Security & Compliance

Your Data is Safe With Us

Enterprise-grade security built for multi-jurisdictional compliance. WeChat Work, DingTalk, Feishu, WhatsApp, Microsoft Teams, and Telegram — every IM platform, one trusted framework.

ISO 27001 targeting · MLPS 2.0 Level 3 targeting · SOC 2 Type II targeting

15+
Years Experience
7
IM Platforms
AES-256
Encryption at Rest
TLS 1.3
Encryption in Transit

End-to-End Protection

Data encrypted, isolated, and governed across every jurisdiction we operate in.

PIPL GDPR PDPO EU AI Act
01 — Experience & Trust

15 Years in the Trenches

We know what can go wrong with data because we've been there. Since 2010, we've navigated every data security challenge enterprises face — not from a textbook, but from 15 years of fixing them.

Data Quality Issues

We've spent years reconciling metric inconsistencies and cleaning pipelines across enterprises.

Governance Gaps

Seen firsthand what happens when data governance is an afterthought — and how to fix it.

Compliance Headaches

PIPL, PDPO, GDPR, cross-border transfer rules — we've navigated the regulatory minefield for years.

Adoption Failure

We watched 70-85% of BI projects fail to deliver value. That failure drove us to build Beehive.

2010 – 2015

Analytics Foundations

Google Analytics, marketing analytics, social media analytics. Learned that clients needed real-time insights, not monthly reports.

2015 – 2020

Enterprise Data

Mobile app analytics, CRM analytics, data transformation. BI adoption stuck at 10-30%. The delivery model was the problem.

2020 – 2025

Transformation Consulting

Data transformation consulting, BI implementation. Saw the hidden TCO iceberg. Lived the pain of traditional BI.

2025 – 2026

AI Conversational BI

Built the Beehive platform. Solved the adoption problem by delivering answers in IM — WeChat Work, DingTalk, Feishu, WhatsApp, Microsoft Teams, and Telegram.

02 — Regulatory Compliance

Multi-Jurisdictional Compliance

As a Hong Kong-based company serving enterprises in China, Hong Kong, and internationally, we operate under multiple overlapping regulatory regimes. Compliance is not optional — it is a competitive advantage.

China

Three-pillar framework

  • PIPL (Personal Information Protection Law) — China's GDPR. Separate consent, PRC representative, data subject rights.
  • DSL (Data Security Law) — Data classification into core, important, and general tiers.
  • CSL (Cybersecurity Law) — Network operator security and CII protection.
  • MLPS 2.0 Level 3 (Targeting) — National cybersecurity baseline for SaaS platforms. De facto benchmark for B2B SaaS in China.

Hong Kong

Privacy + critical infrastructure

  • PDPO (Cap. 486) — Six Data Protection Principles covering collection, accuracy, use, security, openness, and access.
  • CIO Ordinance (Effective Jan 2026) — Critical infrastructure operators must implement cybersecurity management plans and risk assessments.
  • PCPD RMCs — Recommended Model Clauses as best practice for cross-border transfers (Section 33 not yet in force).

International

Global data protection standards

  • EU GDPR — DPA (Art. 28), RoPA (Art. 30), DPIA (Art. 35), SCCs with Transfer Impact Assessments for EU to HK transfers.
  • EU AI Act — Classified as transparency risk. We disclose AI use to users and ensure human oversight options for enterprise clients.
  • Singapore PDPA — 11 Data Protection Obligations including DPO, consent, breach notification, and transfer limitation.
  • US State Laws — CCPA/CPRA, VCDPA, CPA, TDPSA, CTDPA. Privacy notices, opt-out mechanisms, data minimisation.

Cross-Border Data Transfer Strategy

Our data residency-first approach minimises regulatory complexity and maximises client trust.

