1. Authentication & Access Management
Primary authentication: Magic Links
Beacon uses email-based magic links as the default authentication method. This approach offers several security advantages over traditional passwords:
Authentication is tied to the user's corporate email account.
When a user leaves the organization and loses email access, they automatically lose access to Beacon — no separate deprovisioning step required.
Eliminates common password-related attack vectors (credential stuffing, weak passwords, password reuse, phishing of static credentials).
Optional password-based authentication
Customers may opt into password-based login if their internal policies require it.
2. Hosting & Infrastructure
Item | Detail |
Cloud provider | Amazon Web Services (AWS) |
Data residency | United States |
Inherited compliance | Beacon leverages AWS's underlying compliance posture (SOC 1/2/3, ISO 27001, PCI DSS, and others) for physical security, hardware, and core infrastructure controls. |
3. Data Collected & Stored
Beacon stores two primary categories of customer data:
Operational Analytics
Part Definitions
Operational Analytics
Number of parts produced
Consumables usage (welding gas, wire, etc.)
Related production telemetry
Part Definitions
Each "part" in Beacon consists of:
Part settings — parameters that drive the attached equipment (welder, cutter, etc.).
Waypoints — positional information defining the path the robot travels to produce the part.
User account information (primarily email addresses used for authentication) is the only personal data collected.
4. Tenancy & Data Isolation
Beacon is a multi-tenant platform with logical data isolation enforced per customer. Each tenant's data is segregated such that no customer can access another customer's data through the application.
5. Encryption
Type | Standard |
In transit | TLS 1.2 or higher for all client, robot, and API traffic. |
At rest | AES-256 encryption applied to all stored data using AWS-managed keys. |
6. Network Security & Robot Connectivity
Beacon is designed to minimize the customer's network attack surface:
Outbound-only communication: the robot initiates all connections to Beacon.
HTTPS over port 443 only: all robot-to-cloud traffic is encrypted via HTTPS on standard TCP port 443.
No inbound ports required: customers do not need to open any inbound firewall ports for Beacon to function.
This deployment model means Beacon does not weaken the customer's existing network perimeter and is compatible with restrictive industrial network policies.
For specific firewall allowlist domains and full network setup instructions, see the Networking Requirements article.
7. Internal Access Controls
Access to customer data by Beacon personnel is governed by the following controls:
Multi-factor authentication (MFA) is required for all employee access to systems that store or process customer data.
Least-privilege access: employees are granted only the minimum access necessary to perform their job functions.
Access reviews and offboarding: access is reviewed periodically and revoked immediately upon employee offboarding.
8. Operational Security
Backups
Production data is backed up daily with point-in-time recovery enabled and retained for at least 14 days.
Logging & Monitoring
Centralized logging and monitoring are in place across production systems to support operational visibility, troubleshooting, and security event detection.
Vulnerability Management
Beacon monitors infrastructure, application code, and dependencies for known vulnerabilities using industry-standard tooling. Identified vulnerabilities are triaged and remediated according to severity.
9. Data Handling & Customer Offboarding
At the end of a customer engagement, or upon customer request, Beacon supports:
Data export — customers may export their data prior to deletion.
Data deletion — upon written request, Beacon deletes the customer's data from production systems.
Backups containing deleted data are aged out per the standard backup retention schedule.
10. Sub-processors
Beacon uses the following third-party services to deliver the platform. Each sub-processor is bound by appropriate data protection terms.
Sub-processor | Purpose |
Amazon Web Services (AWS) | Cloud infrastructure and data storage |
Intercom | In-app customer support and messaging |
Sentry | Application error tracking and monitoring |
Mixpanel | Product usage analytics |
Stripe | Payment processing |
Contact
For security questions or to request additional information, please contact support@hirebotics.com.