Security statement
Beacon reads the systems you already run, computes your figures the same way every time, and serves them — with their origin, freshness and a seal — to people, boards, investors and AI. This is what a technical review needs to approve it: what Beacon touches, what it never will, and how your data is protected.
Your team builds nothing and maintains nothing
Beacon connects to billing, and optionally CRM, accounting and other systems, through read-first connectors. There is no data pipeline for your team to build, no warehouse to run, no integration code to maintain. Setup is a guided conversation; connecting each source is the only technical step, and you do it yourself.
We never hold your credentials
Every source is connected by your administrator, in that system's own login screen — the native authorisation flow. Beacon never asks for, stores, or completes a login; there are no shared passwords and no service-account sprawl. Each connection is revocable in your own system, instantly, without contacting us.
Your records stay where they are
Beacon holds the derived shape it needs — the aggregated figures and the tables built from them — and links back to your records. The raw line items stay in your source systems. There is no second copy of your ledger sitting in a Beacon warehouse.
Read-first — writes only with a human yes
Beacon is read-first. Where write-back is enabled, the scope is declared per system, in plain words (for example, "may add insight notes to accounts"), and everything not listed is read-only. Every write is a suggestion — drafted, queued, and executed only after a person approves it. Beacon never writes to your books or billing ledger — that's structural, not a setting. A request beyond the declared scope is refused and logged, so you can watch the guardrail work.
The AI reasons — it never computes a number
Every headline figure is produced by a deterministic engine — reproducible, versioned, and sealed with its inputs. Ask twice, get the same number twice. Beacon's AI explains, drafts and recommends; it never invents a value, never estimates a missing one, and never recomputes a figure. Agents act at or below the role of the person they act for, and a fixed list of actions is refused to every agent, always, and logged.
The eight fixed lines
These hold in every configuration, for every customer:
Never computes a headline number with AI.
Never decides, pulls a lever, or seals a decision itself.
Never overwrites a sealed record — the history is append-only and replayable.
Never asks for or stores your credentials.
Never changes who can see what — your administrator does.
Never acts in your systems without a human's approval.
Never writes to your books or billing ledger.
Never shows a number it can't trace, or guesses one it doesn't have.
Access is scoped, and sensitive data is a separate grant
Access is scoped by role and by the part of the business a person is responsible for. Restricted data — such as compensation — is its own explicit grant, never implied by a role. External seats (board, investors, advisors) read sealed figures only; operator detail is excluded when their view is built, not filtered away per request. Beacon proposes access changes; your administrator makes every change in the tool's own permission screen.
It stops rather than guesses
A part of the system runs only when its sources are live. If billing is missing, it stops rather than estimate. Any other missing source produces a named, bounded limited mode that states exactly what can and can't be read. Every figure carries its origin, freshness and sealed state; sealed decisions replay exactly as they stood, backed by an append-only record of every seal, approval and access change.
Where your data is held
By default, Beacon hosts data in the United States. EU data residency — hosted in Frankfurt, with backups in Dublin — is available for customers on the appropriate plan. Where a region can't be served in-region across our data layer, we say so plainly at sign-up rather than host your data somewhere it shouldn't be.
Our service providers
Beacon runs on a small set of established providers, each under contract to protect your data: Airtable and Notion (the data layer), Anthropic (Claude) (the reasoning engine), Clerk (authentication), Stripe (payments), Vercel and Railway (hosting), Resend (email), Sentry (monitoring), Mintlify (documentation) and HubSpot (customer communications). The complete, current list — with roles and hosting regions — is in our Data Processing Agreement.
Leaving is a settings page, not a negotiation
You can revoke any connector in the source system itself, at any time, and any reader's access (a person, an external seat, or a connected AI) in Beacon's admin screen. Your records were never moved. Exports of your derived data and the sealed history are available on request.
Verify before publishHosting & compliance snapshot — the one block the internal CTO brief intentionally ships empty pending verified facts: encryption in transit and at rest, cloud subprocessor detail and data-residency regions, certification status (SOC 2 / ISO 27001 — state current status only, no forward-looking claims), DPA availability, and the security contact. Fill these before this statement goes live.