Security at Beviso

Last updated 27 September 2026

Beviso holds sensitive information about how our customers run security. This page describes how we protect it.

Tenant isolation

Every record in Beviso belongs to exactly one organisation, and every query is scoped to the organisation of the signed-in user. Members only see workspaces they have been invited to.

Read-only integrations

  • Beviso only reads from the tools you connect and never changes their configuration.
  • AWS connects through a cross-account IAM role with an external ID, so no AWS access keys are shared.
  • Microsoft and Google connect through admin consent, and GitHub through a GitHub App you install and can revoke.
  • You can disconnect an integration at any time.

Access and sessions

Session cookies are HTTP-only and sent only over HTTPS. Administrative actions such as enabling frameworks or managing members require an admin role.

Encryption

All traffic to Beviso is served over HTTPS.

Tokens and keys for the tools you connect are encrypted with AES-256-GCM before they are stored, and each is bound to its workspace so it cannot be read in the context of another.

Responsible disclosure

If you believe you have found a security issue, email support@beviso.app. Please give us reasonable time to fix it before disclosing it publicly. We will not take action against good-faith research that respects our customers’ data.