Free Consultation
Security & Trust

Security & Trust

How BeeWeb protects your code, your data, and your clients.

When you work with BeeWeb, you share something that matters: your source code, your credentials, and sometimes your customers' data. We are an Armenian IT outsourcing company with 11 years of experience and 100+ clients — including companies in US fintech and healthtech, where a security failure is not just a technical problem.

This page describes exactly what security controls we have in place today, what we are honest about not having yet, and what you can ask us to prove.

Compliance status

What we have in place today

Every item marked Active is implemented and in force as of April 2026 — not aspirational, not planned.

ItemStatusDetails
Information Security Policy (ISP-001)ActiveSigned by CEO Karen Hovhannisyan. Mandatory for all staff and contractors. Effective April 23, 2026.
AI Tools Usage Policy (ISP-008)ActiveGoverns use of Claude Code, GitHub Copilot, ChatGPT, Cursor. Enterprise tiers only. Client code never sent to public AI.
Mandatory peer code reviewActiveNo code reaches production without approval from a second engineer via GitHub pull request. Branch protection enforced.
NDA — all personnelActiveEvery employee and contractor signs an NDA before receiving access to any client system or project material.
Named Compliance LeadActiveKaren Hovhannisyan (Co-founder & CTO) holds named, documented accountability for BeeWeb's security program.
US legal entity — DelawareActiveBeeWeb is registered in Delaware, USA. US contract law applies to US client engagements.
SOC 2 Type 1 auditIn ProgressFormal audit underway. Expected completion Q2 2026.
MFA enforcement — all systemsIn ProgressBeing rolled out across all company systems. Target: complete before SOC 2 Type 1.
MDM on all devicesIn ProgressImplementation in progress. Required for SOC 2.
Background checks — all staffPlannedScheduled before SOC 2 Type 1 completion.
Security controls

What we do to protect every client engagement

Four controls that are active on every BeeWeb project today, without exception.

  • Every code change is peer-reviewed

    No code written by a BeeWeb engineer reaches a client's production environment without being reviewed and approved by a second engineer via GitHub pull request. This is not a guideline — it is enforced by branch protection rules on every client repository. Direct commits to production branches are blocked for everyone, including senior engineers. Every change to your codebase is documented, attributed to a named engineer, and verified by a qualified second person before it ships.

  • Every person signs an NDA before touching your project

    Before any BeeWeb employee or contractor receives access to a client system, repository, or project material, they sign a Non-Disclosure Agreement. This is a condition of engagement — not optional, not retroactive. The NDA covers source code, credentials, customer data, and all project materials for the duration of the engagement and after it ends.

  • Formal written security policies — signed and active

    BeeWeb operates under two formal written security policies, both signed by our CEO and effective April 2026: the Information Security Policy (ISP-001) covering access control, encryption, change management, audit logging, incident response, and personnel security; and the AI Tools Usage Policy (ISP-008) governing exactly how our engineers use AI coding tools. Both are available to clients under NDA — email security@beewebsystems.com to request them.

  • A named person is accountable for security

    Karen Hovhannisyan, BeeWeb's Co-founder and CTO, is our named Compliance Lead. She has documented accountability for our security program, our SOC 2 audit journey, and incident response. If you have a security question at any point in your engagement, you can ask to speak with her directly.

Client data

Client data protection

What we do with your source code, credentials, and project data

When you work with BeeWeb, we handle your Client Project Data — source code, credentials, API keys, documentation, and any customer data you share with us. Here is exactly how it is treated.

  • Accessible only to engineers assigned to your specific engagement. No one else inside BeeWeb has access.
  • Never shared with any third party without your explicit written authorisation.
  • Never used to train AI models or for any purpose outside your agreed engagement.
  • Returned to you or permanently deleted within 30 days of project completion, with written confirmation provided.
  • If we detect or suspect unauthorised access to your data, you hear from us within 72 hours of discovery.

Every person who touches your project has signed a Non-Disclosure Agreement before their first day of access. This is a condition of employment and contracting at BeeWeb — not optional.

