Security & Trust
How BeeWeb protects your code, your data, and your clients.
When you work with BeeWeb, you share something that matters: your source code, your credentials, and sometimes your customers' data. We are an Armenian IT outsourcing company with 11 years of experience and 100+ clients — including companies in US fintech and healthtech, where a security failure is not just a technical problem.
This page describes exactly what security controls we have in place today, what we are honest about not having yet, and what you can ask us to prove.
What we have in place today
Every item marked Active is implemented and in force as of April 2026 — not aspirational, not planned.
| Item | Status | Details |
|---|---|---|
| Information Security Policy (ISP-001) | Active | Signed by CEO Karen Hovhannisyan. Mandatory for all staff and contractors. Effective April 23, 2026. |
| AI Tools Usage Policy (ISP-008) | Active | Governs use of Claude Code, GitHub Copilot, ChatGPT, Cursor. Enterprise tiers only. Client code never sent to public AI. |
| Mandatory peer code review | Active | No code reaches production without approval from a second engineer via GitHub pull request. Branch protection enforced. |
| NDA — all personnel | Active | Every employee and contractor signs an NDA before receiving access to any client system or project material. |
| Named Compliance Lead | Active | Karen Hovhannisyan (Co-founder & CTO) holds named, documented accountability for BeeWeb's security program. |
| US legal entity — Delaware | Active | BeeWeb is registered in Delaware, USA. US contract law applies to US client engagements. |
| SOC 2 Type 1 audit | In Progress | Formal audit underway. Expected completion Q2 2026. |
| MFA enforcement — all systems | In Progress | Being rolled out across all company systems. Target: complete before SOC 2 Type 1. |
| MDM on all devices | In Progress | Implementation in progress. Required for SOC 2. |
| Background checks — all staff | Planned | Scheduled before SOC 2 Type 1 completion. |
What we do to protect every client engagement
Four controls that are active on every BeeWeb project today, without exception.
Every code change is peer-reviewed
No code written by a BeeWeb engineer reaches a client's production environment without being reviewed and approved by a second engineer via GitHub pull request. This is not a guideline — it is enforced by branch protection rules on every client repository. Direct commits to production branches are blocked for everyone, including senior engineers. Every change to your codebase is documented, attributed to a named engineer, and verified by a qualified second person before it ships.
Every person signs an NDA before touching your project
Before any BeeWeb employee or contractor receives access to a client system, repository, or project material, they sign a Non-Disclosure Agreement. This is a condition of engagement — not optional, not retroactive. The NDA covers source code, credentials, customer data, and all project materials for the duration of the engagement and after it ends.
Formal written security policies — signed and active
BeeWeb operates under two formal written security policies, both signed by our CEO and effective April 2026: the Information Security Policy (ISP-001) covering access control, encryption, change management, audit logging, incident response, and personnel security; and the AI Tools Usage Policy (ISP-008) governing exactly how our engineers use AI coding tools. Both are available to clients under NDA — email security@beewebsystems.com to request them.
A named person is accountable for security
Karen Hovhannisyan, BeeWeb's Co-founder and CTO, is our named Compliance Lead. She has documented accountability for our security program, our SOC 2 audit journey, and incident response. If you have a security question at any point in your engagement, you can ask to speak with her directly.
Client data protection
What we do with your source code, credentials, and project data
When you work with BeeWeb, we handle your Client Project Data — source code, credentials, API keys, documentation, and any customer data you share with us. Here is exactly how it is treated.
- Accessible only to engineers assigned to your specific engagement. No one else inside BeeWeb has access.
- Never shared with any third party without your explicit written authorisation.
- Never used to train AI models or for any purpose outside your agreed engagement.
- Returned to you or permanently deleted within 30 days of project completion, with written confirmation provided.
- If we detect or suspect unauthorised access to your data, you hear from us within 72 hours of discovery.
Every person who touches your project has signed a Non-Disclosure Agreement before their first day of access. This is a condition of employment and contracting at BeeWeb — not optional.
