Your Data is Safe With Us
Enterprise-grade security built for multi-jurisdictional compliance. WeChat Work, DingTalk, Feishu, WhatsApp, Microsoft Teams, and Telegram — every IM platform, one trusted framework.
ISO 27001 targeting · MLPS 2.0 Level 3 targeting · SOC 2 Type II targeting
End-to-End Protection
Data encrypted, isolated, and governed across every jurisdiction we operate in.
15 Years in the Trenches
We know what can go wrong with data because we've been there. Since 2010, we've navigated every data security challenge enterprises face — not from a textbook, but from 15 years of fixing them.
Data Quality Issues
We've spent years reconciling metric inconsistencies and cleaning pipelines across enterprises.
Governance Gaps
Seen firsthand what happens when data governance is an afterthought — and how to fix it.
Compliance Headaches
PIPL, PDPO, GDPR, cross-border transfer rules — we've navigated the regulatory minefield for years.
Adoption Failure
We watched 70-85% of BI projects fail to deliver value. That failure drove us to build Beehive.
Analytics Foundations
Google Analytics, marketing analytics, social media analytics. Learned that clients needed real-time insights, not monthly reports.
Enterprise Data
Mobile app analytics, CRM analytics, data transformation. BI adoption stuck at 10-30%. The delivery model was the problem.
Transformation Consulting
Data transformation consulting, BI implementation. Saw the hidden TCO iceberg. Lived the pain of traditional BI.
AI Conversational BI
Built the Beehive platform. Solved the adoption problem by delivering answers in IM — WeChat Work, DingTalk, Feishu, WhatsApp, Microsoft Teams, and Telegram.
Multi-Jurisdictional Compliance
As a Hong Kong-based company serving enterprises in China, Hong Kong, and internationally, we operate under multiple overlapping regulatory regimes. Compliance is not optional — it is a competitive advantage.
China
Three-pillar framework
-
PIPL (Personal Information Protection Law) — China's GDPR. Separate consent, PRC representative, data subject rights.
-
DSL (Data Security Law) — Data classification into core, important, and general tiers.
-
CSL (Cybersecurity Law) — Network operator security and CII protection.
-
MLPS 2.0 Level 3 (Targeting) — National cybersecurity baseline for SaaS platforms. De facto benchmark for B2B SaaS in China.
Hong Kong
Privacy + critical infrastructure
-
PDPO (Cap. 486) — Six Data Protection Principles covering collection, accuracy, use, security, openness, and access.
-
CIO Ordinance (Effective Jan 2026) — Critical infrastructure operators must implement cybersecurity management plans and risk assessments.
-
PCPD RMCs — Recommended Model Clauses as best practice for cross-border transfers (Section 33 not yet in force).
International
Global data protection standards
-
EU GDPR — DPA (Art. 28), RoPA (Art. 30), DPIA (Art. 35), SCCs with Transfer Impact Assessments for EU to HK transfers.
-
EU AI Act — Classified as transparency risk. We disclose AI use to users and ensure human oversight options for enterprise clients.
-
Singapore PDPA — 11 Data Protection Obligations including DPO, consent, breach notification, and transfer limitation.
-
US State Laws — CCPA/CPRA, VCDPA, CPA, TDPSA, CTDPA. Privacy notices, opt-out mechanisms, data minimisation.
Cross-Border Data Transfer Strategy
Our data residency-first approach minimises regulatory complexity and maximises client trust.
Systematic Data Governance
We don't just comply with regulations — we have a systematic approach to data governance that ensures your data is handled correctly at every stage.
Data Classification Framework
| Classification | Examples | Handling Rules |
|---|---|---|
| Restricted | Customer/employee personal data, financial records, trade secrets | AES-256 at rest + TLS 1.3 in transit. Named individuals only. Full audit logging. No LLM prompt exposure. |
| Confidential | Operational metrics, KPIs, business intelligence, aggregated analytics | Encrypted. Role-based access. Audit logging. Only aggregated results in LLM prompts. |
| Internal | Non-sensitive operational data, public metrics | Standard access controls. Encryption in transit. |
| Public | Published reports, public marketing data | No restrictions. |
Data Processing Architecture
Retention Policy
| Data Type | Retention |
|---|---|
| Client raw data | Contract + 30 days, then auto-purge |
| Query logs | 30 days (zero-retention option for enterprise) |
| LLM API responses | Not stored |
| Audit logs | 2 years (encrypted, access-restricted) |
| Training data | N/A — we never use client data for training |
Data Subject Rights
Responsible AI, By Design
We take AI governance seriously. Our architecture ensures that AI serves your business without compromising your data, your compliance, or your control.
Raw Data Never Sent to LLM
Only aggregated and anonymised query results are sent to the LLM for natural language generation. Your raw data never leaves the secure processing environment.
Never Used for Model Training
Client data is never used to train any LLM models. This is a non-negotiable architectural principle, not a policy that can be changed.
