TRUST CENTER
Security overview
Application controls implemented in Beetl and the operational evidence still required before production use.
Last reviewed: 31 August 2026
Implemented
Tenant isolation
Every tenant-owned model carries an organisation identifier. Server authorization establishes trusted membership context, tenant-scoped repositories are guarded, and PostgreSQL row-level security supplies defence in depth.
Implemented
Authentication and sessions
Verified email, a 12-character minimum password, expiring server sessions, password-reset session revocation, origin checks, and generic sign-in failure messages are enforced. Workspace MFA is not yet implemented.
Implemented
Private files
Object storage keys are tenant-prefixed and private files are served only through authorization-aware application routes with private, no-store caching. High-risk formats are blocked and document signatures are inspected.
Deployment evidence required
Infrastructure
HTTPS, private database networking, encrypted storage and backups, monitoring, restore tests, key rotation and least-privilege cloud roles must be verified for each production environment. Repository configuration alone is not proof of those controls.
Manual/external
Assurance
Independent penetration testing, vulnerability remediation evidence, cyber-insurance decisions, workforce training and supplier contract review remain operational responsibilities.