Security

Security and compliance

The page for your due diligence file. What we do, where things run and what we can honestly claim.

Operational resilience and DORA

Our clients answer to supervisors, so their duties reach us.

  • ICT third party provider

    We work as an ICT third party provider to financial companies and mirror their operational resilience duties in how we run the platform.

  • Article 30 contracts

    The DORA obligations of our clients are covered contractually under Article 30, so your register of information has what it needs.

Your supervisor oversees Your company Article 30 contract Reload dev · ICT third party Resilience duties mirrored

How the platform runs

Beeqeeper is operated by us and delivered as SaaS.

Hosting in the EU

The platform is hosted in the Czech Republic by default. Where your regulator requires it, we deploy on servers in your own country. Source code stays with us, delivery is SaaS only.

Access control

Two factor authentication over SMS and Google Authenticator, and role based access for operators, compliance officers and administrators.

Audit trail

A full audit log of operator actions, with hashing of attached files.

Reconciliation

A reconciliation report compares client liabilities against balances held at banks, currency by currency.

Client data in services work

The rules we apply when your documents pass through our hands.

NDA is standard

We sign before we see anything.

No training on your data

External models are not trained on client documents.

No silent retention

Documents are not kept beyond the support window unless you ask us to keep them.

How due diligence works with us

Send the questionnaire you already use. We answer in your format.

  1. Send your questionnaire

    Your vendor or ICT third party questionnaire, in the form your supervisor expects. If you need a signed NDA first, we sign it first.

  2. Answers from the people who run the platform

    The team that operates Beeqeeper writes the answers. Where a question needs a document rather than a sentence, we name the document.

  3. Documents under NDA, then a call

    Our policies and the Article 30 contract schedule are shared under NDA during due diligence. Your reviewer can walk through any of it with us on a call.

What we do not claim

Certifications we hold none of, stated before you ask.

We hold no ISO 27001 and no SOC 2 certificate today. ISO 27001 is planned once the company passes an internal revenue threshold. Penetration tests have not been commissioned yet. If a claim is not on this page, do not assume it.

This website

Static pages, no cookies, no analytics, no external scripts, self hosted fonts. Server logs are kept for at most 30 days. Details are in the privacy policy. Privacy policy

Questions for your due diligence?

Send your questionnaire or ask a specific question. Either way you get a straight answer.

Contact us