Enterprise-Grade LLM Providers Only
We use enterprise-grade LLM providers with data processing agreements, not consumer endpoints. Your queries are processed under contract.
Human Oversight Option
Enterprise clients can require human review before AI-generated answers are delivered. You decide the level of automation.
Full Audit Trail
Every AI interaction is logged — query, response, model used, and timestamp. Complete traceability for compliance and debugging.
EU AI Act Classification
Our conversational BI service falls primarily in the transparency risk tier under the EU AI Act. We disclose AI use to users and provide human oversight options.
Security Inherited, Not Added
Our IM-native delivery model is a security advantage, not a risk. Because we deliver inside your existing IM, we inherit your security framework — your SSO, your MFA, your DLP policies, your data retention rules.
| IM Platform | Inherited Enterprise Security | Our Additional Layer |
|---|---|---|
| WeChat Work | Enterprise authentication, Tencent cloud security | ISV-level data isolation, no credential storage |
| DingTalk | Alibaba cloud security, enterprise SSO | ISV sandbox, data minimisation |
| Feishu | ByteDance enterprise security | Bot API security, scoped permissions |
| End-to-end encryption, Meta enterprise security | Token-based API access, no message content stored | |
| Microsoft Teams | M365 security, Azure AD, DLP policies | Bot Framework security, tenant isolation |
| Telegram | MTProto encryption, bot token security | No sensitive data in messages, auto-delete timers |
| Slack | Enterprise Grid security, SSO, DLP | App-level permissions, scoped tokens |
We don't add a new attack surface — we work within the security framework you've already secured. WeChat Work, DingTalk, Feishu, WhatsApp, Microsoft Teams, and Telegram — every deployment inherits the enterprise-grade security of the platform you choose.
Targeting Industry Standards
We are transparent about where we are and where we are heading. Our security architecture already meets these standards — formal certification is the next step.
Our Security Architecture Already Meets These Standards
While formal certification is in progress, our security architecture already meets the requirements of ISO 27001, MLPS 2.0 Level 3, and SOC 2 Type II. We encrypt all data in transit and at rest, isolate each client's data, never expose raw data to LLMs, and operate within your existing IM security framework across WeChat Work, DingTalk, Feishu, WhatsApp, Microsoft Teams, and Telegram.
Rapid Response Protocol
When an incident occurs, speed and transparency matter. Our six-phase response protocol ensures containment, communication, and remediation.
Detection
Automated monitoring + manual reporting
Assessment
Classify severity, determine scope
Containment
Isolate systems, revoke access
Notification
Notify clients and regulators
Remediation
Fix vulnerability, restore service
Post-Incident
Root cause analysis, preventive measures
Security FAQ
Practical answers about our security practices, compliance posture, and data governance.
How does Beehive Strategy protect client data?
We encrypt all data in transit using TLS 1.3 and at rest using AES-256. Client data is fully isolated per tenant, with role-based access control and complete audit logging. Raw client data never leaves the secure processing environment and is never sent to LLM prompts. Only aggregated, anonymised query results are sent to enterprise-grade LLM providers for natural language generation.
Which data privacy regulations does Beehive Strategy comply with?
We operate under multiple overlapping regulatory regimes. In China: PIPL, DSL, CSL, and we are targeting MLPS 2.0 Level 3. In Hong Kong: PDPO and the CIO Ordinance. Internationally: GDPR, EU AI Act, Singapore PDPA, and applicable US state privacy laws including CCPA/CPRA.
Does Beehive Strategy use client data to train AI models?
No. Client data is never used to train any LLM models. Only aggregated and anonymised query results are sent to the LLM for natural language generation. Raw client data never leaves the secure processing environment. Enterprise clients can additionally require human review before any AI-generated answers are delivered.
Where is client data stored?
We follow a strict data residency strategy. China client data stays in mainland China infrastructure. Hong Kong client data stays in Hong Kong infrastructure. Only aggregated or anonymised results may cross borders, potentially qualifying for China's Scenario A exemption. Where personal data must cross borders, we use the appropriate mechanism — China SCC, GBA Standard Contract, CAC Security Assessment, or EU SCCs with Transfer Impact Assessments.
What security certifications is Beehive Strategy pursuing?
We are currently targeting three key certifications: ISO 27001:2022 (6-12 months), MLPS 2.0 Level 3 (China cybersecurity), and SOC 2 Type II (6-18 months including observation period). Our security architecture already meets these standards — we encrypt all data in transit and at rest, isolate each client's data, never expose raw data to LLMs, and operate within the existing IM security framework of WeChat Work, DingTalk, Feishu, WhatsApp, Microsoft Teams, and Telegram.
Talk to Us About Your Security Requirements
Whether you need to discuss PIPL compliance, data residency options, AI governance, or our certification roadmap — our team is ready to answer your questions.
No credit card · No long-term contract · Cancel anytime