Legal & Trust
Trust Center
Last updated: June 2026
One place to understand how Benchside protects your data. This matrix is stated honestly: controls that are live are marked live, and anything still in progress or planned is labeled as such, so your security review can rely on it.
Data protection
Tenant isolation
Row-level security on every table
Encryption in transit & at rest
TLS 1.2+ and AES-256
OAuth token encryption
AES-256-GCM; keys never logged
Data export & deletion
GDPR/CCPA self-service
Data residency (EU)
Region-pinned storage
Identity & access
Passwordless sign-in
Email one-time code; no stored passwords
Multi-factor authentication
TOTP, admin-enforceable org-wide
Account lockout & idle timeout
Brute-force and session controls
Role-based access control
Admin / member / viewer
Enterprise SSO (SAML / OIDC)
Okta, Azure AD, Google Workspace
SCIM provisioning
Self-hosted SCIM 2.0; pending IdP validation
Application security
Security headers
CSP, HSTS, clickjacking protection
Rate limiting
Abuse protection on sensitive endpoints
Prompt-injection defense
Input sanitization and delimiting
Signed, replay-protected webhooks
Payment events
Automated dependency updates
Weekly, CI-gated
Enterprise bot protection
App rate limits today; platform WAF on deploy
Infrastructure & resilience
Append-only audit log
Actor, timestamp, IP; admin export
Health & error monitoring
Liveness endpoint + error capture
Backups & point-in-time recovery
Daily backups + PITR
DDoS protection
Provided by the hosting platform
Multi-region redundancy
Cross-region failover
Compliance
GDPR / CCPA alignment
Data subject rights honored
DPA available
For enterprise agreements
SOC 2 Type II
Controls implemented; audit window pending
Documents
Security overview
Isolation, encryption, access control, and monitoring.
Privacy policy
What we collect, why, and the rights you have over it.
Terms of service
The terms that govern use of Benchside.
Subprocessors
The infrastructure providers we rely on.
Running a vendor security review? Send your questionnaire to security@benchside.ai and we will complete it accurately. A DPA is available for enterprise agreements.
Questions about this page? Email privacy@benchside.ai. For security disclosures, email security@benchside.ai.