Skip to main content

Free platform · 1% coordination fee on external services · 1% performance fee only on verified internal savings · No fee when there is no qualifying activity · Net-30 invoices

BKA

BeeKeeper Assurance

BeeKeeper Assurance Demo

Security Center

Production security readiness for RBAC, tenant isolation, SSO, WORM audit, encryption, secret storage, API access, connector permissions, retention, and evidence chain integrity.

Security readiness

9%

Ready or presentation-ready controls

RBAC roles

13

Production role inventory

Controls

11

Security control areas

Checklist

10

Production security tasks

Auth providers

5

Azure AD, Okta, Google, SAML, OIDC

RBAC overview

Ready

Role inventory covers founder, enterprise, customer, partner, vendor, auditor, inspector, security, finance, and operations users.

Production requirement: Map roles to customer IdP groups and enforce route/action scopes server-side.

Tenant isolation status

Security review in progress

Tenant isolation model is defined with tenant IDs, subsidiaries, departments, locations, and credential metadata.

Production requirement: Enforce row-level security and tenant-scoped secrets in production database and API server.

SSO readiness

Customer access required

SSO configuration is represented in implementation wizard and schema.

Production requirement: Customer must provide SAML/OIDC metadata, group claims, logout URL, and test users.

Audit logging

Security review in progress

WORM audit records, activity feed, and audit-event schema are modeled.

Production requirement: Append immutable records from API actions, connector syncs, exports, and user decisions.

WORM status

Security review in progress

WORM records show hashes, previous hashes, chain status, actor, and event type.

Production requirement: Use customer-approved immutable storage and retention controls.

Encryption status

Security review in progress

Schema and runtime configuration reference encryption key secret IDs.

Production requirement: Confirm KMS provider, key rotation, field-level encryption requirements, and backup encryption.

Secret storage status

Security review in progress

Connector skeletons reference secret IDs only and do not store plaintext credentials.

Production requirement: Configure AWS Secrets Manager, Azure Key Vault, GCP Secret Manager, or customer vault.

API access policy

Security review in progress

API access is documented as scoped, signed, tenant-aware, and audited.

Production requirement: Implement rate limits, IP allowlists, mTLS where required, and audit logs.

Connector permission policy

Customer access required

Connector activation center lists required permissions by system.

Production requirement: Customer IT must approve least-privilege scopes for each connector.

Data retention policy

Security review in progress

Retention is represented for evidence, WORM records, audit exports, and customer data.

Production requirement: Align retention with customer legal, compliance, and DPA requirements.

Evidence chain integrity

Security review in progress

Evidence records include SHA hashes, chain-of-custody, duplicate status, and tenant references.

Production requirement: Hash real uploaded evidence at ingest and bind every decision to WORM audit.

Roles

FOUNDERSUPER_ADMINENTERPRISE_ADMINCUSTOMER_ADMINCUSTOMER_USERPARTNER_ADMINPARTNER_USERVENDORAUDITORINSPECTORIT_SECURITYFINANCEOPERATIONS

Production security checklist

Complete SSO/SAML/OIDC integration test
Enable tenant-level row security
Configure secret manager and rotate connector secrets
Enable audit appenders for all privileged actions
Validate WORM storage retention and legal hold
Confirm data retention and deletion policy
Run penetration test and dependency review
Validate API rate limits and connector scopes
Review customer DPA, MSA, and security questionnaire
Approve production incident response runbook

Enterprise authentication

Azure AD / Microsoft Entra

READY_FOR_CUSTOMER_ACTIVATION

OIDC / MFA: supported

OIDC session with customer IdP MFA and server-side session audit.

Okta

READY_FOR_CUSTOMER_ACTIVATION

SAML / MFA: supported

SAML assertion session with group claim mapping and idle timeout policy.

Google Workspace

READY_FOR_CUSTOMER_ACTIVATION

OIDC / MFA: supported

OIDC session with hosted-domain restriction and customer MFA policy.

Generic SAML

READY_FOR_CUSTOMER_ACTIVATION

SAML / MFA: supported

Generic SAML session with signed assertions, group mapping, and audit logging.

Generic OIDC

READY_FOR_CUSTOMER_ACTIVATION

OIDC / MFA: supported

Generic OIDC session with issuer validation, nonce checks, and token rotation.