Trust & security

Security evidence,ready for review.

Give security and procurement a clear view of Buena's assurance, privacy practices, access controls, and supporting documentation.

  • Independent assuranceSOC 2 Type II
  • PrivacyGDPR compliant
  • Enterprise accessSSO / SAML

Enterprise assurance

The facts reviewers need first.

A concise register of current assurance, privacy, identity, and enterprise access positions—with a direct route to supporting evidence.

01 / Independent assurance

SOC 2 Type II

Buena's control environment is independently examined under the SOC 2 Type II framework.

Review in the Trust Center
02Privacy

GDPR compliant

Buena maintains privacy practices designed to support GDPR-compliant processing.

Compliant
03Identity

SSO / SAML

Enterprise authentication is available through supported SSO and SAML configurations.

Available
04Authorization

Role-based permissions

Workspace access can be scoped by role so people see and control the work appropriate to them.

Available
05Operations

Dedicated support

Enterprise customers receive dedicated support through evaluation, rollout, and operation.

Enterprise

Product controls

Governed action, by design.

Boundaries sit inside the workflow, so teams can see what is eligible, what requires review, and what happened next.

01
Approval

Human review gates

Require a person to review consequential work, including a first touch, before it moves into execution.

Person in the loop
02
Eligibility

Account boundaries

Keep customers, partners, open opportunities, and other protected groups outside eligible workflows.

Eligibility evaluated
03
Policy

Execution guardrails

Define the channels, local operating hours, and account rules that a workflow must respect.

Policy checked
04
Observability

Traceable decisions

Keep the evidence, policy checks, review state, and resulting activity visible to the team.

Visible to the team

Data protection

Safeguards, stated precisely.

Buena pairs technical and organizational safeguards with documented enterprise controls. Current status and supporting documentation live in the Trust Center.Review security documentation
01Protection

Encryption in transit and at rest

The privacy policy describes encryption in transit (TLS/SSL) and at rest, alongside access controls and authentication.

02Access

Restricted data access

Access controls and authentication are paired with need-to-know access for authorized personnel.

03Operations

Secure development and response

Security assessment, secure development practices, and incident-response procedures form part of the operating approach.

04Providers

Processor governance

Service providers processing data on Buena's behalf operate under data processing agreements and appropriate safeguards.

Responsible automation

Keep judgment in the system.

Match autonomy to consequence, evidence quality, and the controls around execution.

01

Show the evidence

Keep the triggering change and account context beside the recommendation so a person can inspect the basis for action.

02

Match autonomy to risk

Automate bounded preparation work first, then retain review where a decision affects an account or external communication.

03

Learn from outcomes

Use accepted, rejected, edited, and disqualified work to refine the workflow rather than expanding activity by default.

Read the responsible automation field guide

Security review

Give your reviewers a better starting point.

Begin with the current assurance materials, then bring Buena into the conversation for workflow-specific questions.

Review current compliance status, supporting documentation, and control details in the Buena Trust Center. Product configuration is confirmed against your intended workflow during evaluation.

Ask a data protection question
  1. 01

    Share your requirements

    Bring the data, access, deployment, review, and procurement requirements that matter to your organization.

  2. 02

    Review the workflow

    Map where data enters, which decisions Buena supports, and which actions remain gated by your team.

  3. 03

    Confirm the implementation

    Agree the available controls and documentation for the specific product scope before deployment.