SECURITY & TRUST

Trust built for the
agentic era.


SOC 2 Type II
ISO 27001
HIPAA
GDPR
CCPA / CPRA

Birdeye runs marketing for thousands of multi-location brands — and protecting their data, and their customers' data, is foundational to how we operate. Security, privacy, and responsible AI are engineered into every layer of the platform.

99.9%

Platform uptime- View Live Status

Continuous

Security testing with annual third-party pen tests

24/7

Security monitoring & incident response

US

Data residency on AWS, encrypted end to end

AI Agents you can trust with your data

Birdeye’s agents act on your behalf across reviews, listings, social and campaigns. That power comes with guardrails.
Here’s how we keep AI accountable to yoy - not the other way around.

Your data is never used to train public models

Customer data is never sold, shared, or used to train third-party or public foundation models. It works for you, and only you.

Human oversight & approval controls

Run agents fully autonomous or supervised. Approval workflows, role-based permissions, and audit logs keep a human in the loop wherever you want one.

Guardrails on every agent action

Input validation, output filtering, and brand-safe constraints govern what agents can generate and do - tested against the OWASP Top 10 for LLMs.

Governed models & full auditability

We use contractually approved AI models under our AI Governance Policy. Every model interaction is logged for audit.

Security engineered into every layer

From the network edge to the application to the data at rest, controls are layered so a single failure never exposes your information.

Data protection & encryption

Your data is protected at every stage of its lifecycle.

  • Encrypted in transit (TLS 1.2+) and at rest (AES-256)
  • Passwords one-way hashed with bcrypt & per-record salts
  • Secrets and credentials are managed with automated rotation — no hardcoded credentials in application code

Cloud infrastructure

Built on Amazon Web Services, with isolation and redundancy engineered by design.

  • Hosted on AWS in the United States
  • Network segmentation & least-privilege access
  • SOC 2, ISO, and PCI-validated facilities

Application & product security

Security is part of how we build, from first commit to production deployment.

  • Secure SDLC with code review & dependency scanning
  • Annual third-party penetration testing
  • SSO, SCIM & role-based access control (RBAC)-SCIM ensures access is automatically removed when someone leaves your organisation — no manual steps required

Monitoring & incident response

We watch continuously and respond using a defined, audited playbook.

  • 24/7 logging, alerting & threat detection
  • Documented incident response & notification process
  • Access to sensitive systems is logged & reviewed

Business continuity & availability

Designed for high availability and to recover fast in the event of a failure.

  • Redundant, multi-zone architecture
  • Automated backups with defined RTO & RPO
  • Public status page for real-time transparency

Vendor & people security

Trust extends to every individual and partner who touches our systems.

  • Sub-processor due diligence & risk reviews
  • Background & reference checks before hire
  • Confidentiality agreements & security training

“Birdeye's security and privacy posture is built for the enterprise. From end-to-end encryption and role-based access controls, to continuous compliance monitoring and third-party audits, to compliance with domestic and international privacy regimes, we've made the investments that matter - so our customers never have to wonder if their data is in good hands.”

Chad Starkey Chief Privacy Officer, Birdeye

Chad Starkey

Compliance & certifications

Independent auditors validate our controls so your security and compliance teams don't have to
take our word for it. Reports are available in the Trust Centre.

SOC 2 Type II

An independent audit of our controls for security, availability, and confidentiality— evaluated over time, not just at a point in time.

Report in Trust Centre

ISO/IEC 27001

The internationally recognised standard for an Information Security Management System (ISMS), maintained through annualthird-party audits.

Certificate available

HIPAA

Our products support HIPAA compliance for healthcare brands, with required workforce training and a Business Associate Agreement (BAA) available.

BAA on request

GDPR

We meet the requirements of the EU General Data Protection Regulation, including data subject rights, lawful processing, and a Data Processing Agreement.

DPA available

CCPA / CPRA

We honor California consumer privacy rights, including access, deletion, and the right to opt out of the sale or sharing of personal information.

Rights request supported

AWS-backed infrastructure

Our platform runs on AWS, whose datacenters maintain SOC 1/2/3, ISO 27001, PCIDSS Level 1, and FedRAMP-aligned controls.

Inherited controls

We use the data you share only to deliver your services -never to build advertising products, and never sold to third parties. You stay in control with tools to access, correct, and delete personal information, plus a published list of the sub-processors we rely on.

Everything your reviewers need, in one place. 

We use the data you share only to deliver your services — never to build advertising products, and never sold to third parties. You stay in control with tools to access, correct, and delete personal information, plus a published list of the sub-processors we rely on.

SOC 2 Type II report
Sub-processor list
ISO 27001 certificate
Real-time system status
Penetration test summary
CAIQ / SIG questionnaire
Security & privacy policies
DPA & BAA templates

“Security isn't a feature we bolt on - it's a commitment we earn every day. As we put AI agents to work for our customers, protecting their data and their customers' trust is the standard we hold every decision to.”

Avik Sarkar Chief Information Security Officer, Birdeye

Avik Sarkar

Security resources

Trust Centre


Reports, certifications, and policies — released under NDA.

Visit now

System Status


Real-time uptime and incident history for the platform.

Visit status

Privacy Policy


How we collect, use, and protect personal information.

Read policy

Sub-processors


The third parties we use to deliver our services.

View list

Contact Security / Report a Vulnerability


Have a security question or found a vulnerability? We want to hear from you.

Disclose securely

AI Policy


How Birdeye governs the use of AI — for our products, our team, and your data.

Read Policy
HomeAbout Ussecurity