Trust Center
Security is non-negotiable in finance.
We are building BeyondNumbers.AI to the standards finance and accounting leaders already expect of their ERP, their auditor, and their bank. Here is where we are, and where we are going.
Compliance
Where we stand today.
In progress
SOC 2 Type II
Currently in the readiness phase. Targeting Type I attestation in 2026, followed by Type II observation period.
In progress
GDPR & PIPEDA
Data Processing Agreements available on request. Built with privacy-by-design principles for both EU and Canadian data subjects.
Roadmap
ISO 27001
Planned after SOC 2 Type II is achieved. We are designing our ISMS to support both frameworks in parallel.
Security program
How we protect your data.
Data protection
Customer data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Production data is logically isolated per tenant and never used for model training.
Access control
Least-privilege access enforced across all systems. SSO and MFA required for all team members. Production access is audited and time-bound.
Infrastructure
Hosted on enterprise-grade cloud infrastructure (SOC 2 Type II certified providers) with hardened network controls, automated patching, and continuous monitoring.
Secure development
Code review on every change, dependency scanning, secrets scanning, and automated security testing in CI. Quarterly access reviews and policy training.
Incident response
Documented incident response plan with defined severity levels, on-call rotation, and customer notification commitments aligned with contractual SLAs.
Sub-processors
We maintain a current list of sub-processors and notify customers of material changes. All sub-processors are vetted for security and privacy posture.
Transparency
We will tell you what we know, and what we don't.
We are an early-stage company building toward the same controls our enterprise customers will require. This page is updated as our program matures.
Do you use customer data to train AI models?
No. Customer data is never used to train foundation models or shared models. Customer-specific intelligence stays inside the customer's tenant.
Where is data hosted?
On enterprise cloud infrastructure in North America. Data residency options for EU customers are on our roadmap.
Do you sign DPAs and BAAs?
We sign DPAs today. BAA support will follow as we expand into regulated verticals.
Can I get a copy of your security documentation?
Yes. Reach out to security@beyondnumbers.ai and we will share what we have, under NDA where appropriate.