Seamark Beacon

Seamark Beacon

Security

Security, explained plainly.

Beacon is early-stage, and we are honest about it. Here is what we do to protect your data today — and what we do not claim.

Sign-in you control

Register with email and password (Argon2id, unique salt) or GitHub, Google, or Microsoft. Optional authenticator MFA with email codes as the backup. We never store provider passwords.

Workspace isolation and RBAC

Workspaces keep team pipelines separate. Owner, member, and viewer roles gate what each person can do.

Encrypted cluster secrets

Basic-auth credentials for your Connect clusters are encrypted at rest before storage. Plaintext passwords are not written to disk.

Hashed API keys

API keys are stored as HMAC-SHA256 hashes. The secret is shown once at creation, then only a last-four remains for display.

Full audit trail

Start, stop, restart, create, and delete are recorded with actor and status so control actions are always explainable.

Minimal data collection

We collect what is needed to run the service. No ad tracking. Customer data is not sold.

No compliance badges — yet

We will not claim certifications we have not earned. Production infrastructure runs on MongoDB Atlas and Vercel. We operate on a principle of least privilege. Questions? Email hello@seamarklabs.io or read the Privacy Policy.

Seamark Labs

Try Beacon on a real cluster

Free for your first cluster. No credit card required.