Security

Updated on September 14, 2026

Infrastructure

Our entire service infrastructure is based on state-of-the-art cloud technology. We have deliberately decided against operating our own hardware and dispense entirely with our own routers, load balancers, DNS servers or physical servers. Instead, we rely on the services of leading cloud providers such as Google Cloud, Amazon Web Services and Microsoft Azure. To meet the strict requirements of data protection, we take particular care that our services are hosted on servers within the European Union. We deliberately avoid hosting on US servers in order to ensure maximum data security and compliance. Our flexibility allows us to respond to the individual needs of our customers. Where required, we can offer specific providers or alternative geographic locations, always taking into account the applicable data protection regulations and security requirements.

Network

The security of our network has the highest priority. Our architecture comprises several security zones that ensure comprehensive protection against unauthorized access. We rely on a virtual private cloud (VPC) with strict network access control lists (ACLs) and do without public IP addresses. A key element of our strategy is the use of a modern, WireGuard-based VPN tool that strictly controls access to our infrastructure: only verified administrators can access our systems through this secure network. An advanced firewall continuously monitors and controls network traffic, while strict IP address filtering further restricts access. To protect against DDoS attacks, we use state-of-the-art defense mechanisms. These comprehensive measures ensure that our network is protected around the clock and that potential threats are detected and repelled at an early stage.

Encryption

The protection of sensitive data is a core aspect of our security strategy. We rely on a two-tier encryption strategy to ensure maximum security. All data sent to or received from our infrastructure is encrypted in transit using Transport Layer Security (TLS) in accordance with the latest industry standards. This ensures that information is protected against unauthorized access during transport. In addition to encryption in transit, we also rely on robust encryption at rest. All user data, including sensitive information such as passwords, is secured in our database using proven and reliable encryption algorithms. This double layer of protection ensures that your data is optimally protected at all times, whether in transit or in storage.

Data retention

Our approach to data storage and deletion is designed to meet both legal requirements and the individual needs of our customers. By default, we store data for a period of up to 12 months. However, we understand that different companies and industries may have different data retention requirements. We therefore offer our customers tailored data retention policies. These range from 1-month retention through shorter periods such as a week or a day to hourly retention. For customers with particularly high security requirements, we even offer the option of immediate data deletion. After the defined retention period expires, all data is completely and irrevocably removed from our dashboard and servers. We place great value on transparency and control: every user has the right to request the deletion of their usage data at any time by simply contacting our support team.

Data processing

Biem uses advanced artificial intelligence to develop state-of-the-art models. Our approach to data processing and model training is based on transparency and respect for the privacy of our users. Regardless of whether our customers use the Elemental, Professional or Enterprise package, the same rules apply to all regarding the use of data for AI training and model development. We attach great importance to ensuring that the use of data for training our AI models is based on a conscious and informed decision by our customers. The use of user data for this purpose is therefore disabled by default. Customers must explicitly give their consent before their data or the data of their installations is used to train AI models.

This approach ensures that our customers retain full control over their data and can decide for themselves whether they wish to contribute to the further development of our AI technologies. We ensure that this process is transparent and easy for our customers to understand, so that they can make an informed decision. This approach underlines our commitment to data protection while respecting the wish of many customers to contribute to the further development of innovative AI solutions.

Continuity

Ensuring business continuity and an effective disaster recovery strategy are central aspects of our corporate philosophy. We rely on a robust system of regular backups of all critical assets. To ensure the reliability and speed of our recovery process, we carry out recovery tests at regular intervals. This practice enables us to guarantee rapid recovery in the event of an unforeseen incident and to reduce potential downtime to a minimum. The security of your data always remains the priority: all our backups are encrypted at rest to ensure their confidentiality even in the unlikely event of unauthorized access to the backup data.

Application security

The security of our applications is our top priority. We rely on advanced, enterprise-grade protection mechanisms to comprehensively protect our infrastructure and our customers’ data. Our security system provides robust protection against DDoS (Distributed Denial of Service) attacks and at the same time acts as a powerful Web Application Firewall (WAF). This technology enables us to quickly detect and effectively mitigate attacks on our cloud-based workloads and virtual machines. A particular feature of our security approach is the use of machine learning. This adaptive protection mechanism enables us to detect and block Layer 7 DDoS attacks in real time, keeping us one step ahead at all times.

We place particular emphasis on mitigating the Top 10 risks identified by OWASP (Open Web Application Security Project). Our security system protects our workloads both on-premises and in the cloud against these most common and most critical security threats. In addition, we have implemented advanced bot management. It uses modern bot detection technologies to prevent fraud on edge devices and to ensure the integrity of our services. Through these comprehensive security measures, we ensure that our applications and our customers’ data are protected in the best possible way. We remain vigilant at all times and continuously adapt our security strategies to stay one step ahead of the ever-evolving threats in the digital world.

Development

Our development processes follow strict security guidelines and best practices aligned with leading security frameworks such as the OWASP Top 10 and SANS Top 25. This alignment enables us to identify and remediate potential vulnerabilities at an early stage, ensuring the highest level of security in our products. Our development team undergoes regular training to stay informed about the latest security threats and defense mechanisms. This continuous training enables us to integrate security into our products from the ground up and to respond proactively to new challenges. We rely on multi-layered security reviews in our development process, including code reviews in which experienced developers examine the code for security vulnerabilities.

