Skip to content

Security at Beltic

Beltic sits close to your production systems. Here is exactly how we protect what you put in it.

Visit the trust center

Compliance

Certifications

  • SOC 2 Type IIReport available
  • ISO 27001In progress

Controls

How the platform is built

  • Secure by design

    Beltic is audited annually against SOC 2 Type II, covering the security, availability and confidentiality of customer data. The controls behind the report are monitored continuously rather than only in the weeks before an audit.

  • Penetration tested

    An independent security firm runs vulnerability and penetration testing across our products at least annually. Findings are triaged by severity and remediated on a fixed schedule, and test summaries can be requested under NDA.

  • Data encryption

    Data at rest is encrypted with AES-256. Everything in transit travels over TLS, including traffic between our own internal services, and keys are rotated on a schedule rather than on incident.

  • Network security

    Internal and external traffic is encrypted with industry-standard protocols. The network is continuously monitored for malicious or abnormal activity, and every anomaly it surfaces is investigated rather than filed.

  • API security

    The Beltic API accepts traffic over TLS only. Access is authenticated with a 256-bit authorization key, scoped per environment, and revocable without a redeploy.

  • Secure authentication

    You control how your team signs in: SSO over SAML 2.0 or OIDC, email and password, or Google. SCIM 2.0 keeps users in sync with your directory and domain routing sends everyone through your IdP. Access is role-based and sessions expire. Identity runs on WorkOS, isolated from the rest of our infrastructure, and sandbox and production authenticate separately.

  • Application security

    We monitor the third-party software we depend on for vulnerabilities and supply-chain attacks, with automated detection and a documented process for investigating and remediating what it finds. Every change is reviewed before it ships.

  • Internal access

    Access to internal systems is protected by multi-factor authentication and granted at the minimum level an employee needs to do their job. Security training is required for everyone, on a recurring schedule.

FAQ

Frequently asked questions