Identity and least privilege
Customer workspaces are isolated by verified identity. GPT-authenticated administration is separately authorized and audited.
TRUST CENTER
BETA ARMY’s control architecture is organized for SOC 2 and ISO 27001 readiness, with privacy-aware deployment patterns and a defined HIPAA compliance roadmap.
Customer workspaces are isolated by verified identity. GPT-authenticated administration is separately authorized and audited.
Test credentials are transmitted only to an approved runner, never written to findings, and excluded from application logs.
Projects, missions, findings, and activity are scoped to their owning account at every server-side access boundary.
Evidence retention is plan-aware, with enterprise options for custom windows, deletion workflows, and legal holds.
Administrative account actions and high-risk changes produce append-only audit events for review.
The control framework includes detection, containment, notification, recovery, and post-incident review requirements.
BETA ARMY does not claim completed SOC 2 attestation, ISO certification, or HIPAA compliance. Those outcomes require independent assessment, operational evidence over time, vendor qualification, workforce procedures, and executed agreements.
Protected health information is not permitted in the current hosted service. A future eligible enterprise deployment would require a completed security review, HIPAA-qualified infrastructure, and an executed BAA before PHI is introduced.
Customers remain responsible for authorization to test each target, using dedicated test accounts, avoiding production data when possible, defining prohibited actions, and obtaining consent for any personal information introduced into a mission.