What we touch. What we never will.
Beacon reads the systems your company already runs and turns them into figures you steer by. The boundaries around that reading aren’t promises we make — they’re structural, and you hold every key.
Most security answers are promises about the future.
They describe a product as it stood the week they were written, set up the way it was demonstrated.
One source, followed all the way across.
Your billing system, connected on a Monday morning. Here is everything that crosses the boundary — and everything that never does.
Illustrative. The same shape holds for your CRM, accounting, marketing and people systems.
Beacon never holds a key. You can cut it any time.
Connections are made in each source system’s own screen, and cut there too.
Sign in at the source
Your administrator authorises Beacon in the source system’s own screen. The credential never reaches us.
Beacon gets a connection
What comes back is scoped, read-only and revocable — never a password.
Revoke it yourself
Cut the connection in the source system, any time. No ticket, no notice, no call.
Intelligence arrives as a draft. A person sends it.
Beacon writes back into the tools your team already works in — and every one of those writes stops at a human being first.
Product usage down 41% since the March seat change, and the renewal lands in 38 days. Suggested move: reach out this week, with the usage picture attached.
Nothing happens in your tools until someone presses approve — and the approval lands on the record with a name against it.
Read-only, permanently.
There is no setting that turns this on, because it isn’t a permission Beacon holds. The systems your auditors care about are read, and only read.
It stops rather than guesses.
Most reporting fails quietly — a sync that stalled, a number quietly estimated to fill a hole. Beacon’s failure mode is saying so, in the place the number would have been.
Eight things Beacon never does. For anyone.
Not settings. Not defaults you could change later. These hold however Beacon is configured, for every customer — which is what makes them worth your CTO’s half hour.
Never computes a headline figure with AI — every number comes from the same deterministic engine, the same way every time.
Never decides, and never seals a decision itself.
Never overwrites a sealed record — the history only ever gets added to.
Never asks for or stores your credentials.
Never changes who can see what. Your administrator does.
Never acts in your systems without a person’s approval.
Never writes to your books or your billing ledger.
Never shows a figure it can’t trace, or guesses one it doesn’t have.
The technical brief, published up front.
What Beacon touches, what it never will, the access to check and the questions a review asks — written to be approved, or to fail fast if we’re not a fit. Read it before you ever talk to us.
- Security statementThe formal wording
- Privacy noticeWhat we process, and why
- Data Processing AgreementFor your legal team
- privacy@beaconrevenue.ioQuestions from a security review
Your security review starts before your first call.
For you
A vendor review you can run yourself.The brief is published, so your team can start checking on the day they hear the name — no call to book, no NDA to sign first.
For your team
Nobody hands over a password.Every connection is made and cut in your own tools, by your own admin. Turning Beacon off never needs a conversation with us.
For your CTO and your board
Boundaries you can check, not trust.The same eight nevers hold in every configuration, and every approval, access change and refusal lands on a record that can be replayed.
Connect a source. Keep every key.
You authenticate in your own tools — Beacon never sees a password. Free at any size, no card, no clock.