Your review is 30 minutes.
Your build is nothing.
Everything a technical reviewer needs to approve Beacon: what it reads, what it never touches, what your team has to do, and how to switch it off. Nothing to fill in, nothing to send back.
The tool gets approved. The engineering never gets scheduled.
Six line items. Four of them are nothing.
The honest accounting of engineering effort, from go-ahead to live. If any line here turns out to be wrong for your estate, that is the thing to tell us on the call.
Once, at the start. There is no second phase where the real work arrives.
Six things to check. Every one has a page behind it.
This is the whole review. Each item links to where the answer is written down, so you are reading our position rather than taking our word for it.
Scopes
Every source we read, and every destination we can write back to, listed by system.
See the connector list →Credentials
Why Beacon holds no key of yours, and how you cut any connection from your own side.
Read: keys and access →Where records live
What stays in your systems, what Beacon keeps, and where it is held.
Read: data you bring into Beacon →Access ceilings
How far any one source travels, and what an external seat can and cannot see.
Read: where the boundary sits →The AI line
The eight things Beacon never does in any configuration — including computing a headline figure.
Read: the fixed lines →Exit
What you can revoke, what you can export, and how long anything is kept.
Read: how long we keep it →Hosting, subprocessors, transfers and certification status
These are not a pack you have to request. They are written into the documents we publish and keep current: the subprocessor list with roles and hosting regions, where data is held and transferred, encryption in transit and at rest, and certification status stated as it actually stands rather than as a promise.
Read-first, human-approved, and revocable from your side.
Your keys stay yours
Every source is connected by your admin in that system's own login screen. Beacon never asks for, stores or completes a login, and each connection is revocable in your own system without contacting us.
Writes need a person
Scope is declared per system in plain words, and anywhere not listed is read-only. Every write is drafted and queued until someone approves it. Beacon never writes to your books or your billing ledger.
Leaving is a settings page
Revoke a connector in the source system, or any reader grant in Beacon, at any time. Your records were never moved. Exports of the derived data and the sealed history are available on request.
The eight things Beacon never does in any configuration, and where the boundary sits for each one, are set out on security & boundaries. This page is the review pack; that one is the argument underneath it.
Nothing lands in your backlog. Nothing lands in your on-call.
For you
A review you can finish today, on evidence you can verify yourself, without booking a discovery call to find out what the integration really costs.
For your team
No pipeline to own, no schema to maintain, no key to rotate, and no ticket queue arriving three months after someone else signed the contract.
For the business
The thing they bought starts working in weeks rather than waiting behind the roadmap — and the numbers it produces can be traced when someone asks.
Bring the hardest question you have. That's the call we want.
Or start free and check every claim on this page against your own connected data.