Plain answers to the questions every CTO asks
| What we do with your data | Answer | Detail |
|---|---|---|
| Share your source code or credentials with third parties | Never | Client materials are never shared without explicit written authorisation from you. |
| Use your code or data to train AI models | Never | Client code and data are never submitted to any AI tool for training purposes. |
| Retain your data after project completion | Never | All client data returned or deleted within 30 days of project close, with confirmation. |
| Notify you of a security incident | Yes | You are notified within 72 hours of any confirmed or suspected breach affecting your data. |
| Sign NDAs and data processing agreements | Yes | We sign client-provided NDAs and DPAs before any project begins. Standard templates available. |
| Use AI tools on your codebase | Conditionally | Only with your written authorisation, only on enterprise-tier tools, only with peer review. |
| Conduct background checks on engineers | Planned | Scheduled before SOC 2 Type 1 completion. All engineers sign NDAs today. |
AI tools & security
We use AI tools. Here is exactly how.
BeeWeb engineers use AI coding assistants — Claude Code, GitHub Copilot, ChatGPT, and Cursor. This makes them faster and the code better. It also creates security risks we take seriously, which is why we have a formal written AI Tools Usage Policy (ISP-008, effective April 2026).
What we always do
- Use only enterprise or team tiers of approved AI tools — never free consumer accounts.
- Require all AI-generated code to go through the same peer review as human-written code.
- Obtain written client authorisation before using AI tools on regulated codebases (fintech, healthtech).
- Log all AI tool usage in production workflows, attributed to a named engineer.
- Sign in to AI tools with BeeWeb company accounts — personal accounts are prohibited.
What we never do
- Paste client source code, credentials, or API keys into any public AI interface.
- Use AI tools to process client personal data or protected health information.
- Use personal AI accounts for client work.
- Merge AI-generated code without human review and approval.
- Use free-tier AI tools where submitted content may be used for model training.
Why enterprise tiers matter
Enterprise and team tiers of AI tools (Claude Team, GitHub Copilot Business, ChatGPT Team, Cursor Business) contractually prohibit the use of submitted content for model training. Your code stays yours.
Free and personal tiers do not carry these guarantees. BeeWeb's policy prohibits their use for any client work — enforced, not voluntary.
Which AI tools BeeWeb engineers are approved to use
| Tool | Required tier | Key restriction |
|---|---|---|
| Claude Code / Claude.ai | Team or Enterprise | Client code never submitted to public interface |
| GitHub Copilot | Business or Enterprise | Signed in with BeeWeb GitHub organisation account |
| ChatGPT / OpenAI API | Team or Enterprise | Training opt-out must be enabled and verified |
| Cursor | Business tier only | Privacy Mode must be enabled at all times |
| Any other AI tool | Written approval required | AI Governance Owner must approve before use on any client work |
What we are honest about
Many outsourcing companies publish security pages full of claims they cannot prove. We do not.
What we have today
- Written Information Security Policy (ISP-001), signed and active since April 2026
- Written AI Tools Usage Policy (ISP-008), signed and active since April 2026
- Employee NDA covering all personnel — includes AI tools clause and client data obligations
- Mandatory peer code review enforced via GitHub branch protection
- Named Compliance Lead with documented accountability
- US Delaware entity — US contract law applies
- SOC 2 Type 1 audit in progress
What we are implementing right now
- Company-wide MFA enforcement across all systems
- Mobile Device Management (MDM) on all employee devices
What we are targeting
- Background checks on all personnel, before SOC 2 Type 1 completion
If you need documentation of our current security posture, email security@beewebsystems.com and we will share ISP-001 under NDA within 24 hours.
Frequently asked questions
BeeWeb is currently pursuing SOC 2 certification. Our SOC 2 Type 1 audit is in progress with an expected completion date of Q2 2026. In the meantime, our Information Security Policy (ISP-001) is available to prospective clients under NDA on request. Email security@beewebsystems.com.
Security questions or due diligence requests
Security questionnaires
Send us your vendor security questionnaire. We return it completed within 5 business days.
security@beewebsystems.comPolicy and NDA requests
Request ISP-001 or ISP-008 under a mutual NDA. Documents shared within 24 hours of NDA signing.
security@beewebsystems.com