ShipsAt launchWave 2Wave 3Wave 4
Security & boundaries

What we touch. What we never will.

Beacon reads the systems your company already runs and turns them into figures you steer by. The boundaries around that reading aren’t promises we make — they’re structural, and you hold every key.

True in every setup
Your logins. Never asked for, never stored, never replayed.
Your raw records. Never moved, never copied into a second ledger.
Every write. Held at the boundary until a person says yes.
How trust usually works

Most security answers are promises about the future.

They describe a product as it stood the week they were written, set up the way it was demonstrated.

The questionnaire
Two hundred rows of answers, signed by someone who read the roadmap.
Never seesWhether it still holds once the tool is set up a different way.
The pilot login
Someone shared an admin account to get a trial moving. It worked.
Never seesWhat that account can still reach a year later, at 3am.
The copy of the data
A second copy of your ledger, made so a dashboard could load fast.
Never seesWho looks after it now — or which of the two copies is right.
Every one of those rests on someone keeping their word.A boundary you can check doesn’t.
Where the boundary sits

One source, followed all the way across.

Your billing system, connected on a Monday morning. Here is everything that crosses the boundary — and everything that never does.

Your systemsThe boundaryBeacon
Your systemsYour billing system
reads
BeaconMRR, ARR, churn
Your systemsYour logins
stops here
BeaconA revocable connection
Your systems4.2M invoice line items
stops here
BeaconTotals only
Your systemsA draft in your CRM
waits
BeaconA suggested next step
Crosses the boundary Never crosses Waits for a person

Illustrative. The same shape holds for your CRM, accounting, marketing and people systems.

Keys and access

Beacon never holds a key. You can cut it any time.

Connections are made in each source system’s own screen, and cut there too.

01

Sign in at the source

Your administrator authorises Beacon in the source system’s own screen. The credential never reaches us.

your-billing-provider.com
Password
••••••••••••
02

Beacon gets a connection

What comes back is scoped, read-only and revocable — never a password.

What Beacon holds
conn_live_7f3a…e21b
03

Revoke it yourself

Cut the connection in the source system, any time. No ticket, no notice, no call.

connected apps › Beacon
Revoke access
Access inside Beacon works the same way. Beacon proposes a change and explains why; your administrator makes it, in your own permission screen. Restricted data — compensation always — is its own deliberate grant, never implied by a job title.
Acting in your tools

Intelligence arrives as a draft. A person sends it.

Beacon writes back into the tools your team already works in — and every one of those writes stops at a human being first.

Waiting for approvalIllustrative
Kestrel Analytics — renewal at risk
For the account’s owner · flagged this morning

Product usage down 41% since the March seat change, and the renewal lands in 38 days. Suggested move: reach out this week, with the usage picture attached.

If you approve, Beacon will 1Create a task on the account, due Friday 2Put a draft email in the owner’s outbox — for them to read and send
ApproveEdit the draftDismiss

Nothing happens in your tools until someone presses approve — and the approval lands on the record with a name against it.

No approval available

Read-only, permanently.

Your accounting ledger
Your billing system
Payment records

There is no setting that turns this on, because it isn’t a permission Beacon holds. The systems your auditors care about are read, and only read.

When something is missing

It stops rather than guesses.

Most reporting fails quietly — a sync that stalled, a number quietly estimated to fill a hole. Beacon’s failure mode is saying so, in the place the number would have been.

Every source connected
$48.2M
ARR, this morning
Billing · synced 14 min ago · sealed
Ask twice, get the same figure twice. Months later, replay it exactly as it stood.
One source not connected
Pipeline forecast unavailable until your CRM is connected.
A named limit in the exact spot the number belongs. Not an estimate, not a blank cell, not a quiet zero.
Billing not connected
Revenue figures do not compute. Beacon stops.
Without the system of record for money, there is nothing honest to say — so nothing runs, rather than running on a guess.
Fixed in every setup

Eight things Beacon never does. For anyone.

Not settings. Not defaults you could change later. These hold however Beacon is configured, for every customer — which is what makes them worth your CTO’s half hour.

01

Never computes a headline figure with AI — every number comes from the same deterministic engine, the same way every time.

02

Never decides, and never seals a decision itself.

03

Never overwrites a sealed record — the history only ever gets added to.

04

Never asks for or stores your credentials.

05

Never changes who can see what. Your administrator does.

06

Never acts in your systems without a person’s approval.

07

Never writes to your books or your billing ledger.

08

Never shows a figure it can’t trace, or guesses one it doesn’t have.

For your technical review

The technical brief, published up front.

What Beacon touches, what it never will, the access to check and the questions a review asks — written to be approved, or to fail fast if we’re not a fit. Read it before you ever talk to us.

What this buys you

Your security review starts before your first call.

For you

A vendor review you can run yourself.

The brief is published, so your team can start checking on the day they hear the name — no call to book, no NDA to sign first.

For your team

Nobody hands over a password.

Every connection is made and cut in your own tools, by your own admin. Turning Beacon off never needs a conversation with us.

For your CTO and your board

Boundaries you can check, not trust.

The same eight nevers hold in every configuration, and every approval, access change and refusal lands on a record that can be replayed.

Start behind the boundary

Connect a source. Keep every key.

You authenticate in your own tools — Beacon never sees a password. Free at any size, no card, no clock.