Skip to main content

No qualifying activity. No qualifying BKA fee. · 1% + 1%

Founder LoginGet Started

Internal dashboards and operational workspace use remain free — no subscription, seat license, or token billing. · 1% Performance Partnership Fee — charged only on qualifying, verified internal financial improvements under the agreed measurement methodology. · 1% Operational Coordination Fee — charged on qualifying, approved external service coordination events. · No qualifying activity. No qualifying BKA fee.

BKA

BeeKeeper Assurance

Legal

Privacy Policy

How BeeKeeper Assurance collects, uses, protects, and retains information across websites, pilot workspaces, and enterprise assurance operations.

Custody model

Non-custodial

Data approach

Evidence-driven

Approvals

Human-gated

Last updated

July 2026

Overview

BeeKeeper Assurance Inc. operates an Enterprise Assurance Operating System that sits above customer enterprise systems. This Privacy Policy explains how we collect, use, store, and protect information when you visit our website, participate in a pilot, or use BeeKeeper Assurance workspaces.

BeeKeeper Assurance is designed to be read-only where possible, human-approved, non-custodial, and evidence-driven. We do not take custody of customer funds, process vendor payments, or replace customer ERP, CRM, CMMS, or industry platforms.

Information We Collect

We collect information necessary to operate assurance workflows, onboarding, and enterprise coordination:

  • Company profile and contact details submitted through Get Started, Contact, and onboarding forms
  • Website analysis metadata when you authorize a company website review during onboarding
  • Documents uploaded during secure onboarding (NDA, MSA, security questionnaires, insurance, vendor files)
  • Operational evidence ingested through approved connectors (read-only where possible)
  • Audit events, session metadata, and security logs required for enterprise assurance
  • Usage telemetry for presentation, narration, and workspace performance (no sale of personal data)

How We Use Information

BeeKeeper Assurance uses collected information to:

  • Provision and secure customer, partner, and founder workspaces
  • Connect approved enterprise systems and normalize operational evidence
  • Run AI Jury review, WORM audit sealing, and digital twin visibility
  • Coordinate external services under human approval with non-custodial commercial boundaries
  • Generate reconciliation exports and monthly Performance Partnership fee invoices where applicable
  • Respond to support, legal, and security inquiries

Data Boundaries and Custody

BeeKeeper Assurance does not take custody of customer money, bank accounts, or vendor payment flows. Customers pay vendors directly using their own payment terms.

Internal dashboards and operational workspace use are free. After the 60-day Performance Evaluation, BeeKeeper Assurance may invoice verified 1.0% Performance Partnership and Operational Coordination fee lines per MSA Section 4.

Connector access is gated by ordered approval flags and tenant isolation. Live sync requires explicit enterprise approval.

Security and Retention

Evidence records are sealed into WORM audit chains. Access is role-based with tenant isolation. Secrets are referenced through secure secret providers — never hardcoded in application code.

Retention follows enterprise pilot agreements, legal holds, and customer offboarding procedures documented in onboarding packages.

Protected security-incident intelligence is compartmented from ordinary dashboards. Employees and vendors may submit suspicious-activity reports without receiving investigation findings. Only individually designated and verified Incident Authority members may ask about, confirm, or view incident information. Access and attempted access may be recorded in tamper-evident Assurance Receipts. WORM preservation proves retention without alteration; it does not prove that submitted information was true.

Controlled Threat Learning and Collective Defense

DRAFT_FOR_LICENSED_COUNSEL_REVIEW. Qualified legal counsel must review final language for privacy, employment, surveillance, cybersecurity, and cross-border requirements.

BeeKeeper Assurance may analyze permitted security telemetry — including detection and access-denial events, sanitized incident outcomes, attempted privilege escalation, JA/avatar manipulation, prompt-injection attempts, phishing and social-engineering patterns, deepfake and identity-spoofing attempts, malware and ransomware behavior, fraud and scam patterns, vendor and supply-chain compromise indicators, insider-threat signals, honey-token events, customer-approved connected security systems, authorized advisories and threat feeds, red-team findings, post-incident reviews, and customer-confirmed false positives and false negatives.

Customer information remains isolated. Raw customer evidence, personal information, credentials, incident existence, infrastructure details, privileged legal information, customer-specific vulnerabilities, vendor relationships, and proprietary operational information are not shared with another customer. One customer cannot query what BKA learned from another specific customer.

Sanitized patterns may improve defenses only when legally permitted, contractually authorized, and above a minimum population threshold. Authenticated information is not automatically treated as truthful. Production security updates are quarantined, shadow-tested, approved according to risk, cryptographically versioned, deployed gradually, monitored, and reversible. Human oversight is required for high-consequence changes. Automated detection does not guarantee prevention of every attack.

  • Consent or legal basis is contractual and jurisdiction-specific; customer configuration rights control telemetry contribution and collective-defense participation
  • Retention and deletion follow enterprise agreements, legal holds, and offboarding procedures
  • Unauthorized employees and vendors do not receive threat-learning details

Sanctions, Export-Control, and Restricted-Party Compliance

DRAFT_FOR_LICENSED_COUNSEL_REVIEW. Qualified sanctions, export-control, privacy, and international counsel must review final language.

BKA uses a documented, continuously updated sanctions and restricted-party compliance process designed to screen organizations, individuals, beneficial ownership, locations, end users, and intended uses against applicable official sources. Potential matches, licenses, exceptions, and ambiguous cases are routed for authorized human and legal review before activation or continued access.

Application, signature, or payment does not constitute authorization to use BKA. Screening is not a country blocklist. AI never makes the final legal determination.

Your Rights and Contact

Enterprise customers may request data access, correction, export, or deletion subject to contractual, legal, and audit obligations.

For privacy inquiries, contact legal@beekeeperassurance.com or use the Contact page. For onboarding workspace questions, use your Customer Portal after activation.