Security
What happens to your prompts, your projects and the code Begin writes for you. Everything on this page is true of the product today.
Encrypted in transit
Every request to the site, the API and the build workers is served over HTTPS. The managed database and object storage the platform runs on encrypt what they hold at rest.
Your code sits in a private repository
Each project builds into its own private repository. It is not published, not indexed and not shared with another workspace, and you can download the whole thing at any time.
No passwords to steal
You sign in with Google or with a one-time link sent to your email. We never create, store or verify a password for you, so there is no password hash on our side to be breached.
Builds are private to the workspace
A project is visible to the account that owns it and, on a team plan, to the members of that workspace. Nobody outside it can open a preview, read the prompt history or fetch the code.
You can delete it all
Delete a project and its builds go with it. Ask us to close your account and we delete your personal data and your projects; we keep only the billing records tax law requires.
We do not train on your prompts
Your prompts and the code produced from them are used to run your builds and nothing else. They are not used to train a model, and they are not sold or shared for anyone else's training.
What we do not claim
Begin holds no third-party security certifications. There is no SOC 2 report, no ISO 27001 certificate and no completed penetration test to send you, because none of those exist yet — we are early, and we would rather write that here than put a badge on the page and explain it later. Nothing above depends on one: they are controls we operate, not audits we passed.
If your review needs something specific — a data flow, a subprocessor list, a deletion commitment in writing — write to [email protected] and you will get a straight answer, including where the answer is “not yet”. What we collect and how long we keep it is in the privacy policy.
Found a vulnerability? Report it to [email protected]. We will confirm receipt, keep you updated while we fix it, and we will not pursue anyone who reports a problem in good faith and does not access other people’s data along the way.