Security & Trust

Security built for sensitive work.

Belt's apps are designed for teams that handle confidential information. Data stays close to the user, isolated per customer, encrypted end to end, and processed only where you choose — on your device or in your own single-tenant cloud.

desktop_windows

Desktop-first architecture

Belt's products are primarily desktop applications backed by hybrid cloud storage. Work happens close to where the data lives, reducing exposure and keeping sensitive workflows local by default.

database

Single-tenant isolation

Every customer's cloud database is single-tenant. Your data is not commingled in a shared multi-tenant database — it lives in an isolated environment dedicated to your organization, which simplifies isolation, residency, and clean off-boarding.

lock

End-to-end encryption

Data is encrypted end to end, in transit (TLS) and at rest. Keys are managed with industry-standard practices, and encryption is applied across the storage and transport layers.

verified_user

SSO with Google & Microsoft 365

Authenticate through your existing identity provider with single sign-on via Google and Microsoft 365 (OIDC/SAML). Belt never receives or stores your SSO passwords, and access follows your directory's provisioning and de-provisioning.

cloud_sync

Local or cloud models — your choice

Run AI fully on-device with local models so prompts and content never leave your environment, or opt into cloud models when you want them. Administrators control which models are enabled, and can restrict sensitive workflows to local inference only.

policy

Compliance & transparency

Belt aligns its controls to recognized frameworks and supports customer compliance programs.

  • SOC 2 (Type II) control alignment
  • GDPR & CCPA/CPRA readiness
  • Transparent sub-processor list in our DPA
  • No use of Customer Data to train models
admin_panel_settings

Access & operations

  • Least-privilege, need-to-know access controls
  • Logging, monitoring, and alerting
  • Vulnerability management and secure development
  • Backups and resilience
crisis_alert

Incident response

We maintain a documented incident response process and will notify affected customers without undue delay of any personal data breach, as described in our DPA.

Questions about security or compliance?

We're happy to share our sub-processor list, security documentation, and compliance reports under NDA. Review our Privacy Policy, DPA, and Terms, or reach out directly.

Contact the Belt team