TRUST CENTER

Security overview

Application controls implemented in Beetl and the operational evidence still required before production use.

Last reviewed: 31 August 2026

Implemented

Tenant isolation

Every tenant-owned model carries an organisation identifier. Server authorization establishes trusted membership context, tenant-scoped repositories are guarded, and PostgreSQL row-level security supplies defence in depth.

Implemented

Authentication and sessions

Verified email, a 12-character minimum password, expiring server sessions, password-reset session revocation, origin checks, and generic sign-in failure messages are enforced. Workspace MFA is not yet implemented.

Implemented

Private files

Object storage keys are tenant-prefixed and private files are served only through authorization-aware application routes with private, no-store caching. High-risk formats are blocked and document signatures are inspected.

Deployment evidence required

Infrastructure

HTTPS, private database networking, encrypted storage and backups, monitoring, restore tests, key rotation and least-privilege cloud roles must be verified for each production environment. Repository configuration alone is not proof of those controls.

Manual/external

Assurance

Independent penetration testing, vulnerability remediation evidence, cyber-insurance decisions, workforce training and supplier contract review remain operational responsibilities.