SupportSecurity & PrivacyHow Beryl Protects Your Data

Security & Privacy

How Beryl Protects Your Data

Written by VibeMonitor Support Team·5 min read·Updated February 2026

Beryl tests your app from a URL, and for login-gated flows that can mean handling sensitive credentials. This article explains exactly what data we store, how we protect it, and what controls you have over it.

What data Beryl stores

When you use Beryl, we store the following categories of data:

  • Account data: Your name, work email address, and hashed password (if using email sign-in). We never store plaintext passwords.
  • App and test data: The URL of the app you test, the pages and flows Beryl discovers while crawling it, the plain-language tests it generates, and the results and reports from every run.
  • Login credentials (encrypted): If you ask Beryl to test pages behind a login, the credentials you provide for that app are encrypted at rest and used only to sign in during a crawl or run.
  • Workspace and team data: Your workspace name, team structure, and the apps and test projects configured in it.
  • Billing data: Your Stripe customer ID and subscription status. Payment card details are held exclusively by Stripe and are never transmitted to or stored by Beryl.

How we protect login credentials

Any credentials you provide so Beryl can test login-gated pages are encrypted at rest using AES-256 encryption before being stored in our database. Encryption and decryption use a secret key that is stored separately from the database and is never logged or exposed in application output.

To keep your exposure minimal, we recommend:

  • Use a dedicated test or staging account rather than a real administrator account wherever possible.
  • Credentials are used only to sign in during a crawl or run and are never displayed back to you in plaintext.
  • You can revoke Beryl's access at any time by rotating the password on that account or removing the stored credentials from your workspace.

Infrastructure and data residency

Beryl's infrastructure runs on Amazon Web Services in the United States. Your data is stored in a managed PostgreSQL database hosted on AWS and is not replicated to other countries. We use additional AWS services including S3 for file storage and SQS for background task processing, all within the same AWS region.

If your organisation has data residency requirements outside the United States, contact [email protected] before using the service.

AI and analytics providers

Beryl uses AI to explore your app and author tests, which means the content of the pages it visits is processed by a small set of AI and analytics sub-processors. Google (Gemini) is the primary model our agent reasons with, OpenAI is a fallback used only when Gemini is unavailable, and PostHog (US-hosted) records the model calls so we can debug and improve the agent. We access these models through their paid business APIs, and your data is not used to train third-party models. The full list of these providers, what each one does, and the training-use position is in the AI and automated processing section of our Privacy Notice.

Access controls within your workspace

Access to data within Beryl is controlled by workspace membership and role:

  • Only members of your workspace can view your apps, test projects, and run history.
  • Stored login credentials are never displayed in plaintext after initial entry - they are write-only from the user's perspective.
  • Removing a member from your workspace immediately revokes their access to all workspace data.

Requesting data deletion

You may request deletion of your workspace data at any time by emailing [email protected]. We will process verified deletion requests within 30 days. Deletion is permanent and cannot be undone.

For more information on your privacy rights, including GDPR rights for users in the European Union, see our Privacy Notice.

Reporting a security vulnerability

If you discover a security vulnerability in Beryl, please disclose it responsibly by emailing [email protected] with the subject line "Security Vulnerability Report." Please include a description of the vulnerability, steps to reproduce it, and the potential impact. We aim to acknowledge all reports within 2 business days and provide a resolution timeline.

We ask that you do not publicly disclose the issue until we have had a reasonable opportunity to investigate and remediate it.

Related Articles

Still need help?

Our support team responds within one business day.

Contact support