Docs

User guide for the whole studio — how Beech works, end to end.

Administration

Security & data handling

Last updated: 11 Sep 2026

How Beech protects firm and Vault data — the same facts as the public Security page, written for operators. Hand the public page (/security) to a client; use this guide to know where to click.

Encryption

  • In transit — TLS for Beech and for Vault uploads/downloads to Backblaze B2.
  • At rest (Vault) — AES-256 server-side encryption on Backblaze B2.
  • Secrets — MFA and integration tokens encrypted with AES-256-GCM in the database.
  • This is not end-to-end encryption and not per-firm customer keys.

Who can access Vault

  • Project Vault — any project member (Admin, Manager, Contributor) can manage files. Admins see all projects.
  • Firm Library — everyone can browse; only Admins can upload or organise.
  • External shares — any project member by default. Admins can restrict to Admins and Managers in Firm settings → Vault.

Audit log

Admins open Firm settings → Audit log to see Vault file access, external share activity, active share links (with revoke), and Beech support sessions. Retention: one year.

Beech support access

Beech does not give engineers ad-hoc access to your Vault. Support uses audited impersonation only. Those sessions appear in your firm's audit log as Beech support.

Full statement for clients

Print or share the public Security & data handling page at /security (footer → Security). It covers encryption, roles, logging, subprocessors, and support access.