Security and trust
How Bullwhip handles your data, controls who sees it, and what you can review before you sign.
SOC 2 Type 2
Our security controls are independently audited by Accorp Partners CPA LLC. Our SOC 2 Type 2 report covers October 1, 2024 to September 30, 2025, and you can request it through our Trust Center.
Data handling
Beacon reads reporting data from your affiliate networks and ad platforms, and can deliver it to BigQuery, Firestore or AlloyDB for PostgreSQL, in a dedicated schema for each client.
- Data delivery
- Beacon delivers your commerce data to BigQuery, Firestore or AlloyDB for PostgreSQL, in a dedicated schema for each client.
- Where data is stored
- Bullwhip is hosted on Google Cloud Platform.
- Encryption
- Data is encrypted in transit and at rest.
- Retention and deletion
- We keep data for 3 years, and delete it on request.
Single sign-on and role-based access
Your teams sign in the way they already do, and each one sees what it should.
- Single sign-on
- Sign in with Google, Microsoft, Okta or OAuth / SSO.
- Role-based permissions
- Give each team the view it needs. Editorial can see traffic and clicks without seeing revenue.
No on-page JavaScript for core analytics
Beacon's core analytics need no on-page JavaScript. The optional lightweight tag, which adds link-level impressions and clicks, runs only on the pages where you deploy it.
Subprocessors and DPA
Our subprocessor list and data processing agreement are available on request, as part of our security package. Our security documentation is in the Trust Center.
Request our security package
Tell us what your security review needs and we'll send what we have.