Legal

Security

Version 1.0 · Effective September 11, 2026

Security approach

Beech uses layered technical and organizational safeguards designed for architecture teams managing project and drawing data.

Authentication and access control

Access is controlled through authenticated user accounts, role-based permissions, and firm-level data boundaries. Optional MFA is available, and organizations can enforce stricter auth policies through internal controls.

Encryption and secrets

Data is encrypted in transit over TLS. Sensitive integration and authentication secrets are encrypted before persistence where supported by the implementation.

File safety and malware controls

Uploaded files pass through validation and malware-scanning safeguards when configured. Vault storage uses dedicated object-storage controls and scoped access paths.

Logging and monitoring

Beech maintains operational monitoring, application error telemetry, and audit logs for key administrative and workflow actions.

Administrative access and impersonation

Authorized operators may access customer environments only for support, maintenance, or security incidents. Super-admin impersonation workflows are audited.

Incident response

Beech follows an internal incident response process. If a confirmed security incident affects customer personal data, impacted customers are notified as required by applicable law.

Live operational status is published on Status.

Contact

Security questions: [email protected]