---
title: "Security at Bead AI: SOC 2 Type II, Zero Retention"
description: "SOC 2 Type II, US data residency, AES-256 at rest, tenant isolation, and zero-retention inference. Your audit evidence never reaches a model provider and never trains a model."
url: "https://usebead.ai/security"
---

# How Bead AI protects your audit evidence

Audit begins and ends with trust. We built Bead AI with that principle from day one.

## Our approach

Our customers rely on Bead AI to process their most sensitive audit data. We treat every piece of evidence as if it were our own: with encryption, isolation, and access controls designed for the most demanding enterprise environments.

Our platform is managed, standardized, externally audited, and built on the principle that security is never an afterthought.

## Your Data, Your Control

No Model Training

Customer data is never used to train or improve any AI model. Period.

Never Sent to Model Providers

Your evidence is never sent to the companies that build the models. Inference runs on Amazon Bedrock and Google Cloud Vertex AI inside our own cloud account under zero-data-retention terms, with only the minimum context a test needs. Nothing is stored or logged for human review. On-premises, nothing leaves your network.

US Data Residency

Customer data is stored and processed in the United States by default. A dedicated deployment can run in another AWS region where the services it depends on are available.

## Data Protection

Encryption in transit and at rest

TLS 1.2+ in transit. AES-256 at rest via AWS KMS. All backups encrypted and versioned

Tenant Isolation

Each customer environment is logically isolated with dedicated resources and unique credentials.

SSO, MFA & RBAC

SAML 2.0 single sign-on, multi-factor authentication, and role-based access control.

Secure Deletion

NIST-compliant sanitization on termination. Data export available prior to deletion upon request.

## Controls at a glance

Every row below is a commitment in our[Security Addendum](https://usebead.ai/legal/security-addendum), which forms part of the contract.

<table data-astro-cid-6262dcpq=""><tbody data-astro-cid-6262dcpq=""><tr data-astro-cid-6262dcpq=""><th scope="row" data-astro-cid-6262dcpq="">Audit and attestation</th><td data-astro-cid-6262dcpq="">SOC 2 Type II, audited annually</td></tr><tr data-astro-cid-6262dcpq=""><th scope="row" data-astro-cid-6262dcpq="">Data location</th><td data-astro-cid-6262dcpq="">Data centres in the United States</td></tr><tr data-astro-cid-6262dcpq=""><th scope="row" data-astro-cid-6262dcpq="">Encryption</th><td data-astro-cid-6262dcpq="">TLS 1.2+ in transit, AES-256 at rest, keys in HSMs and rotated at least annually</td></tr><tr data-astro-cid-6262dcpq=""><th scope="row" data-astro-cid-6262dcpq="">Vulnerability remediation</th><td data-astro-cid-6262dcpq="">Critical within 7 days, high within 30, medium within 90</td></tr><tr data-astro-cid-6262dcpq=""><th scope="row" data-astro-cid-6262dcpq="">Independent testing</th><td data-astro-cid-6262dcpq="">Penetration test and OWASP web application assessment, each at least annually</td></tr><tr data-astro-cid-6262dcpq=""><th scope="row" data-astro-cid-6262dcpq="">Breach notification</th><td data-astro-cid-6262dcpq="">Within 48 hours of Bead AI becoming aware</td></tr><tr data-astro-cid-6262dcpq=""><th scope="row" data-astro-cid-6262dcpq="">Audit log retention</th><td data-astro-cid-6262dcpq="">Between 1 and 10 years, protected against tampering</td></tr><tr data-astro-cid-6262dcpq=""><th scope="row" data-astro-cid-6262dcpq="">Access revocation on separation</th><td data-astro-cid-6262dcpq="">Critical systems within 1 day, all systems within 3</td></tr><tr data-astro-cid-6262dcpq=""><th scope="row" data-astro-cid-6262dcpq="">Your security reviews</th><td data-astro-cid-6262dcpq="">Up to 100 questionnaire questions a year, answered at our cost</td></tr></tbody></table>

## Certifications and attestations

- SOC 2 Type II, independently audited. The report is available through our [Trust Center](https://trust.usebead.ai/).
- Penetration testing by an independent third party at least annually, plus an annual OWASP-based web application assessment. Summary results are available on request.

## Frameworks we build to

- We signed the [CISA Secure by Design Pledge](https://www.cisa.gov/securebydesign/pledge): security is built in, not added afterwards.
- Our AI development is guided by ISO/IEC 42001 and the NIST AI Risk Management Framework. We are not certified against ISO/IEC 42001. See our [AI Policy](https://usebead.ai/legal/ai-policy).

## Common questions

**Is Bead AI SOC 2 Type II certified?**

Yes, and independently audited. The report, the subprocessor list and the security FAQs are available through our Trust Center at trust.usebead.ai.

**Is our audit evidence used to train AI models?**

No, and it never reaches the companies that build the models. Inference runs inside Bead’s own cloud account on Amazon Bedrock and Google Cloud Vertex AI, neither of which passes inputs or outputs to the model provider behind the model, or keeps them after the request. Your evidence trains no model, ours or anyone else’s. On-premises, nothing leaves your network.

**Which services process our data?**

Amazon Bedrock, in the same AWS account and US region as the workload, and Google Gemini through Google Cloud Vertex AI. Both are our subprocessors, both run under zero-data-retention terms, and neither forwards your evidence to the model provider behind the model or trains on it. The current list is in our Privacy Policy.

**Where is our data stored?**

In data centres in the United States by default. A dedicated single-tenant deployment can run in another AWS region instead, wherever the services it depends on — including the inference services — are available there. Ask us about a specific region before you commit to it.

**How quickly are vulnerabilities fixed, and how fast would we hear about a breach?**

Critical vulnerabilities within 7 days, high within 30 and medium within 90. You would be notified of a security incident within 48 hours of us becoming aware of it. Both commitments are contractual, in our Security Addendum.

**Can we have a dedicated environment rather than a shared one?**

Yes. Large customers run in a dedicated single-tenant AWS account with its own network and infrastructure isolation, across three availability zones. Shared deployments separate tenants at the database level with row-level security.

**Can our security team audit Bead AI?**

Yes. On request we provide the SOC 2 Type II report, penetration test summaries and data flow diagrams at no cost, and once a year we answer up to 100 security questionnaire questions at our own cost.

## Talk to us about your review

We answer security questionnaires at our own cost, and can walk your team through the SOC 2 report, our[deployment options](https://usebead.ai/platform/deployment) and the[Security Addendum](https://usebead.ai/legal/security-addendum) on a call.

[Book a security review →](https://usebead.ai/contact) [Or visit the Trust Center](https://trust.usebead.ai/)

## Reporting

If you’ve identified a potential security flaw in our infrastructure or software, please let us know at[security@usebead.ai](mailto:security@usebead.ai). We’ll triage the issue and get back to you.
