Skip to content

Enterprise security & procurement

Evaluate Bee from evidence, not sales claims.

Architecture, data boundaries, contracts, assurance posture, deployment availability, and operational evidence in one place. Every capability is labelled by its current delivery state.

Published boundaries

Current limitations sit beside delivered capabilities.

Contractual controls

Customer-specific controls belong in the Order Form and manifest.

Deployment clarity

Hosted, customer-scoped, and roadmap states are kept distinct.

Evidence routes

Legal, trust, status, and architecture evidence stays directly reachable.

Capability register

What is available today

“Customer-scoped” means the control is not a universal self-serve feature. It must be confirmed and contracted for the specific deployment.

OpenAI-compatible API

Live

Chat Completions-compatible API, SDK, CLI, and MCP integration paths.

Evidence

Multimodal understanding

Live

Tier-aware text, image, audio, and video understanding.

Evidence

Team administration

Live

Seats, pooled usage, plan controls, and organisation administration.

Evidence

Shared team context

In progress

Cross-member projects, conversations, and document context are not generally available yet.

Evidence

Enterprise identity and audit controls

Customer-scoped

SSO/SAML, audit evidence, and operating controls are fixed in the Order Form and deployment manifest.

Evidence

Private cloud deployment

Customer-scoped

Single-customer deployment boundaries are designed and contracted per engagement.

Evidence

Sovereign controls

Customer-scoped

Locality, operators, keys, infrastructure, and transport are scoped contractually.

Evidence

Post-quantum transport

Customer-scoped

The NIST FIPS 203/204/205 high-assurance path is separately scoped; public tiers use TLS 1.3.

Evidence

Self-hosted and air-gapped operation

Roadmap

Broader customer-operated and disconnected deployment is not generally available today.

Evidence

Assurance posture

Certifications are never implied.

HEOSSI (PTE.) LTD. owns and administers the company compliance programme and is the prospective certificate holder. BEE, QNSI, and other HEOSSI offerings may be included within the documented organisational or technical scope; they are not separate certificate holders. ISO/IEC 19790 applies only to specifically identified cryptographic modules or components.

ISO/IEC 27001:2022

Information Security: Evaluated and aligned under ISO/IEC 27001:2022.

ISO/IEC 42001:2023

AI Governance & Safety: Developed and maintained under ISO/IEC 42001:2023.

ISO/IEC 19790:2025

Data Encryption Standards: Core cryptographic components verified under ISO/IEC 19790:2025.

Internal framework posture; accredited certification and independent conformity assessment are not claimed.

Tentative target: Q4 2026 or Q1 2027, subject to funding.

Architecture

A reviewable request boundary.

01

Experience and integration

Web workspace, Android, desktop preview, OpenAI-compatible API, SDKs, CLI, and MCP clients.

02

Identity and tenant boundary

Authentication, organisation context, API keys, entitlements, rate limits, and tenant resolution.

03

Workflow orchestration

Conversation state, tool execution, structured output, retrieval, memory, and scheduled work.

04

Specialist intelligence

BSIS combines 66 specialist domain families with permitted research evidence, 17 restricted and safety profiles, tools, evaluations, and governed reasoning models; versioned Domain Pack runtime is in progress.

05

Intelligence routing

Tier-aware capability selection, governed Bee releases, safety policy, and workload routing.

06

Data and retrieval

Tenant-scoped documents, indexes, citations, retention controls, and deployment-specific storage.

07

Governance and assurance

Telemetry, evaluation gates, audit evidence, release records, policy, and operational review.

08

Deployment boundary

Hosted cloud today, with regulated and Enclave environments scoped through contracts and manifests.

Deployment boundary summary

Bee hosted cloud: Live · Bee Regulated Cloud: Customer-scoped · Bee Enclave Private Cloud: Customer-scoped · Bee Enclave Regulated: Customer-scoped · Bee Enclave Sovereign: Customer-scoped

Review the full reference architecture and scenario flows