TRUST CENTER

Everything a security reviewer will ask, answered before they ask it.

Northbeam holds warehouse inventory data for 610 mid-market retailers. This page exists so your security team can finish their review without four rounds of email.

Download the SOC 2 Type II
View sub-processors
SOC 2
Type II, audited 2026
ISO 27001
Certified since 2024
GDPR + DPDP
DPA available
99.99%
Uptime, trailing year

Controls in place today

Not a roadmap. Every item below is implemented, monitored and evidenced in the audit.

Encryption

AES-256 at rest on every volume and backup. TLS 1.3 in transit, HSTS preloaded, no TLS 1.0/1.1 endpoints anywhere.

Access

SSO-only for staff, hardware keys enforced, no standing production access. Every elevation is time-boxed and logged.

Isolation

Per-tenant row-level security enforced in the database, not the application layer. Verified by an external pentest each year.

Monitoring

Centralised audit log, 400-day retention, immutable. Anomalous access pages the on-call engineer within 90 seconds.

Resilience

Point-in-time recovery to any second in the last 35 days. Restores are rehearsed quarterly against production-sized data.

Vendors

Eleven sub-processors, all listed publicly. Any addition is announced 30 days before it processes customer data.

What we store

  • SKU, quantity, location and movement history
  • Purchase order metadata and supplier names
  • Your team members' work email and role
  • Audit events — who did what, when, from where

What we never store

  • End-customer names, addresses or contact details
  • Card numbers or bank details — payments never touch our systems
  • Government identifiers of any kind
  • Anything from your systems we were not explicitly scoped to read

Security questionnaire, pre-answered

Where is our data hosted?+

AWS ap-south-1 (Mumbai) by default. EU customers can elect eu-central-1 at onboarding; data never leaves the elected region, including backups.

Do you use customer data to train models?+

No. There is no ML training pipeline touching customer data, and the DPA contractually forbids adding one without written consent.

How fast do you patch a critical CVE?+

Base images rebuild nightly. A critical CVE with a published fix is deployed within 24 hours; we have missed that target once in three years and published why.

Can we run our own pentest?+

Yes, against a dedicated staging tenant, with two weeks' notice. We will share our own report first so you are not paying to find what we already know.

What happens if we leave?+

Full export in CSV and JSON within 24 hours of request. Deletion of all copies, backups included, within 35 days, with written confirmation.

Who do we contact about a vulnerability?+

security@northbeam.io, PGP key on the page footer. We acknowledge within one business day and have never taken legal action against a good-faith researcher.

Request the full report pack

SOC 2 Type II, ISO certificate, pentest summary and our standard DPA — sent as one PDF bundle under a click-through NDA.

Email address
you@example.com
Subscribe