BeforeMay docs
Security, data & AI

Security, data and AI

A starting point for practice owners, procurement teams and system reviewers.

Source reviewed Security and privacy documentation

Evaluate the flow you intend to use and the data it will handle. The guides below explain product behaviour and implementation boundaries. The Privacy Policy and Terms and Conditions remain the policy and contractual sources.

QuestionGuide
Where does the data go?Data flow and processing locations
What does AI receive and who checks its output?AI processing and human review
Who can see or change records?Accounts, roles and access controls
What is retained, and what does deletion remove?Retention, deletion and exports
What evidence should we request?Technical and business assessment

Read claims at the right level

A source review describes what the implementation does. It does not establish that a control was tested against your practice, that a restore was exercised recently or that an external assessor certified the system. Ask for evidence against the deployed version and the service you are adopting.

Australian storage does not mean all processing remains in Australia. Removing selected identifiers does not anonymise a document. A completed identity check does not complete every due-diligence obligation, and an AI-reviewed workbook still needs the accountant's review.

Contact

For technical evidence and product questions, contact support@beforemay.com.au. For privacy requests or a suspected security/privacy incident, contact privacy@beforemay.com.au. Tell us which product and control you are assessing; do not send credentials or a client document in the initial request.

On this page