Security
Security and control at every layer
Encryption, access control, audit logging, and compliance, all built into the platform from day one.
Data protection
Encryption at every layer
- TLS encryption for all data in transit
- AES encryption for data at rest
- HMAC-SHA256 signed webhooks with timestamp tolerance
- Consent records stored per contact with opt-in source and timestamp
Access control
Who gets in, and what they can do
- Role-based access control (RBAC) across workspaces
- Per-session permission scoping
- Single sign-on with SAML (Enterprise)
- Multi-factor authentication support
Visibility
Audit logging and monitoring
- Immutable activity audit trails
- Session health events over WebSocket
- Webhook delivery logs with retry tracking
- Real-time failure alerts
Infrastructure
Where it runs
- Cloud-agnostic: deploy on any major provider
- On-premise deployment option (Enterprise)
- Environment separation between production and testing
- Sandbox sessions for safe development
Compliance
Compliance posture
- SOC2-ready controls in place
- GDPR-oriented tooling built in
- Data retention agreements available on request
- Subprocessor list available to customers
See what Beacon does with your WhatsApp traffic
Tell us what you're building. We'll show you the platform and talk numbers.
Talk to us