Security & trust

Your data deserves the same care we give your business.

Beleav Assist works with sensitive client data every day — patient records, financials, contracts, customer lists. Here’s how we protect it.

Our security pillars

Six commitments, every engagement.

NDAs, always.

Every team member signs a mutual non-disclosure agreement before they see a single client artifact. Per-client NDAs available on request.

Encryption everywhere.

Data in transit over TLS 1.2+. Data at rest with AES-256. Password vaults via 1Password Business or your provider — we never store credentials in plain text.

Least-privilege access.

Assistants get only the access they need to do their work — nothing more. Access reviewed quarterly and revoked the day an engagement ends.

Standardized devices.

Every assistant works from a managed device with full-disk encryption, screen-lock policy, anti-malware, and remote-wipe capability.

Audit trails.

Every login, file access, and credential check is logged. Available to clients on request as part of any quarterly review.

BAAs available.

Healthcare clients can sign a Business Associate Agreement before any PHI is touched. We follow HIPAA Privacy and Security Rule guidance for all BAA-covered work.

Sub-processors

The systems we use to do the work.

Updated quarterly. Clients are notified at least 30 days before any new sub-processor is added to a covered engagement.

ProviderPurposeRegion
Google WorkspaceEmail, calendar, docsUS/EU
1Password BusinessCredential vaultingCanada
SlackInternal communicationUS
NotionInternal SOPs and runbooksUS
CloudflareDNS + WAF for client portalsGlobal
ZoomClient video callsUS/EU
Operational commitments

What you can expect from us on day one.

  • Background checks on every assistant before client work
  • Annual security training, role-specific for healthcare and legal teams
  • Incident response within 4 business hours of detection
  • 30-day data return or destruction window after offboarding
  • Annual penetration test on internal systems
  • Vulnerability patches within SLA: critical < 7 days
Need a deeper review?

Send a security questionnaire — we’ll respond within 5 business days.

We’re happy to walk through SIG, CAIQ, vendor risk assessments, or your own custom format. BAAs and DPAs available before any covered work begins.

Trust, then work

Have a security or compliance question? Ask before you sign.