Skip to main content
    About beSirius

    Security at beSirius

    Built for regulated industries. Designed for peace of mind.

    beSirius is purpose-built for sustainability, compliance, and legal teams in mining, metals, energy, and industrial supply chains — sectors where information security, auditability, and data control are non-negotiable.

    We treat your data like it's board-level material (because it is).

    ISO/IEC 27001:2022 certification badge
    ISO/IEC 27001:2022

    Certified by Advantage Partners

    GDPR certification badge
    GDPR

    EU data protection aligned

    Enterprise-grade protection. By default

    • End-to-end encryption

      All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). No exceptions.

    • Private workspaces

      Your documents, answers, and knowledge graph are fully isolated. There is no cross-company data access, and no shared AI training.

    • Zero data training policy

      Your documents and outputs are never used to train any AI models. Ours or anyone else's.

    • Flexible hosting

      Choose EU or US data residency. For high-security environments, we offer VPC and self-hosted deployments.

    • Admin-level control

      Granular user roles, audit trails, IP allow-listing, and workspace permissions give your team full control over access and visibility.

    Secure by design, from upload to output

    • Reviewable AI outputs

      No answer is ever submitted or shared without human review. You stay in control of every response.

    • Source-cited responses

      Each answer links directly to the policy, file, or dataset it's based on — essential for audits, legal reviews, and documentation trails.

    • Sensitive content handling

      You can tag and manage topics like anti-corruption, human rights, or trade restrictions to ensure the right level of oversight.

    • Audit-ready logs

      Every file upload, question, and AI response is logged, timestamped, and exportable for internal or external review.

    Responsible AI, purpose-built for sustainability and compliance

    beSirius is trained to work with complex qualitative data, regulatory language, and documentation across sustainability, legal, and compliance domains.

    That means:

    • Structured, evidence-based answers
    • Traceable logic and document links
    • No hallucinations or unverifiable claims
    • Built-in methodology awareness (CDP, EcoVadis, IRMA, ICMM, SBTi, etc.)

    Compliance frameworks and certifications

    • Certification held by beSirius

      beSirius's Information Security Management System (ISMS) is certified to ISO/IEC 27001:2022 by Advantage Partners, confirming that we meet the international standard for managing information security risk.

    • Aligned with industry standards

      Our security program is designed to meet GDPR requirements for EU data protection, and is aligned with the SOC 2 Trust Services Criteria for security, availability, and confidentiality. We support DPA and SLA agreements with all enterprise customers.

    • Ongoing assurance

      beSirius undergoes independent penetration testing, internal security audits, and annual security training for all team members. Surveillance audits are conducted annually to maintain our ISO 27001 certification.

    Need our security documentation?

    Enterprise customers can request our ISO 27001 certificate and supporting security documentation from their beSirius account team.