Security

Built for the security review.

Encryption in transit and at rest, per-workspace isolation, role-based access, and a full audit trail. Beam never trains models on your data.

Encrypted in transit
Role-based access
Full audit trail
Workspace isolation
No model training

Security engineering, in the open. Controls you can verify in the product, not badges.

Encryption

TLS in transit; at rest by our cloud providers, with app-level encryption on stored credentials.

Access control

Owner, admin, member, and viewer roles, per-resource sharing, and a full audit log.

Workspace isolation

Every query is scoped to your workspace. Retrieval never crosses organization boundaries.

No model training

Beam never trains models on your data; providers you choose serve requests under their API terms.

Two ways to run Beam. Our managed cloud, or entirely on your own hardware.

Beam Cloud

Standard

The managed service, hosted on Vercel and Render in the US.

Self-hosted

Your hardware

The full stack (app, API, Postgres, worker, object store) on your own infrastructure with Docker Compose.

The controls, in plain terms. From encryption to admin permissions.

Where your data lives

  • Managed cloud on Vercel and Render (US)
  • Self-hosted option keeps everything on your infrastructure
  • Encrypted in transit; encrypted at rest by our cloud providers

Security architecture

  • Per-workspace data isolation
  • Role-based access control
  • Integration credentials encrypted at the application layer
  • Rate limiting on by default

Accountability

  • Every admin action lands in the audit log
  • Per-workspace usage analytics
  • Sub-processors listed in the DPA
  • Delete chats, files, and agents at any time

Model usage & BYOK

  • Bring your own model-provider keys
  • One interface across all providers
  • Beam never trains models on your data

Legal & data-processing documents. Public, current, and written to be read.

Data security and trust at Beam

Secure by design

Your data stays yours.

Questions & answers.

In transit with TLS. At rest, data is encrypted by our cloud providers, and stored integration credentials get an extra layer of application-level encryption on top.