Security

Read-only, in your cloud, and auditable.

Northbeam holds no copy of your product data. The architecture is the security control — everything below is the paperwork around it.

warehouse connection
SFSnowflakeread-only
nbNorthbeamno copy stored
UIYour pulses90s to first result
SOC 2 Type IGDPREU data residencyYour cloud

Certification

SOC 2 Type I

Achieved September 2025. Type II audit in progress, report expected Q3 2026.

GDPR

EU data residency in eu-west-1. DPA available on the Scale tier.

Encryption

In transit

TLS 1.3 on every connection, including the warehouse adapters.

At rest

AES-256 for everything we store, which is metadata and pulse definitions — not your product data.

Access

SSO

Google, Okta and Azure AD on the Scale tier.

Read-only by design

Northbeam never requests write access to your warehouse, and every query it compiles is logged in plain SQL.

Disclosure

Responsible disclosure

[email protected], PGP key published. First response within 24 hours.

Bug bounty

Rolling programme, €100 to €5,000 per validated finding, with public credit if you want it.

Sub-processors

Everyone who touches anything

Scale customers are notified at least 30 days before a new sub-processor begins processing, with a contractual right to object.

Amazon Web Services (eu-west-1)VercelStripeGoogle WorkspaceNotion

Send us your security questionnaire.

Scale includes a SOC 2 report, a signed DPA and a review call with Lior.