Security
Enterprise-grade security protecting your department's sensitive data
Security First: Beacon35 is built with security as a foundational principle, not an afterthought. We implement industry-leading practices to protect your incident reports and personnel data.
Core Security Architecture
Secure Cloud Infrastructure
Beacon35 runs on secure cloud infrastructure with enterprise security measures, automatic backups, and high availability. Your data is protected with industry-standard security at every layer.
Authentication & Access Control
Password Security
- Secure Hashing: Passwords are hashed using industry-standard cryptographic algorithms
- Irreversible Protection: Even in the event of a database breach, passwords remain secure and cannot be reversed
- Password Requirements: Enforced minimum complexity standards
- Google Sign-In: Optional SSO via Google for passwordless authentication
Session Management
- Token-Based Authentication: Secure signed tokens issued for each authenticated session
- Automatic Expiration: Tokens expire automatically and are refreshed securely
- Custom Claims: Role and permission data embedded in authentication tokens for efficient access control
Multi-Factor Authentication (MFA)
- TOTP-based two-factor authentication is available in early access and rolling out to all accounts
- Google Sign-In is available today as a stronger alternative to password-only login
Role-Based Access Control
Beacon35 implements granular permission controls with four access levels:
Global Admin
Full system access including user management, department configuration, and all data across departments
Chief
Department-level administration, user management, report approval, and team oversight
Officer
Report approval, department data access, and operational management
Firefighter
Create and submit reports, view department data, access assigned resources
Network & Application Defense
Cloud Infrastructure Protection
- DDoS Mitigation: Built-in distributed denial-of-service protection at the infrastructure level
- TLS Encryption: All data in transit is encrypted with TLS
- Rate Limiting: Protection against brute force and enumeration attacks
Application Security
- Database Security: Granular security rules enforce data access controls at the database level
- XSS Protection: Input validation and HTML escaping
- Authentication Tokens: Cryptographic token verification on all API requests
- Input Validation: Server-side validation of all user input
Compliance & Standards
Beacon35 is built with awareness of industry-recognized security frameworks:
OWASP Top 10
Security Practices
- Code Review: Security-focused code reviews for all changes
- Dependency Monitoring: Tracking of third-party package vulnerabilities
- Infrastructure Security: Hosted on enterprise-grade cloud infrastructure with industry security certifications
Audit Logging & Monitoring
Activity logging provides accountability for key events:
- Administrative Actions: Plan and subscription changes, integration key generation
- Integration Events: Incidents created automatically from CAD webhooks
- Export Events: Full department data exports
Activity logs are visible in the Admin dashboard, retained for 90 days, and included in your department's data export.
Data Protection
Encryption
- In Transit: TLS encryption for all data transmission
- At Rest: Default encryption for all stored data at the infrastructure level
- Redundant Storage: Data is stored on replicated, highly available cloud infrastructure
- Self-Service Backups: Department admins can download a complete copy of their department's data at any time with the built-in Backup & Export tool — API keys and credentials are never included in export files
Data Isolation
- Multi-tenant architecture with strict data separation
- Department-level data isolation
- Database-level access controls
Incident Response
In the unlikely event of a security incident, our procedures are to:
- Work to detect and contain the incident promptly
- Notify affected departments without undue delay, consistent with applicable law
- Provide information about the incident and remediation steps
- Implement corrective measures to prevent recurrence
Security Disclosure
We welcome responsible disclosure of security vulnerabilities. If you discover a security issue:
- Email us at security@beacon35.com
- Provide detailed information about the vulnerability
- Allow us reasonable time to address the issue before public disclosure
- We aim to acknowledge reports within two business days
Security Questions?
For security-related questions or to report a vulnerability:
- Email: security@beacon35.com
- Contact form: Contact Us