Consultation Kelly

Security

What we do today to protect accounts and consultation content in the pilot, and what we do not yet claim.

Access control

  • Email and password sign-in; passwords are hashed by our auth provider.
  • New accounts start as Pending Approval and cannot reach the app until an administrator approves them. Accounts can be locked at any time.
  • Administrator rights are held in a separate role table and checked server-side on every privileged action.
  • Registration, sign-in and status changes are written to an audit log.

Data handling

  • All traffic is encrypted in transit over HTTPS.
  • Recordings are streamed in parts for transcription and are not stored on our servers.
  • Transcripts and insights are stored in your browser, namespaced to your signed-in account, and deleted automatically after 30 days.
  • Account data is held in a managed EU-hosted database with row-level access rules.

What we do not claim

  • No certification is claimed — the pilot is not ISO 27001, SOC 2, HIPAA or Cyber Essentials certified.
  • Browser storage is not encrypted at rest and is readable by anyone with access to the device.
  • No formal penetration test or independent audit has been carried out.

Reporting a vulnerability

Email support@axisbeamlabs.com with steps to reproduce. Please do not test against other people's accounts or real consultation data. We aim to acknowledge reports within five working days.