In addition, we use automated tools for static and dynamic application security testing (SAST and DAST) to identify potential vulnerabilities in the code and in the running application. Our dependencies are regularly updated and checked for known vulnerabilities to ensure that we do not use vulnerable components in our software. Furthermore, we carry out automated penetration tests and engage external security experts annually for comprehensive manual penetration tests of our applications. This holistic approach to secure development enables us to continuously improve the security of our products and to strengthen our customers’ trust in our solutions.

User security

The security and convenience of our users are at the center of our authentication strategy. We offer advanced single sign-on (SSO) solutions that allow users to access our services securely and conveniently. For our Enterprise customers, we provide SSO options that can be seamlessly integrated into their existing identity management systems. This not only increases security through the use of centralized authentication mechanisms, but also improves the user experience by eliminating the need for multiple passwords. Our authentication system is designed to meet modern security standards while being flexible enough to adapt to the specific needs and preferences of our different user groups. By implementing advanced authentication methods, we not only strengthen the security of our platform but also improve the overall efficiency and usability of our system.

Compliance

As a Swiss provider, we attach the greatest importance to compliance with national and international data protection regulations. Our compliance framework is based primarily on the Swiss Bundesgesetz über den Datenschutz (DSG). At the same time, we meet the requirements of the European General Data Protection Regulation (GDPR). We have carefully aligned our processes, policies and technical measures with the requirements of both the DSG and the GDPR. This ensures comprehensive protection of personal data and the safeguarding of the extended rights of data subjects under both laws.

Our measures include improved transparency in data processing, strict consent requirements and extended rights of access, erasure and data portability. In addition to these legal obligations, we are working toward further important certifications. We are in the process of achieving SOC 2 Type II compliance and obtaining ISO 27001 certification. These internationally recognized standards underline our commitment to information security, availability, processing integrity and confidentiality.

Our multi-layered compliance approach, which incorporates national, EU-wide and international standards, demonstrates our unwavering commitment to protecting our customers’ data. We strive not only to meet the minimum legal requirements but to implement best practices in data protection and information security. Through this comprehensive approach, we strengthen our customers’ trust in our ability to protect their sensitive information with the utmost care and in accordance with the strictest legal and ethical standards.

Payment security

The secure handling of our customers’ payment information is our top priority. To ensure the highest level of security, we have chosen to outsource the processing of all payment instruments to Stripe, a leading provider of payment infrastructure certified as a PCI Level 1 Service Provider. This certification represents the highest security standard in the payment card industry. Through this outsourcing, we ensure that our customers’ sensitive financial data is handled with the utmost care and in compliance with the strictest security protocols. A key advantage of this approach is that we ourselves do not collect or store any payment information.

This significantly minimizes the risk of data leaks and relieves us of the complex PCI DSS obligations that would come with directly processing credit card data. Stripe’s robust security infrastructure includes advanced encryption technologies, regular security audits and continuous monitoring to prevent fraud and unauthorized access. By using these highly specialized services, we can focus on our core competencies while guaranteeing our customers the highest level of security in their financial transactions. We recommend that our customers learn about Stripe’s security practices in detail to gain a comprehensive understanding of the measures that protect their payment data.

Employee access

Responsible handling of customer data begins with our own employees. We have implemented strict internal procedures that severely restrict employee or administrator access to user data. These measures serve to protect our customers’ privacy and minimize the risk of unauthorized data access. Our access management is based on the principle of least privilege, which means that employees can only access the data and systems that are strictly necessary for their specific role. In exceptional cases, for example for customer support, limited access can be granted, but only after a strict approval process and with detailed logging of all activities.

For additional protection, we use advanced authentication methods such as two-factor authentication for all employee access. Every employee who is given access to sensitive systems or data must first complete comprehensive training in data protection and information security. In addition, all our employees sign a strict confidentiality and non-disclosure agreement when joining the company. This agreement legally obliges them to protect our customers’ sensitive information and treat it confidentially. Regular audits and reviews ensure that these policies are adhered to and that access rights are always up to date and appropriate. Through these multi-layered security measures, we create a corporate culture in which the protection of customer data is not merely a rule but a deeply rooted responsibility of every single employee.

Commitment

The security measures and practices set out in this document form the foundation of our unwavering commitment to protecting your data and the integrity of our services. From robust infrastructure security to strict development standards, we pursue a holistic approach to cybersecurity. We understand that security in the digital world is not a one-time task but a continuous process. We therefore commit to constantly reviewing, updating and improving our security practices in order to keep pace with evolving threats.

Our commitment goes beyond mere compliance with regulations; we strive to be an industry leader in data protection and information security. We invite our customers to ask questions, raise concerns and actively engage with us on security topics. Transparency and trust are the cornerstones of our relationships, and we always strive to strengthen them.

By using state-of-the-art technologies, following strict policies and fostering a culture of security throughout our company, we work tirelessly to offer you the highest level of protection and reliability. Your trust is our most valuable asset, and we do everything we can to earn it anew every day. Together, we are building a more secure digital future.

Contact

If you have any questions about security, please contact us.

The dawn of a new era in retail.