Platform
Organization & Admin
The control plane that sits above every workspace. Members, identity, security posture, integrations, and audit. One place for the admin to see and govern the whole tenant.
One Control Plane
Everything an admin needs, in one place
Members, workspaces, integrations, secrets, audit, security posture. The org admin home pulls it all into a single view, so setup work and ongoing governance don't require switching contexts.
- Org-level visibility. See every workspace, every active project, and every member from one screen.
- Setup without tickets. Admins add users, create workspaces, and assign roles directly.
- Governance always on. Every action against any resource captured in the audit log.
Members & roles
Manage every person on the platform.
Add and remove people. Move them between workspaces. Adjust their role. Every change captured in the audit log with actor, action, resource, and timestamp.
- Roles that fit insurance teams. Admin, Builder, Reviewer, Annotator. Assign at the workspace or project level.
- Invite, revoke, reassign. Onboard a new claims analyst in minutes. Offboard with one click. Cross-scope access stays denied by default.
- Quarterly access reviews. Bevaya audits access controls every quarter as part of its security operations.
Security & Trust
Built for the most regulated industry there is..
Bevaya was built for an industry where data security isn't optional. SOC 2 Type 2 certified, independently audited every year. Customer data encrypted end-to-end with 256-bit AES. Never shared with other customers or vendors.
- SOC 2 Type 2, independently audited. Compliant with HIPAA, CCPA, GDPR, and 23 NYCRR 500.
- 256-bit AES end-to-end. Data encrypted in transit and at rest. Customer data is never used to train models for other customers.
- Hosted on Microsoft Azure. No on-premises hardware.
- Secure connectivity. SSL-encrypted API calls and IP-whitelisting.
FEATURE INDEX
Inside Organization & Admin
Members & roles | Capability
One directory for every person on the platform. Add, move, and remove members. Adjust roles at the workspace or project level. Every change captured in the audit log.
- Member directory across the tenant
- Standard roles: Admin, Builder, Reviewer, Annotator
- Workspace-scoped and project-scoped assignments
- Invite, role change, and revocation
- Member activity history
- Quarterly access review reporting
Tenant structure | Capability
Organization, Workspace, and Project levels give every deployment a clean backbone. Resources stay isolated. Cross-scope access is denied by default.
- Organization, Workspace, Project hierarchy
- Workspace creation and lifecycle controls
- Project archiving and restoration
- Strict data isolation at every level
- Cross-scope access denied by default
- Resource tagging and search across the tenant
Security & compliance | Capability
Bevaya was built for an industry where data security isn't optional. Independent annual audits, encryption end-to-end, secure connectivity, and dedicated cloud storage.
- SOC 2 Type 2, independently audited annually
- HIPAA, CCPA, GDPR, 23 NYCRR 500 compliant
- 256-bit AES encryption at rest and in transit
- Hosted on Microsoft Azure, US data centers
- SSL-encrypted API calls and IP-whitelisting
- Daily and weekly backups across multiple data centers
- Annual penetration testing
Audit & reporting | Capability
Every action against any resource captured immutably with actor, action, resource, and timestamp. Quarterly access reviews and one-click compliance exports keep auditors satisfied.
- Immutable audit log: actor, action, resource, timestamp
- Coverage of creates, updates, deletes, role changes
- Secret access events logged with reference, not value
- Quarterly access audit reporting
- Compliance export for SOC 2, HIPAA, NYCRR 500 reviews
- Incident response with direct customer communication
Resources & insights
More on Workspaces

Research
Page stream segmentation with LLMs
How Bevaya Labs approaches a foundational problem in insurance document AI.

Case Study
Workers' comp carrier processes claims 100x faster
How indexing automation delivered 432% ROI in 12 months.

Architecture
Inside the Bevaya platform architecture
How specialized models, HITL controls, and integrations come together in production.
More Capabilities
Explore the rest of the platform.
Designed, deployed, and governed together. Powered by InsurGPT™ and accessed through the AI Assistant.
Workflow Canvas
Visual builder and production runtime for every automation.
Current page ReviewHuman-in-the-Loop
Configurable review queues with X-Ray verification and a patented feedback loop.
Current page DocumentsDocument Intelligence
Read any insurance document — hundreds of carrier formats, scanned or digital.
Current page GroundingGrounded Explainability
Every value traceable to its source. X-Ray Highlight Mode brings citations to reviewers.
Current page AnalyticsAnalytics Dashboard
Live accuracy, STP rates, reviewer SLA, and agent performance across every workflow.
Current page GovernanceGoverned Automation
Immutable audit trails, role-based access, flow versioning. Compliance is the architecture.
Current pageTrust & Security
Trust by design
Built for an industry where data security isn't optional.
Your data stays yours.
Never shared with other customers or vendors. Bevaya doesn't train shared models on your data.
Visit the Trust CenterYour data · only your team sees it
Encrypted end-to-end.
256-bit AES encryption, in transit and at rest. Independent third-party audits conducted annually.
Visit the Trust CenterAudited annually · independent third party
Runs in Azure.
Enterprise-grade infrastructure, hosted where insurance organizations already trust their data.
Visit the Trust CenterDeploy where your stack already lives
Every decision audited.
Immutable audit logs. Confidence scoring. Human-in-the-Loop review on low-confidence items.
Visit the Trust CenterImmutable trail · every decision, every reviewer
FAQ
Common questions.
The admin is typically someone on the IT, automation, or operations team who owns user setup, integrations, and governance. It does not need to be a developer. Admins can be added or changed at any time, and the role can be held by more than one person for redundancy.
SOC 2 Type 2, independently audited annually. Bevaya is also compliant with HIPAA, CCPA, GDPR, and 23 NYCRR 500. The current SOC 2 report is available to qualified prospects and customers under NDA.
End-to-end encryption with 256-bit AES, in transit and at rest. Customer data is stored in dedicated cloud storage and is never shared with other customers or vendors. It is never used to train models for other customers. Daily and weekly backups are stored across multiple data centers.
SSL-encrypted API calls and IP-whitelisting. This is the same secure access model trusted BPO partners use. Pre-built connectors are available for Guidewire (ClaimCenter, InsuranceSuite, InsuranceNow), Salesforce, Outlook, SFTP, and any system reachable by HTTP API.
Bevaya runs a prioritized incident response protocol with prompt remediation, law enforcement engagement as needed, root cause analysis, and direct customer communication at time of breach and following RCA completion.
Access to customer data is audited quarterly. Bevaya also performs penetration testing annually. Findings flow into the security operations program and are available to customers on request.
Get Started
Ready to design, deploy, and govern your AI workforce?
Bevaya AI Agents can help you triage, analyze, and recommend across underwriting, claims, and policy servicing.
Let's connect and show you how it works.


