Information Security
Security by Design
Beita is built from the ground up with a "Security by Design" approach. Here is how we protect your data.
Six pillars of our security
1. Secure infrastructure
The service runs on Google Cloud (GCP) infrastructure, which holds ISO 27001 and SOC 2 certifications. All traffic is encrypted with TLS, and there is no direct access to the internal network from the internet.
2. Encryption in transit and at rest
Data in transit is encrypted with TLS 1.3. Data in storage is encrypted with AES-256. Encryption keys are managed in Google Cloud KMS and rotated automatically.
3. Automatic backups
The system is built for automatic daily backups on Google Cloud infrastructure, retained for up to 30 days. We plan to expand to point-in-time recovery and multi-region backups as the service grows.
4. Strict access control
A Role-Based Access Control (RBAC) model applies to every user, with two-factor authentication (MFA) available on all accounts. The system is built on a principle of least privilege — each role only accesses what it needs.
5. Logging and monitoring
Every sensitive action in the system is recorded in an audit log. The system is designed so that we can identify unusual access patterns and receive real-time alerts.
6. Incident response
We are planning a structured protocol for managing security incidents. In the event of a significant breach, we will notify you and the relevant authorities in accordance with GDPR requirements and the Privacy Protection Law.
Our servers
Beita operates on Google Cloud infrastructure. GCP holds ISO 27001, SOC 2 Type II, and PCI DSS certifications, and complies with GDPR requirements.
Our architecture is built on Firestore (a real-time database), Firebase Authentication, and Cloud Functions — all GCP services managed in a serverless configuration that reduces the attack surface.
Who has access
Only authorized personnel with a specific need can access customer data, and every such access is monitored and logged in the audit log. We do not access congregants' personal information without explicit authorization for support purposes.
The system is built so that access is granted strictly on a need-to-know basis and revoked once the need ends, including IAM permissions. We plan to tighten these processes and add further layers of control as our team and service grow.
Vulnerability research
We invite security researchers and ethical users to report any issues they find, and we commit to responding to every report within 48 hours.
Our dependency libraries are automatically scanned for known vulnerabilities (CVEs). We plan to incorporate penetration testing and SAST/DAST testing into our CI/CD processes.
Compliance with halachic and privacy requirements
Beita manages sensitive information related to the Jewish community — names of the deceased, memorial (yahrzeit) dates, memorial boards, and donations. We place the utmost importance on honoring the deceased and protecting the family's privacy.
Names are displayed on a public memorial board only on the basis of data entered by the gabbai, who takes on responsibility for obtaining consent. At a family's request, any name will be removed within 24 hours.
Found a vulnerability?
We value security researchers. Report an issue to us and we will respond within 48 hours.
Frequently asked questions
Where is my data stored?
Your data is stored on Google Cloud infrastructure. Personal information is encrypted using AES-256.
Who has access to my synagogue's information?
Only users you authorize. We ourselves do not access your information without explicit authorization for support purposes.
What happens if I want to delete my data?
You can export everything to Excel at any time. Full deletion is completed within 30 days of your request, in accordance with GDPR.
Is the system compliant with Israeli privacy regulations?
Yes. We comply with the Privacy Protection regulations and GDPR. A full compliance document is available through your Customer Success Manager.
Is two-factor authentication (MFA) available?
Yes. MFA is available to all users, and is especially recommended for gabbaim and administrators.
Is there an audit log for sensitive actions?
Yes. Every audited action (audit log) by a gabbai, administrator, or rabbi is retained for at least 12 months.
More questions about security?
We're happy to answer any security question and to share further information with CIOs at nonprofit organizations.