Security & data
How we handle your streams and your data. Short, specific, and true today — not a certification wall we don't have yet. If your security team wants a deeper walkthrough, we'll do a call and answer a questionnaire.
Encryption in transit
Everything moves encrypted. Ingest is SRT (with its own AES encryption), RTMPS, or WHIP over HTTPS. Delivery is WebRTC (DTLS-SRTP) and LL-HLS/HLS over HTTPS. There is no unencrypted hop between your encoder and your viewer.
Access control
Playback is gated with signed URLs issued per viewer — per player, per bidder, per enrolled student — so only the people you authorise can watch, and you can revoke access at any time. Region-level geoblocking and SDK-level controls are co-built with design partners where a vertical needs them.
Data residency
We don't run a generic global footprint. We deploy a dedicated regional edge for your audience, on the cloud or hardware you choose — AWS, GCP, Azure, OVH, Hetzner, bare-metal, or your own account. Your stream and its delivery data stay in the region you pick, which is what makes per-region data residency real rather than a checkbox.
Recording & retention
Session recording to VOD is opt-in and yours to control. If you enable it (common for audit in regulated verticals), you decide the retention window; we don't keep recordings longer than you ask. Storage is billed transparently at $9/TB/month.
Data minimisation
We process only what's needed to run and observe your service: the stream itself and delivery/telemetry metadata (concurrent viewers, regional breakdown, latency percentiles, ingest health, egress). We don't build viewer profiles or resell anything. Our own marketing site uses cookieless, GDPR-safe analytics (Umami).
Sub-processors
Because we deploy into the cloud or hardware you choose, the underlying infrastructure provider is a sub-processor and is disclosed per deployment before go-live. A current list is available on request and named in your DPA.
GDPR & DPA
We build for GDPR from the start — encryption, minimisation, residency and access control above are the mechanics behind it. A Data Processing Agreement is available on request and covers roles, sub-processors, security measures and breach handling. Email hello@beon.live with "DPA" and we'll send it same day.
Incidents & SLAs
We don't sell "five nines" marketing. SLAs are co-designed with you per deployment against the latency and availability that actually matter for your use case, and we write an honest post-mortem for any incident that affects you.
Talk to our team
Security questionnaire, architecture review, or a DPA — just email hello@beon.live. A real engineer replies, usually within one business hour (UTC working hours).
Last updated: [date] · Questions: hello@beon.live