China data stays in China — processed and stored within mainland China infrastructure
HK data stays in HK — processed and stored within Hong Kong infrastructure
Aggregated results only cross borders — qualifying for Scenario A exemption
EU SCCs + TIA for EU transfers; China SCC or GBA Standard Contract for China transfers
03 — Data Governance

Systematic Data Governance

We don't just comply with regulations — we have a systematic approach to data governance that ensures your data is handled correctly at every stage.

Data Classification Framework

Classification Examples Handling Rules
Restricted Customer/employee personal data, financial records, trade secrets AES-256 at rest + TLS 1.3 in transit. Named individuals only. Full audit logging. No LLM prompt exposure.
Confidential Operational metrics, KPIs, business intelligence, aggregated analytics Encrypted. Role-based access. Audit logging. Only aggregated results in LLM prompts.
Internal Non-sensitive operational data, public metrics Standard access controls. Encryption in transit.
Public Published reports, public marketing data No restrictions.

Data Processing Architecture

Client Data Sources
CRM, ERP, DB, APIs
Encrypted Ingestion
TLS 1.3 + PII Detection
Secure Processing
Region-Specific (China / HK / Intl)
AI Agent Layer
Aggregated Data Only to LLM
IM Delivery
WeChat Work, DingTalk, Feishu, WhatsApp, Teams, Telegram

Retention Policy

Data Type Retention
Client raw data Contract + 30 days, then auto-purge
Query logs 30 days (zero-retention option for enterprise)
LLM API responses Not stored
Audit logs 2 years (encrypted, access-restricted)
Training data N/A — we never use client data for training

Data Subject Rights

Access — request all account data within 30 days
Correction — correct data via platform or support request
Deletion — request deletion, completed within 30 days (90 days from backups)
Portability — export data in JSON/CSV format
Objection — object to processing; we stop within 15 days
Withdrawal of consent — withdraw at any time; processing stops immediately
04 — AI & LLM Governance

Responsible AI, By Design

We take AI governance seriously. Our architecture ensures that AI serves your business without compromising your data, your compliance, or your control.

Raw Data Never Sent to LLM

Only aggregated and anonymised query results are sent to the LLM for natural language generation. Your raw data never leaves the secure processing environment.

Never Used for Model Training

Client data is never used to train any LLM models. This is a non-negotiable architectural principle, not a policy that can be changed.

Enterprise-Grade LLM Providers Only

We use enterprise-grade LLM providers with data processing agreements, not consumer endpoints. Your queries are processed under contract.

Human Oversight Option

Enterprise clients can require human review before AI-generated answers are delivered. You decide the level of automation.

Full Audit Trail

Every AI interaction is logged — query, response, model used, and timestamp. Complete traceability for compliance and debugging.

EU AI Act Classification

Our conversational BI service falls primarily in the transparency risk tier under the EU AI Act. We disclose AI use to users and provide human oversight options.

AI Disclosure Human Review Hallucination Guard
05 — IM Platform Security

Security Inherited, Not Added

Our IM-native delivery model is a security advantage, not a risk. Because we deliver inside your existing IM, we inherit your security framework — your SSO, your MFA, your DLP policies, your data retention rules.

IM Platform Inherited Enterprise Security Our Additional Layer
WeChat Work Enterprise authentication, Tencent cloud security ISV-level data isolation, no credential storage
DingTalk Alibaba cloud security, enterprise SSO ISV sandbox, data minimisation
Feishu ByteDance enterprise security Bot API security, scoped permissions
WhatsApp End-to-end encryption, Meta enterprise security Token-based API access, no message content stored
Microsoft Teams M365 security, Azure AD, DLP policies Bot Framework security, tenant isolation
Telegram MTProto encryption, bot token security No sensitive data in messages, auto-delete timers
Slack Enterprise Grid security, SSO, DLP App-level permissions, scoped tokens

We don't add a new attack surface — we work within the security framework you've already secured. WeChat Work, DingTalk, Feishu, WhatsApp, Microsoft Teams, and Telegram — every deployment inherits the enterprise-grade security of the platform you choose.

