaves the engagement.

Where a platform supports marking a value as write-only, we use it, so a credential cannot be read back out after it is set.

  • No secret in source control, enforced by automated scanning
  • Platform secret stores only. Vercel, AWS, or whichever host you run on
  • Rotation on team change, and at the end of an engagement
04

How we build

  • Every change goes through review before it reaches a production branch
  • Dependencies pinned by lockfile, with advisories checked before release
  • Least privilege by default: a service gets the narrowest role that works
  • Audit trails on records where a dispute would later need a history
  • Tests on the logic where being wrong costs money
05

AI and your data

Where an engagement uses language models, your data is sent to the model provider contracted for that project and nowhere else. We use providers with a zero-retention or no-training commitment for business tiers, and we name the provider in writing before any of your data reaches it.

Retrieval systems we build search your own records. They do not send your documents to a general-purpose assistant, and output carries the source it came from so a person can check it.

  • The model provider is named before any data is sent
  • No client data used to train a third-party model
  • Human approval on any step that writes a record, sends a message or spends money
06

When something goes wrong

We tell you. Quickly, in plain language, before we know the full picture, because a delayed disclosure is worse than an incomplete one.

During an active engagement you get a named person to contact rather than a ticket queue.

  • Notification as soon as we are aware, not after an internal investigation concludes
  • A written account of what happened, what was affected, and what changed as a result
  • Support with any regulatory notification you are obliged to make
07

What we do not claim

We do not hold SOC 2 or ISO 27001. Claiming a certification we have not been audited for would be the fastest way to lose an enterprise client, so we state it plainly instead.

If a certified supplier is a hard requirement for your procurement, say so early and we will tell you honestly whether to continue the conversation.

08

This site

The site you are reading sets no cookies, runs no analytics and loads no third-party trackers. The only thing stored in your browser is whether you chose the light or dark theme.

This page describes how we work. For a specific engagement we will complete your security questionnaire, sign your data processing agreement, and agree controls particular to your sector in writing.

Questions about any of this?

hello@beestudiox.com