Plain answers to the questions every CTO asks

What we do with your dataAnswerDetail
Share your source code or credentials with third partiesNeverClient materials are never shared without explicit written authorisation from you.
Use your code or data to train AI modelsNeverClient code and data are never submitted to any AI tool for training purposes.
Retain your data after project completionNeverAll client data returned or deleted within 30 days of project close, with confirmation.
Notify you of a security incidentYesYou are notified within 72 hours of any confirmed or suspected breach affecting your data.
Sign NDAs and data processing agreementsYesWe sign client-provided NDAs and DPAs before any project begins. Standard templates available.
Use AI tools on your codebaseConditionallyOnly with your written authorisation, only on enterprise-tier tools, only with peer review.
Conduct background checks on engineersPlannedScheduled before SOC 2 Type 1 completion. All engineers sign NDAs today.
AI & security

AI tools & security

We use AI tools. Here is exactly how.

BeeWeb engineers use AI coding assistants — Claude Code, GitHub Copilot, ChatGPT, and Cursor. This makes them faster and the code better. It also creates security risks we take seriously, which is why we have a formal written AI Tools Usage Policy (ISP-008, effective April 2026).

What we always do

  • Use only enterprise or team tiers of approved AI tools — never free consumer accounts.
  • Require all AI-generated code to go through the same peer review as human-written code.
  • Obtain written client authorisation before using AI tools on regulated codebases (fintech, healthtech).
  • Log all AI tool usage in production workflows, attributed to a named engineer.
  • Sign in to AI tools with BeeWeb company accounts — personal accounts are prohibited.

What we never do

  • Paste client source code, credentials, or API keys into any public AI interface.
  • Use AI tools to process client personal data or protected health information.
  • Use personal AI accounts for client work.
  • Merge AI-generated code without human review and approval.
  • Use free-tier AI tools where submitted content may be used for model training.

Why enterprise tiers matter

Enterprise and team tiers of AI tools (Claude Team, GitHub Copilot Business, ChatGPT Team, Cursor Business) contractually prohibit the use of submitted content for model training. Your code stays yours.

Free and personal tiers do not carry these guarantees. BeeWeb's policy prohibits their use for any client work — enforced, not voluntary.

Which AI tools BeeWeb engineers are approved to use

ToolRequired tierKey restriction
Claude Code / Claude.aiTeam or EnterpriseClient code never submitted to public interface
GitHub CopilotBusiness or EnterpriseSigned in with BeeWeb GitHub organisation account
ChatGPT / OpenAI APITeam or EnterpriseTraining opt-out must be enabled and verified
CursorBusiness tier onlyPrivacy Mode must be enabled at all times
Any other AI toolWritten approval requiredAI Governance Owner must approve before use on any client work
Straight talk

What we are honest about

Many outsourcing companies publish security pages full of claims they cannot prove. We do not.

What we have today

  • Written Information Security Policy (ISP-001), signed and active since April 2026
  • Written AI Tools Usage Policy (ISP-008), signed and active since April 2026
  • Employee NDA covering all personnel — includes AI tools clause and client data obligations
  • Mandatory peer code review enforced via GitHub branch protection
  • Named Compliance Lead with documented accountability
  • US Delaware entity — US contract law applies
  • SOC 2 Type 1 audit in progress

What we are implementing right now

  • Company-wide MFA enforcement across all systems
  • Mobile Device Management (MDM) on all employee devices

What we are targeting

  • Background checks on all personnel, before SOC 2 Type 1 completion

If you need documentation of our current security posture, email security@beewebsystems.com and we will share ISP-001 under NDA within 24 hours.

FAQ

Frequently asked questions

BeeWeb is currently pursuing SOC 2 certification. Our SOC 2 Type 1 audit is in progress with an expected completion date of Q2 2026. In the meantime, our Information Security Policy (ISP-001) is available to prospective clients under NDA on request. Email security@beewebsystems.com.

Contact

Security questions or due diligence requests

Security questionnaires

Send us your vendor security questionnaire. We return it completed within 5 business days.

Policy and NDA requests

Request ISP-001 or ISP-008 under a mutual NDA. Documents shared within 24 hours of NDA signing.