Security statement
Beacon reads the systems you already run, computes your figures the same way every time, and serves them — with their origin, freshness and a seal — to people, boards, investors and AI. This is what a technical review needs to approve it: what Beacon touches, what it never will, and how your data is protected.
Questions from a security review are welcome at privacy@beaconrevenue.io.
Your team builds nothing and maintains nothing
Beacon connects to billing, and optionally CRM, accounting and other systems, through read-first connectors. There is no data pipeline for your team to build, no warehouse to run, no integration code to maintain. Setup is a guided conversation; connecting each source is the only technical step, and you do it yourself.
Your logins never leave your own systems
Every source is connected by your administrator, in that system's own login screen — the native authorisation flow. Beacon never asks for, stores, or completes a login; there are no shared passwords and no service-account sprawl. What Beacon holds is the scoped connection you authorised there — kept encrypted on Beacon's own backend, never shown in the workspace you and your team work in, and revocable in your own system, instantly, without contacting us.
Your records stay where they are
Beacon holds the derived shape it needs — the aggregated figures and the tables built from them — and links back to your records. Beacon keeps the invoice lines it needs to reproduce every sealed figure, in your own isolated section of our EU database. Your billing system stays the system of record, and Beacon never writes to it.
Read-first — writes only with a human yes
Beacon is read-first. Where write-back is enabled, the scope is declared per system, in plain words (for example, "may add insight notes to accounts"), and everything not listed is read-only. Every write is a suggestion — drafted, queued, and executed only after a person approves it. Beacon never writes to your books or billing ledger — that's structural, not a setting. A request beyond the declared scope is refused and logged, so you can watch the guardrail work.
The AI reasons — it never computes a number
Every headline figure is produced by a deterministic engine — reproducible, versioned, and sealed with its inputs. Ask twice, get the same number twice. Beacon's AI explains, drafts and recommends; it never invents a value, never estimates a missing one, and never recomputes a figure. Agents act at or below the role of the person they act for, and a fixed list of actions is refused to every agent, always, and logged.
The eight fixed lines
These hold in every configuration, for every customer:
Never computes a headline number with AI.
Never decides, pulls a lever, or seals a decision itself.
Never overwrites a sealed record — the history is append-only and replayable.
Never asks for, stores or completes a login.
Never changes who can see what — your administrator does.
Never acts in your systems without a human's approval.
Never writes to your books or billing ledger.
Never shows a number it can't trace, or guesses one it doesn't have.
Access is scoped, and sensitive data is a separate grant
Access is scoped by role and by the part of the business a person is responsible for. Restricted data — such as compensation — is its own explicit grant, never implied by a role. External seats (board, investors, advisors) read sealed figures only; operator detail is excluded when their view is built, not filtered away per request. Beacon proposes access changes; your administrator makes every change in the tool's own permission screen.
It stops rather than guesses
A part of the system runs only when its sources are live. If billing is missing, it stops rather than estimate. Any other missing source produces a named, bounded limited mode that states exactly what can and can't be read. Every figure carries its origin, freshness and sealed state; sealed decisions replay exactly as they stood, backed by an append-only record of every seal, approval and access change.
Where your data is held
We think you should be able to read this page and know exactly where your numbers sit. So here is the whole list, service by service.
Run inside the EU
- Our application servers and our operational database run in the Netherlands.
- Error monitoring runs in Frankfurt, Germany.
- Email we send you goes through Ireland.
- Product-usage analytics runs in the EU.
Run in the United States
- The database holding your analytics tables (Airtable).
- Sign-in and account security (Clerk).
- The AI reasoning layer (Anthropic).
- The website and app front end (Vercel).
- Our internal workspace, and the permanent record of your sealed settings and figures (Notion).
Transfers to the United States are covered by standard contractual clauses and, where the provider is certified, the EU–US Data Privacy Framework.
We are not going to tell you we are EU-resident, because we are not. We chose the EU everywhere we could. Where we could not — and the AI layer is the one that cannot move — we have named it above rather than leaving it for you to find.
How your data is protected
Everything travels over HTTPS.
The connections you authorise for Stripe, HubSpot and your accounting system get particular care: each one is encrypted with its own key, and those keys are themselves encrypted by a master key held outside the database. Someone who obtained a copy of the database would not have your credentials.
Our providers document encryption of stored data at rest; we state that as their claim, not ours.
What we do not have yet
We hold no security certifications. No SOC 2, no ISO 27001, no third-party penetration test. We are a small company running an early programme and we would rather say that here than have you discover it in a procurement review. A Data Processing Agreement is available and can be signed on request.
Our service providers
Beacon runs on a small set of established providers, each under contract to protect your data: Airtable and Notion (the data layer), Anthropic (Claude) (the reasoning engine), Clerk (authentication), Stripe (payments), Vercel and Railway (hosting), Resend (email), Sentry (monitoring), PostHog (product-usage analytics), Mintlify (documentation) and HubSpot (customer communications). The complete, current list — with roles and hosting regions — is in our Data Processing Agreement.
Leaving is a settings page, not a negotiation
You can revoke any connector in the source system itself, at any time, and any reader's access (a person, an external seat, or a connected AI) in Beacon's admin screen. Your source systems were never written to. Exports of your derived data and the sealed history are available on request.
Security questions, questions from a security review and vulnerability reports are welcome at privacy@beaconrevenue.io.