Skip to content

Enterprise security & procurement

Evaluate Bee from evidence, not sales claims.

Architecture, data boundaries, contracts, assurance posture, deployment availability, and operational evidence in one place. Every capability is labelled by its current delivery state.

Published boundaries

Current limitations sit beside delivered capabilities.

Contractual controls

Customer-specific controls belong in the Order Form and manifest.

Deployment clarity

Hosted, customer-scoped, and roadmap states are kept distinct.

Evidence routes

Legal, trust, status, and architecture evidence stays directly reachable.

Capability register

What is available today

“Customer-scoped” means the control is not a universal self-serve feature. It must be confirmed and contracted for the specific deployment.

OpenAI-compatible API

Live

Chat Completions-compatible API, SDK, CLI, and MCP integration paths.

Evidence

Multimodal understanding

Live

Tier-aware text, image, audio, and video understanding.

Evidence

Team administration

Live

Seats, pooled usage, plan controls, and organisation administration.

Evidence

Shared team context

In progress

Cross-member projects, conversations, and document context are not generally available yet.

Evidence

Enterprise identity and audit controls

Customer-scoped

SSO/SAML, audit evidence, and operating controls are fixed in the Order Form and deployment manifest.

Evidence

Private cloud deployment

Customer-scoped

Single-customer deployment boundaries are designed and contracted per engagement.

Evidence

Sovereign controls

Customer-scoped

Locality, operators, keys, infrastructure, and transport are scoped contractually.

Evidence

Post-quantum transport

Customer-scoped

The NIST FIPS 203/204/205 high-assurance path is separately scoped; public tiers use TLS 1.3.

Evidence

Self-hosted and air-gapped operation

Roadmap

Broader customer-operated and disconnected deployment is not generally available today.

Evidence

Assurance posture

Certifications are never implied.

CSA STAR Level 1

ISO 27001

In progress

SOC 2 Type II

Roadmap

HIPAA

Contractual workload and control scoping; not a general Bee certification claim.

Customer-scoped

Architecture

A reviewable request boundary.

01

Experience and integration

Web workspace, Android, desktop preview, OpenAI-compatible API, SDKs, CLI, and MCP clients.

02

Identity and tenant boundary

Authentication, organisation context, API keys, entitlements, rate limits, and tenant resolution.

03

Workflow orchestration

Conversation state, tool execution, structured output, retrieval, memory, and scheduled work.

04

Intelligence routing

Tier-aware capability selection, governed Bee releases, safety policy, and workload routing.

05

Data and retrieval

Tenant-scoped documents, indexes, citations, retention controls, and deployment-specific storage.

06

Governance and assurance

Telemetry, evaluation gates, audit evidence, release records, policy, and operational review.

07

Deployment boundary

Hosted cloud today, with regulated and Enclave environments scoped through contracts and manifests.

Deployment boundary summary

Bee hosted cloud: Live · Bee Regulated Cloud: Customer-scoped · Bee Enclave Private Cloud: Customer-scoped · Bee Enclave Regulated: Customer-scoped · Bee Enclave Sovereign: Customer-scoped