Your data and your keys, protected
We build Beaufixe so that your secrets stay secret and each workspace's data stays siloed. Here is, in all honesty, how we protect your account.
Sensitive secrets (AI keys, messaging tokens, credentials) are encrypted at rest with AES-256-GCM. They are never sent to the browser in plain text.
Each workspace is siloed. Data access is protected at the database level with Supabase Row Level Security (RLS): a workspace can never read another workspace's data.
Your AI key is encrypted before storage and is never displayed in plain text again, even to you, once saved. You can replace or revoke it at any time.
The infrastructure runs on Railway and Supabase, with data hosted in the European Union.
You can delete your workspace and its associated data. Deletion honors your right to erasure in accordance with the GDPR.
We rely on a limited number of technical subprocessors. The up-to-date list is published in our legal documentation.
Our practices, in plain terms
We prefer to describe honestly what we do rather than display certification logos. We do not claim any certification we do not hold.
- Secrets encrypted at rest with AES-256-GCM
- Strict data isolation per workspace (Supabase RLS)
- AI keys encrypted and never displayed again after saving
- Authenticated application access, per-member workspace permissions
- Data hosted in the European Union
- Workspace deletion and right to erasure (GDPR)
For any request about security, data protection, or exercising your GDPR rights, our help center will point you to the right contact.
Go to the help center