Security & Trust
Your data is yours. We never train on it.
BeneDoc is built so you can put confidential data into the platform and know exactly how it is protected: encrypted, US-hosted, used only to serve you, and yours to export and delete at any time.
Protections at a glance
What you can count on
Your data stays yours
We process your data only to provide the service, on your documented instructions, and for no purpose of our own.
Never used to train models
Your data is never used to train, fine-tune, or improve any general model, and it is never sold or shared for advertising.
Encrypted and US-hosted
Data is encrypted in transit and at rest on Google Cloud in the United States, with access limited to those who need it.
A short, disclosed subprocessor list
We name every third party that touches your data, and give you advance notice and a right to object before it changes.
72-hour breach notice
If a security incident affects your data, we notify you within 72 hours of becoming aware, with what we know.
Clean exit, on demand
On termination we return your data in usable formats and then delete it, with a deletion certificate on request.
How your data is handled
Built secure, not secured later
Purpose-limited processing
Your data is used only to run the service you asked for. We do not repurpose it, sell it, or share it for advertising.
Least-privilege access
Access is identity-based and need-to-know. Credentials never live in our code; they are held in a managed secrets vault.
A tamper-evident trail
The platform keeps immutable, append-only audit logs engineered to 21 CFR Part 11 standards, so every change is traceable.
US data residency
Your data is processed and stored in the United States on Google Cloud, whose infrastructure carries SOC 2, ISO 27001, and PCI DSS.
AI you can trust with private data
Automated, but never at your expense
No training on your data
Your content is used to produce your results and nothing else. It never becomes training data for any model.
Human-final by design
Outputs are drafts for your review. You apply the final judgment and remain the decision-maker, every time.
Ready for 2026 privacy rules
We support your obligations around automated decision-making and risk assessments under the CCPA/CPRA and comparable state laws.
Traceable to the source
Outputs carry source traceability and citations, so every result can be checked back to its underlying evidence.
Compliance and standing
Where we stand today
CCPA/CPRA Service Provider
For US customers, we contract as a Service Provider under the CCPA/CPRA and comparable state privacy laws: no sale, no sharing, purpose-limited.
SOC 2-aligned program
Our controls are designed to the SOC 2 Trust Services Criteria. A formal SOC 2 examination is on our roadmap; we are candid that it is not yet complete.
Ready for the EU when you need it
If your data reaches the GDPR, UK GDPR, or Swiss FADP, our DPA carries the Standard Contractual Clauses and UK Addendum automatically.
We answer your questions
We respond to security questionnaires and due-diligence requests, and provide our documentation under NDA where appropriate.
Policies and documentation
The formal instruments behind the summary above.
- Privacy Policy — how we handle personal information.
- Terms and Conditions — the terms for using our website and service.
- Data Processing Agreement — our standard DPA, which attaches to each customer agreement. Available on request.
- Information Security Overview — our technical and organizational security controls. Available on request.
Have a security or data question?
Our team answers due-diligence requests and security questionnaires directly.