06 — Certifications Roadmap

Targeting Industry Standards

We are transparent about where we are and where we are heading. Our security architecture already meets these standards — formal certification is the next step.

ISO 27001:2022

Information Security Management

Targeting

Global standard for data security. Required by most enterprise clients, especially financial services. 93 controls across 4 themes.

Timeline: 6–12 months

MLPS 2.0 Level 3

China Cybersecurity Protection

Targeting

De facto benchmark for serious B2B SaaS in China. Requires security management systems, network segmentation, access control, encryption, and incident response.

In progress

SOC 2 Type II

Service Organisation Controls

Targeting

US/international standard for SaaS providers. Covers security, availability, processing integrity, confidentiality, and privacy.

Timeline: 6–18 months (incl. observation period)

Our Security Architecture Already Meets These Standards

While formal certification is in progress, our security architecture already meets the requirements of ISO 27001, MLPS 2.0 Level 3, and SOC 2 Type II. We encrypt all data in transit and at rest, isolate each client's data, never expose raw data to LLMs, and operate within your existing IM security framework across WeChat Work, DingTalk, Feishu, WhatsApp, Microsoft Teams, and Telegram.

07 — Incident Response

Rapid Response Protocol

When an incident occurs, speed and transparency matter. Our six-phase response protocol ensures containment, communication, and remediation.

01

Detection

Automated monitoring + manual reporting

Real-time
02

Assessment

Classify severity, determine scope

Within 1 hour
03

Containment

Isolate systems, revoke access

Within 4 hours
04

Notification

Notify clients and regulators

Within 72 hours
05

Remediation

Fix vulnerability, restore service

24–48 hours
06

Post-Incident

Root cause analysis, preventive measures

Within 2 weeks

Security FAQ

Practical answers about our security practices, compliance posture, and data governance.

How does Beehive Strategy protect client data?

We encrypt all data in transit using TLS 1.3 and at rest using AES-256. Client data is fully isolated per tenant, with role-based access control and complete audit logging. Raw client data never leaves the secure processing environment and is never sent to LLM prompts. Only aggregated, anonymised query results are sent to enterprise-grade LLM providers for natural language generation.

Which data privacy regulations does Beehive Strategy comply with?

We operate under multiple overlapping regulatory regimes. In China: PIPL, DSL, CSL, and we are targeting MLPS 2.0 Level 3. In Hong Kong: PDPO and the CIO Ordinance. Internationally: GDPR, EU AI Act, Singapore PDPA, and applicable US state privacy laws including CCPA/CPRA.

Does Beehive Strategy use client data to train AI models?

No. Client data is never used to train any LLM models. Only aggregated and anonymised query results are sent to the LLM for natural language generation. Raw client data never leaves the secure processing environment. Enterprise clients can additionally require human review before any AI-generated answers are delivered.

Where is client data stored?

We follow a strict data residency strategy. China client data stays in mainland China infrastructure. Hong Kong client data stays in Hong Kong infrastructure. Only aggregated or anonymised results may cross borders, potentially qualifying for China's Scenario A exemption. Where personal data must cross borders, we use the appropriate mechanism — China SCC, GBA Standard Contract, CAC Security Assessment, or EU SCCs with Transfer Impact Assessments.

What security certifications is Beehive Strategy pursuing?

We are currently targeting three key certifications: ISO 27001:2022 (6-12 months), MLPS 2.0 Level 3 (China cybersecurity), and SOC 2 Type II (6-18 months including observation period). Our security architecture already meets these standards — we encrypt all data in transit and at rest, isolate each client's data, never expose raw data to LLMs, and operate within the existing IM security framework of WeChat Work, DingTalk, Feishu, WhatsApp, Microsoft Teams, and Telegram.

Talk to Us About Your Security Requirements

Whether you need to discuss PIPL compliance, data residency options, AI governance, or our certification roadmap — our team is ready to answer your questions.

No credit card · No long-term contract · Cancel anytime