Trust built for the
agentic era.
Birdeye runs marketing for thousands of multi-location brands — and protecting their data, and their customers' data, is foundational to how we operate. Security, privacy, and responsible AI are engineered into every layer of the platform.
99.9%
Platform uptime- View Live Status
Continuous
Security testing with annual third-party pen tests
24/7
Security monitoring & incident response
US
Data residency on AWS, encrypted end to end
AI Agents you can trust with your data
Birdeye’s agents act on your behalf across reviews, listings, social and campaigns. That power comes with guardrails.
Here’s how we keep AI accountable to yoy - not the other way around.
Your data is never used to train public models
Customer data is never sold, shared, or used to train third-party or public foundation models. It works for you, and only you.
Human oversight & approval controls
Run agents fully autonomous or supervised. Approval workflows, role-based permissions, and audit logs keep a human in the loop wherever you want one.
Guardrails on every agent action
Input validation, output filtering, and brand-safe constraints govern what agents can generate and do - tested against the OWASP Top 10 for LLMs.
Governed models & full auditability
We use contractually approved AI models under our AI Governance Policy. Every model interaction is logged for audit.
Security engineered into every layer
From the network edge to the application to the data at rest, controls are layered so a single failure never exposes your information.
Data protection & encryption
Your data is protected at every stage of its lifecycle.
- Encrypted in transit (TLS 1.2+) and at rest (AES-256)
- Passwords one-way hashed with bcrypt & per-record salts
- Secrets and credentials are managed with automated rotation — no hardcoded credentials in application code
Cloud infrastructure
Built on Amazon Web Services, with isolation and redundancy engineered by design.
- Hosted on AWS in the United States
- Network segmentation & least-privilege access
- SOC 2, ISO, and PCI-validated facilities
Application & product security
Security is part of how we build, from first commit to production deployment.
- Secure SDLC with code review & dependency scanning
- Annual third-party penetration testing
- SSO, SCIM & role-based access control (RBAC)-SCIM ensures access is automatically removed when someone leaves your organisation — no manual steps required
Monitoring & incident response
We watch continuously and respond using a defined, audited playbook.
- 24/7 logging, alerting & threat detection
- Documented incident response & notification process
- Access to sensitive systems is logged & reviewed
Business continuity & availability
Designed for high availability and to recover fast in the event of a failure.
- Redundant, multi-zone architecture
- Automated backups with defined RTO & RPO
- Public status page for real-time transparency
Vendor & people security
Trust extends to every individual and partner who touches our systems.
- Sub-processor due diligence & risk reviews
- Background & reference checks before hire
- Confidentiality agreements & security training
“Birdeye's security and privacy posture is built for the enterprise. From end-to-end encryption and role-based access controls, to continuous compliance monitoring and third-party audits, to compliance with domestic and international privacy regimes, we've made the investments that matter - so our customers never have to wonder if their data is in good hands.”
Chad Starkey Chief Privacy Officer, Birdeye

Compliance & certifications
Independent auditors validate our controls so your security and compliance teams don't have to
take our word for it. Reports are available in the Trust Centre.

SOC 2 Type II
An independent audit of our controls for security, availability, and confidentiality— evaluated over time, not just at a point in time.

ISO/IEC 27001
The internationally recognised standard for an Information Security Management System (ISMS), maintained through annualthird-party audits.

HIPAA
Our products support HIPAA compliance for healthcare brands, with required workforce training and a Business Associate Agreement (BAA) available.

GDPR
We meet the requirements of the EU General Data Protection Regulation, including data subject rights, lawful processing, and a Data Processing Agreement.

CCPA / CPRA
We honor California consumer privacy rights, including access, deletion, and the right to opt out of the sale or sharing of personal information.

AWS-backed infrastructure
Our platform runs on AWS, whose datacenters maintain SOC 1/2/3, ISO 27001, PCIDSS Level 1, and FedRAMP-aligned controls.
Privacy & your
data rights
We use the data you share only to deliver your services -never to build advertising products, and never sold to third parties. You stay in control with tools to access, correct, and delete personal information, plus a published list of the sub-processors we rely on.
Everything your reviewers need, in one place.
We use the data you share only to deliver your services — never to build advertising products, and never sold to third parties. You stay in control with tools to access, correct, and delete personal information, plus a published list of the sub-processors we rely on.
“Security isn't a feature we bolt on - it's a commitment we earn every day. As we put AI agents to work for our customers, protecting their data and their customers' trust is the standard we hold every decision to.”
Avik Sarkar Chief Information Security Officer, Birdeye

Security resources
Contact Security / Report a Vulnerability
Have a security question or found a vulnerability? We want to hear from you.
Disclose securely