Third Party Index

Snapshot 55080

Document
Trust center
URL
https://birdeye.com/security/
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
304377 bytes
SHA-256 (raw)
0ec322dc1b4b3b0c102e071d4df38bab78f56d76ef2573d930864042ce38126d
SHA-256 (normalized text)
e789da11e70c7d41a90a319a554d1b40fc142b461816c7502751d7665c633bb4

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Birdeye Launches AI Coworkers for Multi-Location BrandsFind out more
SECURITY & TRUST
Trust built for the
agentic era.
SOC 2 Type II
ISO 27001
HIPAA
GDPR
CCPA / CPRA
Birdeye runs marketing for thousands of multi-location brands — and protecting their data, and their customers' data, is foundational to how we operate. Security, privacy, and responsible AI are engineered into every layer of the platform.
Visit Trust CenterTalk to Our Security Team
99.9%
Platform uptime- View Live Status
Continuous
Security testing with annual third-party pen tests
24/7
Security monitoring & incident response
US
Data residency on AWS, encrypted end to end
AI Agents you can trust with your data
Birdeye’s agents act on your behalf across reviews, listings, social and campaigns. That power comes with guardrails.
Here’s how we keep AI accountable to yoy - not the other way around.
Your data is never used to train public models
Customer data is never sold, shared, or used to train third-party or public foundation models. It works for you, and only you.
Human oversight & approval controls
Run agents fully autonomous or supervised. Approval workflows, role-based permissions, and audit logs keep a human in the loop wherever you want one.
Guardrails on every agent action
Input validation, output filtering, and brand-safe constraints govern what agents can generate and do - tested against the OWASP Top 10 for LLMs.
Governed models & full auditability
We use contractually approved AI models under our AI Governance Policy. Every model interaction is logged for audit.
Security engineered into every layer
From the network edge to the application to the data at rest, controls are layered so a single failure never exposes your information.
Data protection & encryption
Your data is protected at every stage of its lifecycle.
Encrypted in transit (TLS 1.2+) and at rest (AES-256)
Passwords one-way hashed with bcrypt & per-record salts
Secrets and credentials are managed with automated rotation — no hardcoded credentials in application code
Cloud infrastructure
Built on Amazon Web Services, with isolation and redundancy engineered by design.
Hosted on AWS in the United States
Network segmentation & least-privilege access
SOC 2, ISO, and PCI-validated facilities
Application & product security
Security is part of how we build, from first commit to production deployment.
Secure SDLC with code review & dependency scanning
Annual third-party penetration testing
SSO, SCIM & role-based access control (RBAC)-SCIM ensures access is automatically removed when someone leaves your organization — no manual steps required
Monitoring & incident response
We watch continuously and respond using a defined, audited playbook.
24/7 logging, alerting & threat detection
Documented incident response & notification process
Access to sensitive systems is logged & reviewed
Business continuity & availability
Designed for high availability and to recover fast in the event of a failure.
Redundant, multi-zone architecture
Automated backups with defined RTO & RPO
Public status page for real-time transparency
Vendor & people security
Trust extends to every individual and partner who touches our systems.
Sub-processor due diligence & risk reviews
Background & reference checks before hire
Confidentiality agreements & security training
“Birdeye's security and privacy posture is built for the enterprise. From end-to-end encryption and role-based access controls, to continuous compliance monitoring and third-party audits, to compliance with domestic and international privacy regimes, we've made the investments that matter - so our customers never have to wonder if their data is in good hands.”
Chad Starkey Chief Privacy Officer, Birdeye
Compliance & certifications
Independent auditors validate our controls so your security and compliance teams don't have to
take our word for it. Reports are available in the Trust Center.
SOC 2 Type II
An independent audit of our controls for security, availability, and confidentiality— evaluated over time, not just at a point in time.
Report in Trust Center
ISO/IEC 27001
The internationally recognized standard for an Information Security Management System (ISMS), maintained through annualthird-party audits.
Certificate available
HIPAA
Our products support HIPAA compliance for healthcare brands, with required workforce training and a Business Associate Agreement (BAA) available.
BAA on request
GDPR
We meet the requirements of the EU General Data Protection Regulation, including data subject rights, lawful processing, and a Data Processing Agreement.
DPA available
CCPA / CPRA
We honor California consumer privacy rights, including access, deletion, and the right to opt out of the sale or sharing of personal information.
Rights request supported
AWS-backed infrastructure
Our platform runs on AWS, whose datacenters maintain SOC 1/2/3, ISO 27001, PCIDSS Level 1, and FedRAMP-aligned controls.
Inherited controls
Privacy & your
data rights
Privacy PolicySub-processorsData Processing AgreementSubmit a data request
We use the data you share only to deliver your services -never to build advertising products, and never sold to third parties. You stay in control with tools to access, correct, and delete personal information, plus a published list of the sub-processors we rely on.
Everything your reviewers need, in one place.
We use the data you share only to deliver your services — never to build advertising products, and never sold to third parties. You stay in control with tools to access, correct, and delete personal information, plus a published list of the sub-processors we rely on.
Request Documents
SOC 2 Type II report
Sub-processor list
ISO 27001 certificate
Real-time system status
Penetration test summary
CAIQ / SIG questionnaire
Security & privacy policies
DPA & BAA templates
“Security isn't a feature we bolt on - it's a commitment we earn every day. As we put AI agents to work for our customers, protecting their data and their customers' trust is the standard we hold every decision to.”
Avik Sarkar Chief Information Security Officer, Birdeye
Security resources
Trust Center
Reports, certifications, and policies — released under NDA.
Visit now
System Status
Real-time uptime and incident history for the platform.
Visit status
Privacy Policy
How we collect, use, and protect personal information.
Read policy
Sub-processors
The third parties we use to deliver our services.
View list
Contact Security / Report a Vulnerability
Have a security question or found a vulnerability? We want to hear from you.
Disclose securely
AI Policy
How Birdeye governs the use of AI — for our products, our team, and your data.
Read Policy
HomeAbout Ussecurity