BELA
✦ Ask BELA Sign in
Home › Security
Security

Security designed for autonomous engineering

BELA builds and runs software on your behalf, so it holds itself to a high bar: least privilege by default, every action recorded, and a security layer that assesses the platform continuously.

How we protect your data

Default-deny access

Role-based access control starts closed. A role grants only the permissions it is explicitly given, and platform administration is separated from tenant roles entirely.

Tenant isolation

Every record is scoped to its tenant. One organisation can never read or write another’s data — enforced in the data layer, not just the UI.

Full audit trail

Security-relevant actions are written to an immutable audit log with actor, subject, before/after and source — the evidence a real investigation needs.

Encryption

Data is encrypted in transit (TLS) and at rest. Secrets are held in configuration, never in the codebase.

Hardened responses

Enterprise HTTP security headers are applied to every response by default, closing common browser-side attack classes.

Continuous assessment

A Security Intelligence layer assesses the platform against a control catalogue and surfaces findings — security is measured, not assumed.

Controls at a glance

What is live today, and what is on the way. We report status honestly.

Role-based access control (default-deny)
Live
Multi-tenant data isolation
Live
Immutable audit logging
Live
Encryption in transit and at rest
Live
Enterprise HTTP security headers
Live
Single sign-on (SSO / SAML)
In progress
Customer-managed data residency
Planned
Independent penetration test (published summary)
Planned

Need our security documentation?

We share our architecture overview and answer security questionnaires under NDA.

Compliance roadmap