Skip to main content
AstroBee is built with security at its core. We implement industry-standard security practices and maintain compliance certifications to protect your data.

Trust Center

For detailed information about our security practices, compliance certifications, and policies, visit our Trust Center:

AstroBee Trust Center

View our security documentation, compliance reports, and policies
Our Trust Center includes:
  • SOC 2 Type II compliance status and reports
  • Security policies and procedures
  • Subprocessor list
  • Data Processing Agreement (DPA)
  • Penetration test summaries

Security Overview

Data Encryption

LayerProtection
In TransitTLS 1.3 encryption for all data transfers
At RestAES-256 encryption for stored data
CredentialsAES-256-GCM encryption for OAuth tokens and secrets

Infrastructure

AstroBee runs on secure, SOC 2 compliant cloud infrastructure with:
  • Isolated compute environments
  • Regular security patches and updates
  • Network segmentation and firewalls
  • DDoS protection

Access Control

  • Authentication: Secure passwordless authentication and OAuth providers (Google)
  • Authorization: Role-based access control (Admin, Member)
  • Sessions: Secure session management with automatic timeouts
  • API Access: OAuth 2.0 client credentials for programmatic access

Data Handling

Your Data Stays Yours

  • AstroBee queries your data sources but does not permanently store your raw data
  • Query results are cached temporarily for performance, then purged
  • Conversation history is retained for your convenience and can be deleted anytime
  • Enterprise customers can use Bring Your Own Bucket (BYOB) for complete data control

Data Processing

  • All data processing occurs in secure, isolated environments
  • AI features use API-only integrations with no data retention by AI providers
  • Your data is never used to train AI models

Data Retention

Data TypeRetentionDeletion
Chat conversationsUntil you deleteSelf-service in app
Data layer definitionsUntil you deleteSelf-service in app
Uploaded filesUntil you deleteSelf-service in app
Audit logs90 daysAutomatic

Third-Party Integrations

AstroBee uses trusted partners for specific functionality:

Fivetran (Data Connectors)

External data source connections (Google Sheets, Salesforce, HubSpot, etc.) are powered by Fivetran, a SOC 2 Type II certified data integration platform.
  • Data flows: Source → Fivetran → AstroBee Warehouse
  • All transfers encrypted in transit
  • Fivetran does not retain your data after sync
  • View Fivetran’s security practices

AI Providers

AstroBee uses leading AI providers for natural language processing:
  • API-only integration (no data retention)
  • Your data is not used for model training
  • Conversations are not stored by AI providers

Reporting Security Issues

If you discover a security vulnerability, please report it responsibly:

Compliance Questions

For compliance documentation, audit requests, or security questionnaires:

Next Steps