Security at Beedux
A plain-language summary of the security practices and product controls Beedux uses today.
Last updated: July 2, 2026
1. Security at Beedux
Beedux is a self-service B2B approval workflow and decision-governance platform. This page summarizes, in plain language, the security practices and product controls Beedux uses today — for prospective customers, reviewers, and anyone evaluating the platform.
This page is a summary, not a legal document. Legal and privacy commitments are set out in our Terms of Service and Privacy Policy, which control if anything here conflicts with them.
2. Access Control and Roles
Beedux uses role-based access control (RBAC) to scope what each person can see and do. Access to workflows, documents, settings, and administrative areas is controlled by role, not left open by default.
Beedux includes the following built-in role categories: Account Owner, Administrator, Workflow Manager, Auditor, and User. Each role has a defined set of permissions. Roles may be assigned at the workspace and/or organization level, depending on the area and configuration, so access can be scoped to the appropriate workspace or organization context.
3. Approval Records and Audit Trails
Beedux records approval actions, comments, decisions, and related workflow activity in an audit trail as they happen. This is designed to support accountability and recordkeeping for approval decisions.
The audit trail is a product feature, not a legal certification. Beedux provides workflow controls, audit trails, and decision records, but customers remain responsible for their own legal, regulatory, and internal compliance obligations.
4. Data Protection and Ownership
You retain ownership of the data, documents, and content you submit to Beedux. Beedux does not claim ownership of your content.
Beedux uses security controls including authentication, role-based access control, and encryption where supported by our infrastructure providers, to help protect data in the platform.
5. Public and Private Surface Separation
Beedux separates its public pages — such as this one, the homepage, pricing, and FAQ — from the authenticated product. Application, administrative, and API areas require sign-in and are not intended for public indexing.
This separation is part of how Beedux is designed to reduce the surface area that is reachable without authentication.
6. Backups and Operational Resilience
Beedux maintains production backup and restore procedures as part of launch readiness. Restore procedures have been documented and exercised.
We do not publish specific recovery-time or recovery-point figures on this page. If you need details for a procurement or security review, contact
[email protected].
7. Email Authentication and Trusted Notifications
Beedux sends product notifications from an authenticated Beedux notification domain. Email authentication controls such as SPF, DKIM, and DMARC are configured for Beedux notification email, which is designed to help reduce spoofing of Beedux-branded email.
Email authentication reduces certain kinds of spoofing risk; it does not mean every email client or provider will treat every message identically.
8. What Beedux Does Not Claim
Beedux does not currently claim formal third-party security certifications, attestations, or compliance reports for frameworks such as SOC 2, ISO 27001, HIPAA, PCI, or similar standards. Beedux provides workflow controls, audit trails, and decision records, but using Beedux does not by itself make a company compliant with any law, regulation, or industry standard.
Formal certifications, attestations, or compliance reports, if obtained or published, will be listed on this page.