Security

The platform you can audit.

We treat security like compliance: not a project, an ongoing posture. Hardening, encryption, and isolation by default. Disclosure paid in real money.

Posture

How the platform is built.

Encryption everywhere

TLS 1.3 in transit, AES-256 at rest. KMS-backed keys, per-tenant envelope encryption for PII.

Isolation

Workloads run in dedicated VPCs, with strict IAM boundaries. Production access is just-in-time and dual-approved.

Identity

WebAuthn-first auth for staff and customers. SSO for orgs at any tier.

Continuous testing

Static analysis on every PR, dependency scanning on every merge, quarterly third-party pen tests.

Monitoring

24x7 detection on production. Pager rotation, runbooks, and post-mortems shared with affected customers.

Backups

Point-in-time recovery, cross-region replicas, restore drills run monthly.

Responsible disclosure

Find something? We pay.

If you find a security issue, please report it to security@bequest.org. Encrypt with our PGP key for sensitive details.

We respond within one business day, fix critical issues within 14, and pay rewards for verified findings on a published scale.

We won't pursue researchers who act in good faith under our disclosure terms. The full policy is on this page.

Reward scale

Critical$5,000–$15,000
High$1,500–$5,000
Medium$500–$1,500
Low$100–$500