Your data and your keys, protected
We build Beaufixe so that your secrets stay secret and each workspace's data stays siloed. Here is, in all honesty, how we protect your account.
Secrets encrypted at rest
Sensitive secrets (AI keys, messaging tokens, credentials) are encrypted at rest with AES-256-GCM. They are never sent to the browser in plain text.
Multi-tenant isolation
Each workspace is siloed. Data access is protected at the database level with Supabase Row Level Security (RLS): a workspace can never read another workspace's data.
BYOK: your AI key stays yours
Your AI key is encrypted before storage and is never displayed in plain text again, even to you, once saved. You can replace or revoke it at any time.
Hosted in the European Union
The infrastructure runs on Railway and Supabase, with data hosted in the European Union.
Workspace deletion
You can delete your workspace and its associated data. Deletion honors your right to erasure in accordance with the GDPR.
Subprocessors
We rely on a limited number of technical subprocessors. The up-to-date list is published in our legal documentation.
Our practices, in plain terms
We prefer to describe honestly what we do rather than display certification logos. We do not claim any certification we do not hold.
- Secrets encrypted at rest with AES-256-GCM: AI keys, SMTP and IMAP passwords, Gmail and Outlook tokens, client Stripe keys
- Strict data isolation per workspace (Supabase RLS)
- AI keys encrypted and never displayed again after saving
- Authenticated application access, per-member workspace permissions
- Data stored in the European Union (Supabase, eu-central-1); application served from Railway infrastructure
- Workspace deletion and right to erasure (GDPR)
A question about security?
We are transparent about what we have in place and what is still in progress.
For any request about security, data protection, or exercising your GDPR rights, our help center will point you to the right contact.
Go to the help center