Skip to content

Legal

Security Practices

Effective 2026-04-28·Last updated 2026-04-28·HEOSSI (Pte.) Ltd.

This document describes the program-level security practices HEOSSI follows in operating Bee. Customer-facing technical detail is consolidated in TrustHub at /trust#security; this page is intended for procurement, vendor-risk, and audit teams.

1. Cryptography

  • API path: TLS 1.3 minimum.
  • Data at rest: AES-256-GCM with per-object data-encryption keys wrapped under service-managed per-tenant key-encryption keys on shared cloud. Customer-controlled keys are scoped to separately contracted Enclave Regulated or Sovereign deployments.
  • Key rotation: at most 90-day cadence for tenant DEKs; KEKs every 12 months or on personnel-departure trigger.

2. Identity, authentication, and access

  • Customer authentication: email/password, OAuth (Google, GitHub, Microsoft), SSO/SAML on Hive+. MFA available for all tiers; required for Hive+ admins.
  • Operator authentication: hardware-backed FIDO2 (WebAuthn) is the only path to production access. No long-lived static credentials in production.
  • Operator access: just-in-time, audited, time-bounded, with a written reason. Reviewed quarterly.

3. Secrets and key management

Production secrets are stored in dedicated secret managers (per-environment), never in source control. CI uses short-lived OIDC-issued credentials. Secret-scanning runs on every push to detect accidental disclosure.

4. Vulnerability management

  • Dependency scanning runs on every CI build (npm, pip).
  • Static analysis (SAST) runs on every change set.
  • Automated dependency, secret, and security checks run in the release pipeline. Independent penetration testing is commissioned when required by an enterprise engagement or assurance programme; we do not claim a completed annual external test unless a current report exists.
  • Bug bounty / responsible-disclosure program runs via the security inbox; safe-harbour terms published.

5. Logging, monitoring, and audit

Authentication events, admin actions, and material data accesses are logged centrally; logs are tamper-evident and retained per the Privacy Policy. Workspace audit logs (Hive+) are exposed to customers.

6. Incident response

  • Automated monitoring and alerting operate continuously. Human response is best-effort outside staffed operating hours unless a customer Order Form expressly includes a contracted support or incident-response SLA.
  • Severity classification: SEV-1 (customer impact, data exposure), SEV-2 (degraded service), SEV-3 (single-tenant impact), SEV-4 (no customer impact).
  • Customer notification of data breaches within 72 hours of confirmation. Public post-mortems for SEV-1 within 14 days.

7. Personnel

Background checks where permitted by local law. Annual security-awareness training. Confidentiality obligations survive termination. Production access removed within 1 hour of role change.

8. Physical security

Production workloads run on Modal serverless infrastructure (primary inference), Vercel application infrastructure, and managed data services. Hugging Face hosts model cards and dataset metadata rather than Bee's primary live inference surface. Physical and environmental security is inherited from the applicable hosting provider; provider scope can change and is maintained in the sub-processor schedule.

9. Vendor management

Sub-processors are listed in Schedule A of the DPA. We assess each for SOC 2 / ISO 27001 / equivalent attestations, data-protection terms, and termination provisions before onboarding. Material changes go through the changelog with at least 14 days' notice.

10. Vulnerability disclosure

Reach us at bee-security@heossi.com. We acknowledge within 24 hours and aim to remediate critical vulnerabilities within 7 days. RFC 9116 contact published at /.well-known/security.txt. PGP key on request. We commit not to pursue legal action against good-faith researchers.

11. Attestations

Parent HEOSSI (Pte.) Ltd. holds CSA STAR Level 1; ISO 27001 track in progress. SOC 2 Type II is on the 2026 roadmap. Procurement-grade evidence available under NDA via the security address.

Questions about this document? Contact bee-security@heossi.com. Service of process: bee-legal@heossi.com (HEOSSI (Pte.) Ltd., Singapore).

Counter-signed copies on request. The text on this page is the canonical published version. For procurement teams that need a counter-signed copy of the Terms, DPA, or Order Form, email bee-legal@heossi.com. Where there is conflict between this page and an executed counter-signed agreement, the counter-signed agreement controls.

HEOSSI (Pte.) Ltd. · Singapore · heossi.comSee evidence index →