> ## Documentation Index
> Fetch the complete documentation index at: https://docs.beam.cloud/llms.txt
> Use this file to discover all available pages before exploring further.

# Security overview

> How Beam protects customer workloads and data.

This page summarizes the controls Beam uses to protect the platform and the data our customers run on it. It is the security reference for our [Terms of Service](/v2/security/terms-and-conditions), [Privacy Policy](/v2/security/privacy-policy), and [Data Processing Addendum](/v2/security/data-processing-addendum). The vendors that process data on our behalf are listed in the [Subprocessor list](/v2/security/subprocessor-list).

To report a vulnerability or ask a security question, email [security@beam.cloud](mailto:security@beam.cloud).

## Compliance

* **SOC 2 Type II.** Beam's controls are audited under SOC 2 Type II by Advantage Partners. Customers can request the most recent report under a non-disclosure agreement by emailing [security@beam.cloud](mailto:security@beam.cloud).
* **HIPAA.** Beam signs Business Associate Agreements with Enterprise customers under an Order Form. Do not submit protected health information before a BAA is in place; see Section 6.8 of the Terms of Service.
* **GDPR, UK GDPR, and Swiss FADP.** Our [Data Processing Addendum](/v2/security/data-processing-addendum) incorporates the EU Standard Contractual Clauses and the UK Addendum and applies automatically to every customer.

## Infrastructure

Beam runs on infrastructure provided by Amazon Web Services and Google Cloud, across multiple availability zones. Beam does not operate its own data centers; physical security is provided by our cloud providers under their own SOC 2 and ISO 27001 programs. Customer workloads run in the United States unless you choose a specific region or compute pool where the platform offers one.

## Workload isolation

* Workloads run in isolated containers. The effective user depends on the image and runtime configuration; a custom image is not guaranteed to run as a non-root user. Configure its user and permissions for your application.
* Network isolation separates customer workloads from one another and from Beam's control plane.
* Containers are ephemeral. Files written outside a mounted volume or disk are discarded when the container stops.

## Data protection

* **In transit.** All traffic between your clients and Beam, and between platform components, is encrypted with TLS.
* **At rest.** Customer Data, including volumes, disks, snapshots, and container images, is encrypted at rest.
* **Secrets.** Secrets you store on Beam are encrypted at rest and injected only into the containers you configure to use them. You control their names and scope and can rotate or delete them at any time from the dashboard or CLI.
* **Backups.** Beam maintains regular backups of platform data. Use snapshots to protect your own volumes and disks.
* **Retention and deletion.** Customer Data is retrievable for 30 days after your account is terminated and then deleted as described in Section 6.11 of the Terms of Service. Application logs are retained for 30 days on the Developer and Team plans and for 1 year on the Growth plan.

## Access control

**For customers**

* Access to your workspace is controlled with per-workspace API tokens, which you can create, rotate, and revoke from the dashboard or CLI.
* Team and Growth plans include multiple seats so each person uses their own credentials. All members of a workspace currently have the same permissions, and single sign-on is not yet available; remove members and rotate tokens when someone leaves your team.

**For Beam staff**

* Beam personnel authenticate with single sign-on and multi-factor authentication.
* Access to production systems is role-based and limited to the least privilege needed. Access to customer data is restricted to support and operations tasks, is logged, and is reviewed quarterly and revoked on role change or departure.
* All personnel sign confidentiality agreements and complete security and privacy training on hire and annually.

## Logging and monitoring

Beam centrally logs authentication, administrative, and system events and monitors errors and performance across the platform, with alerting on anomalous activity. Customer application logs are available to you in the dashboard and CLI for the retention period of your plan.

## Vulnerability management

* Dependencies and container images are scanned for known vulnerabilities, and patches are prioritized by severity.
* **Coordinated disclosure.** If you find a vulnerability, email [security@beam.cloud](mailto:security@beam.cloud) with steps to reproduce it. We will acknowledge your report and keep you informed as we work on a fix. Please do not access other customers' data, degrade the service, or publicly disclose the issue before we have addressed it. Beam will not pursue legal action against researchers who follow these guidelines in good faith.

## Incident response

Beam maintains a documented incident response process with defined roles, severity levels, and escalation paths, and conducts post-incident reviews. If a security incident affects your Customer Data, we will notify you as described in Section 6 of the Data Processing Addendum, within 72 hours of becoming aware of it. Platform status is published at [status.beam.cloud](https://status.beam.cloud).

## Self-hosting and Bring Your Own Cloud

Customers with strict data residency or isolation requirements have two options beyond the hosted platform:

* **Self-hosted.** The [beta9](https://github.com/beam-cloud/beta9) platform is open source and can run entirely in your own infrastructure. See the [self-hosting overview](/v2/self-hosting/overview) and the guides for [AWS](/v2/self-hosting/aws) and [local machines](/v2/self-hosting/local-machine). Beam has no access to a self-hosted deployment.
* **Bring Your Own Cloud (BYOC).** Beam's control plane schedules workloads onto compute in your own cloud account, such as AWS, Google Cloud, or Azure. Your code and data are processed on instances in your account; Beam receives the metadata needed to operate the platform, such as scheduling state and resource metrics, and application logs are shipped to Beam so they appear in your dashboard. Management fees for BYOC are listed on the [pricing page](https://www.beam.cloud/pricing).

## Shared responsibility

Beam secures the platform. You are responsible for:

* the security of the code, dependencies, and container images you deploy;
* scoping secrets and cloud credentials to the least privilege they need, and rotating them;
* protecting your account credentials and API tokens and removing access for people who leave your team;
* configuring authentication for the endpoints you expose;
* deciding what data you send to Beam, including whether you have the rights and consents to do so; and
* keeping backups of Customer Data that fit your recovery needs, using volume snapshots or your own tooling.

## Contact

* Security reports and questions: [security@beam.cloud](mailto:security@beam.cloud)
* Privacy: [privacy@beam.cloud](mailto:privacy@beam.cloud)
* SOC 2 report requests: [security@beam.cloud](mailto:security@beam.cloud)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.