Useful access.Small blast radius.

Beaam asks for the narrowest credentials each provider allows to your production stack. That deserves a straight account of how they are handled and what happens when something goes wrong.

The trade you are being asked to make

Monitoring is intrusive by nature: to tell you your database is struggling, something has to be allowed to look at your database. The honest framing is not "Beaam is secure" but "here is exactly what Beaam can do, and what an attacker would get if they took it."

Everything below is implemented, not aspirational. Where a control does not exist, this page says so.

Access is scoped, and never changes your infrastructure

Beaam never changes your infrastructure. There is no code path that restarts, scales, deploys, deletes or remediates anything in a connected account. That is a property of Beaam's code, not of every credential it holds: a token wider than Beaam needs could write, in someone else's hands. So make the narrow grant each integration page names; where a provider cannot grant less than full access (Netlify, Resend), the page says so.

There is exactly one kind of write, on exactly two integrations: Beaam registers an endpoint so the provider can push events to it. Connecting Resend creates one webhook; signing in with Vercel creates one runtime Log Drain. A failed connect removes it again, and so does disconnecting. If the provider refuses, Beaam says exactly what to delete and where.

You are never asked to create a user or paste a credential that cannot be rotated from your side, because a credential you cannot revoke is one you have lost control of. Each integration documents the narrow read scope it needs and nothing wider, and where a provider supports role assumption with an external ID rather than a long-lived key, Beaam uses it.

Credentials at rest

Integration credentials are encrypted with AES-256-GCM through the Web Crypto API before they reach the database. The key lives as a Cloudflare Worker secret and is never exposed to browser code. Decryption happens server-side in exactly two places: the collection path, and the refresh of an OAuth grant that is about to expire. Never in a browser, never in a log.

Disconnecting an integration deletes its credentials immediately rather than marking a row inactive.

Earlier builds used XChaCha20-Poly1305 via libsodium. That was replaced because Cloudflare Workers block runtime WASM compilation, and existing rows were migrated in one shot. This page previously still named the old cipher — a stale claim, corrected on 28 July 2026.

Tenant isolation is enforced by the database

Row Level Security is on for every table, and every policy scopes rows to your organization membership. This matters more than it sounds: isolation enforced in application code fails whenever a single query forgets a where clause. Enforced in Postgres, a forgotten check returns nothing rather than someone else's data.

The service role that can bypass RLS exists only in server-side code — it is never shipped to the browser, and the one permitted direct use of the database from a page is reading the current session.

Outbound requests you control

Beaam calls endpoints you supply: HTTP checks, MCP servers, Slack webhooks, your own webhook receivers. That is a server-side request forgery surface, and it is treated as one. All of them pass shared controls on scheme, port, DNS resolution, redirect following, private-network ranges, request duration and response size — so a URL pointing at internal metadata services or a rebound DNS name does not become a way to make Beaam fetch something on an attacker's behalf.

Failure independence

The watchdog runs on a separate cloud account with its own secrets and its own state, sharing no database, no deploy pipeline and no failure domain with the application. This is the difference between a real control and a diagram: a watchdog inside the system it watches goes down with it, precisely when you need it.

It probes the application, collection freshness, the marketing site and alert delivery every minute — and is itself watched, both by the application and by a third-party dead-man's switch, drawn in full on the architecture page. It alerts Beaam's operator if the service goes quiet. It is an operational control on the platform, not a per-customer notifier — what reaches you directly is the daily heartbeat and per-account silence detection on your own collectors.

Billing cannot be self-granted

Paid entitlements change only from a verified Polar webhook. There is no client-side upgrade path and no debug route that promotes an account — a browser-side toggle that grants a paid tier is a revenue bug and a security bug at once.

What Beaam does not have

  • No SOC 2, ISO 27001 or other certification, and no plan to claim one until it is real
  • No SSO or SAML — email and password with leaked-password checking, or sign in with Google or GitHub
  • No customer-managed encryption keys
  • No formal bug-bounty programme, though reports are very welcome
  • No 24/7 staffed security response — one founder, one time zone

Data handling

Raw metric samples expire after 30 days in both stores, enforced by a scheduled prune in Postgres and a TTL in the telemetry store. Incidents, alerts and delivery records are retained while your account is active, because that history is what you look back at after an outage. Deleting your account removes your identity and control-plane records immediately, and the Postgres rows that hang off them; raw samples already in the telemetry store expire on the 30-day window rather than being deleted on the spot.

Every processor is listed publicly on the subprocessors page, along with its data-processing agreement status. Traffic on this marketing site is measured with Plausible — cookieless, EU-hosted, no cross-site identifier, and no IP address stored. Google Analytics and Google Ads measurement are separate: in the EU, the wider EEA, the UK and Switzerland the Google tag loads only after explicit permission, elsewhere it runs unless declined, and a decline is honoured on both sites; Analytics measures the public marketing journey and one completed signup, and Ads may attribute that signup to Beaam's own campaign. Neither receives an email address or signed-in product activity; Google signals, advertising personalization and enhanced conversions are off. There is no Segment or session recording.

Reporting a vulnerability

Email support@beaam.app with “Security” in the subject. It reaches the person who wrote the code. Please do not include credentials or production data in a first message. We will acknowledge, and we will tell you honestly if something is a known limitation rather than a finding.

Questions

What access does Beaam need to my infrastructure?

As little as each provider allows, and Beaam never changes your infrastructure. Most connections are read-only. Two providers cannot grant less than full access — Netlify has no scopes at all, and Resend's only key that can read domains is full access — and Beaam only reads with those grants. Each integration page names exactly what it needs. Beaam makes one kind of write, on two integrations: registering a delivery endpoint so the provider can push events to it — a webhook in Resend, and a runtime Log Drain in Vercel when you sign in.

How are my credentials stored?

Encrypted with AES-256-GCM via the Web Crypto API before they reach the database, using a key held as a Cloudflare Worker secret that is never exposed to browser code. They are decrypted server-side only — when collecting, and when refreshing an OAuth grant — and deleted the moment you disconnect the integration.

Can another customer see my data?

Row Level Security is enabled on every table and every policy is scoped to organization membership, enforced by Postgres rather than by application code. A missing check in a query cannot leak another tenant's rows.

What happens to my data if I leave?

Deleting your account removes your authentication identity and control-plane records immediately, and foreign-key cascades remove the incidents, alerts and samples stored in Postgres with them. Copies of raw samples in the telemetry store are not deleted on the spot; they expire on the 30-day retention window. Nothing identifies you in that store after the control-plane rows are gone.

Do you have SOC 2?

No. We will say that plainly rather than imply otherwise with security-theatre language. SOC 2 is out of scope until an enterprise customer needs it. If it is a hard requirement today, Beaam is not the right fit.

This page describes implemented controls, not a certification claim.