Your data in safe hands.
Proof verified by third parties, not promises
Beeye’s security is audited every year by independent bodies. The complete security package is provided to your IT department on request.
Attestation renewed every year by an independent auditor, covering security, availability and confidentiality. Report available under NDA.
A demanding assessment of social and environmental standards, periodically renewed.
Information security policy approved by management, regularly reviewed, audited as part of SOC 2 and owned by a dedicated confidentiality and security team.
Your data hosted in your region
Hosted on Microsoft Azure, in the region agreed in your contract. No transfer outside your region without your prior written approval.
| Clients | Hosting | Continuity |
|---|---|---|
| Europe | Exclusively within the European Union (data center in France) | Regular backups within the EU |
| Canada | Canada (Québec City data center) | Backups in the Toronto data center |
| United States | Exclusively within the United States | Hosting region agreed in the contract |
Remote access by authorized Beeye personnel takes place from Canada, a jurisdiction covered by a European Commission adequacy decision, within the scope of Beeye’s SOC 2 controls.
The technical measures, in black and white
In transit (TLS 1.2 or higher) and at rest (AES-256), with an annual penetration test.
Office 365 / Entra ID SSO with MFA inherited from your directory. MFA or SSO required for administrator accounts and remote access by Beeye personnel.
Access logging, regular backups, security testing. Every change to the workload plan is dated and attributed.
Annual security awareness training, yearly commitment to internal policies, access limited to a need-to-know basis. Staff use of generative AI tools is governed by a dedicated policy.
Contractual commitments, not intentions
Incident notification without undue delay, no later than 48 hours after becoming awarewith nature, scope, measures and a point of contact
Reversibility: full export in a structured, commonly used and machine-readable formatfor 90 days, then return or deletion, written certificate on request
Data processing agreement (DPA) attached to the contract: GDPR, Québec Law 25, PIPEDAsubprocessors: Microsoft Azure and HubSpot only, up-to-date list on request
General liability, professional liability and cyber insurance with reputable insurerscertificate available on request
What your IT team will ask
Who can access our data?
Beeye staff who need it for their duties, bound by confidentiality obligations. Access to third-party tools is strictly limited in the same way.
Can we audit Beeye?
The SOC 2 Type II report answers audit requests first. Contracts additionally provide a framed client audit right (written notice, once per twelve-month period).
What happens at the end of the contract?
Full export of your data for 90 days in a machine-readable format, then return or deletion, backups included, with a written certificate of destruction on request.
Do you use our data to train AI?
Beeye does not use its clients’ data to train third-party AI models. Only aggregated, irreversibly anonymized data may be used to improve its own systems.
The complete security package (SOC 2 report, DPA, detailed measures) is provided to your IT department on request: security@mybeeye.com.
Your IT team’s questions, answered one by one.
A conversation with someone who speaks security, and the full pack (SOC 2, DPA, hosting) sent to your IT team on request.
Book my demo30 minutes with an expert who knows firms. We’ll tell you straight if Beeye is right for you.