BetonX.

Trust

Security Documentation

BetonX designs its platforms for institutional workflows where project assumptions, technical evidence, and decision records require careful handling.

Infrastructure Overview

BetonX services are cloud-hosted and designed around separation of environments, managed infrastructure, monitored application services, and controlled administrative access.

Production systems are operated with change discipline, backup practices, and service monitoring appropriate for a B2B SaaS platform in active development.

Encryption

BetonX uses encrypted transport for web traffic and service communications where supported. The target posture is TLS 1.3 for data in transit and AES-256 or equivalent managed encryption for data at rest.

Secrets and credentials are not intended to be stored in source code. Access keys are managed through environment configuration and provider controls.

Access Controls

Platform access is invite-only and role-based. Users are assigned permissions according to organization, project, and workflow needs.

Administrative access follows least-privilege principles. Access may be reviewed, limited, or revoked when personnel roles change or when risk conditions require it.

Audit Logging and Monitoring

BetonX records operational logs to support troubleshooting, security review, abuse detection, and incident investigation.

Audit events may include authentication activity, access changes, analysis workflow events, administrative actions, and system errors.

Vulnerability Disclosure

Security researchers and partners should report suspected vulnerabilities through the company contact email listed on this site.

Reports should include a clear description, affected URL or component, reproduction steps, potential impact, and contact information for follow-up. Do not access, alter, or exfiltrate data that is not your own.

Incident Response

BetonX maintains an incident response process covering triage, containment, investigation, remediation, communication, and post-incident review.

If an incident affects customer data, BetonX will notify affected organizations as required by applicable agreements and law.

SOC 2 Readiness

BetonX is building toward a SOC 2 readiness posture. Formal certification status should be confirmed directly with BetonX before being used as a procurement requirement.

Current practices are designed to support future control maturity across security, availability, confidentiality, and change management.

Security Contact

Report security issues to the company contact email listed on this site with a subject line that includes Security Report.