Security & Trust

Your data is yours. We never train on it.

BeneDoc is built so you can put confidential data into the platform and know exactly how it is protected: encrypted, US-hosted, used only to serve you, and yours to export and delete at any time.

Protections at a glance

What you can count on

Your data stays yours

We process your data only to provide the service, on your documented instructions, and for no purpose of our own.

Never used to train models

Your data is never used to train, fine-tune, or improve any general model, and it is never sold or shared for advertising.

Encrypted and US-hosted

Data is encrypted in transit and at rest on Google Cloud in the United States, with access limited to those who need it.

A short, disclosed subprocessor list

We name every third party that touches your data, and give you advance notice and a right to object before it changes.

72-hour breach notice

If a security incident affects your data, we notify you within 72 hours of becoming aware, with what we know.

Clean exit, on demand

On termination we return your data in usable formats and then delete it, with a deletion certificate on request.

How your data is handled

Built secure, not secured later

Want the detail? Our Information Security Overview walks through our infrastructure, encryption, access controls, and incident response, and is available to customers and prospects on request.

Purpose-limited processing

Your data is used only to run the service you asked for. We do not repurpose it, sell it, or share it for advertising.

Least-privilege access

Access is identity-based and need-to-know. Credentials never live in our code; they are held in a managed secrets vault.

A tamper-evident trail

The platform keeps immutable, append-only audit logs engineered to 21 CFR Part 11 standards, so every change is traceable.

US data residency

Your data is processed and stored in the United States on Google Cloud, whose infrastructure carries SOC 2, ISO 27001, and PCI DSS.

AI you can trust with private data

Automated, but never at your expense

No training on your data

Your content is used to produce your results and nothing else. It never becomes training data for any model.

Human-final by design

Outputs are drafts for your review. You apply the final judgment and remain the decision-maker, every time.

Ready for 2026 privacy rules

We support your obligations around automated decision-making and risk assessments under the CCPA/CPRA and comparable state laws.

Traceable to the source

Outputs carry source traceability and citations, so every result can be checked back to its underlying evidence.

Compliance and standing

Where we stand today

CCPA/CPRA Service Provider

For US customers, we contract as a Service Provider under the CCPA/CPRA and comparable state privacy laws: no sale, no sharing, purpose-limited.

SOC 2-aligned program

Our controls are designed to the SOC 2 Trust Services Criteria. A formal SOC 2 examination is on our roadmap; we are candid that it is not yet complete.

Ready for the EU when you need it

If your data reaches the GDPR, UK GDPR, or Swiss FADP, our DPA carries the Standard Contractual Clauses and UK Addendum automatically.

We answer your questions

We respond to security questionnaires and due-diligence requests, and provide our documentation under NDA where appropriate.

Policies and documentation

The formal instruments behind the summary above.

Have a security or data question?

Our team answers due-diligence requests and security questionnaires directly.