Security
Built for the security review.
Encryption in transit and at rest, per-workspace isolation, role-based access, and a full audit trail. Beam never trains models on your data.
Security engineering, in the open. Controls you can verify in the product, not badges.
Encryption
TLS in transit; at rest by our cloud providers, with app-level encryption on stored credentials.
Access control
Owner, admin, member, and viewer roles, per-resource sharing, and a full audit log.
Workspace isolation
Every query is scoped to your workspace. Retrieval never crosses organization boundaries.
No model training
Beam never trains models on your data; providers you choose serve requests under their API terms.
Two ways to run Beam. Our managed cloud, or entirely on your own hardware.
Beam Cloud
The managed service, hosted on Vercel and Render in the US.
Self-hosted
The full stack (app, API, Postgres, worker, object store) on your own infrastructure with Docker Compose.
The controls, in plain terms. From encryption to admin permissions.
Where your data lives
- Managed cloud on Vercel and Render (US)
- Self-hosted option keeps everything on your infrastructure
- Encrypted in transit; encrypted at rest by our cloud providers
Security architecture
- Per-workspace data isolation
- Role-based access control
- Integration credentials encrypted at the application layer
- Rate limiting on by default
Accountability
- Every admin action lands in the audit log
- Per-workspace usage analytics
- Sub-processors listed in the DPA
- Delete chats, files, and agents at any time
Model usage & BYOK
- Bring your own model-provider keys
- One interface across all providers
- Beam never trains models on your data
Legal & data-processing documents. Public, current, and written to be read.

Secure by design
Your data stays yours.
Questions & answers.
In transit with TLS. At rest, data is encrypted by our cloud providers, and stored integration credentials get an extra layer of application-level encryption on top.