Protecting participant information and maintaining the security, integrity, and reliable operation of the Companion are essential expressions of the trust that participants place in been.
This Security & Infrastructure Statement describes the technical and operational safeguards that are currently implemented within the Companion. It also explains the principles that guide our approach to security and identifies areas where future development may strengthen the system as the Companion evolves.
Security within been is not treated as a separate technical concern. It forms part of the broader ethical responsibility to provide a trustworthy environment for reflection, protect participant information, support responsible stewardship, and maintain confidence in the operation of the Companion.
This document describes the current implementation of been at the time of publication. As the Companion develops, elements of the technical infrastructure may change. Significant changes that materially affect the protection of participant information or the operation of the Companion will be reflected through updates to this document and the wider Governance Framework.
Security Principles
The security of been is guided by principles that include:
- protecting participant information from unauthorized access, disclosure, alteration, or misuse;
- limiting access to participant information wherever reasonably possible;
- applying security measures that are proportionate to the current implementation and operational needs of the Companion;
- using recognized security practices appropriate to the technologies supporting the service;
- maintaining transparency about how participant information is protected;
- supporting privacy through responsible technical and operational safeguards;
- continuously reviewing security practices as the Companion evolves; and
- strengthening security in ways that remain consistent with the ethical commitments described throughout the Governance Framework.
No security measure can eliminate every possible risk. The objective of been is not to claim absolute security, but to implement reasonable safeguards, review them continuously, respond responsibly to emerging risks, and improve the security of the Companion as it develops.
Security within been is therefore understood as an ongoing practice of responsible stewardship rather than a completed technical achievement.
Current Technical Infrastructure
At the time of publication, been is implemented as a secure web application using managed cloud infrastructure.
The current implementation includes:
- managed authentication services;
- a managed PostgreSQL database;
- secure HTTPS communication;
- server-side AI processing;
- managed cloud hosting; and
- controlled access to participant information through application-level permissions.
The technical infrastructure has been selected to provide a secure, reliable, and scalable foundation for the Companion while supporting responsible management of participant information.
As been continues to evolve, elements of the technical infrastructure may change. Significant architectural changes affecting participant information or the operation of the Companion will be reflected through updated governance documentation where appropriate.
Authentication
Participant accounts are protected through managed authentication services designed to support secure access to the Companion.
At the time of publication, the current implementation includes:
- email and password authentication;
- authenticated sessions using secure access tokens; and
- server-side validation of authenticated requests before protected resources are accessed.
Authentication mechanisms are reviewed as part of the ongoing development of the Companion. Additional authentication features may be introduced in future versions where they strengthen security while remaining proportionate to the needs of the service.
Data Protection
Participant information is protected through multiple technical and operational safeguards working together to reduce the risk of unauthorized access or disclosure.
At the time of publication, the current implementation includes:
- encrypted communication between participants and the application using HTTPS;
- encryption provided by the managed cloud infrastructure for stored data;
- row-level access controls restricting participants to their own conversations and information; and
- server-side validation before protected participant information is accessed.
These safeguards are intended to support the confidentiality, integrity, and availability of participant information while remaining proportionate to the current implementation of the Companion.
As the technical implementation evolves, additional safeguards may be introduced to strengthen the protection of participant information where appropriate.
Access Controls
Access to participant information is intentionally restricted in accordance with the principle of least privilege. Participant information should be accessible only to those who require it for the legitimate operation, maintenance, or governance of the Companion.
At the time of publication:
- participants can access only the information associated with their own account through application-level permissions;
- access to participant information is controlled through authentication and authorization mechanisms;
- administrative access is limited to authorized project administrators responsible for maintaining and operating the Companion; and
- participants cannot access another participant's conversations, Journal entries, or personal information through the normal operation of the application.
Access controls are reviewed as part of the ongoing development of been and may be refined as the Companion evolves.
AI Infrastructure
The conversational capabilities of been are provided through a managed artificial intelligence service using secure server-side communication.
Participant messages required to generate a response are transmitted securely through the application's server infrastructure to the AI service supporting the Companion.
When a participant chooses to use the optional voice-to-text feature, microphone audio is transmitted securely through the application's server infrastructure to the AI transcription service for the purpose of generating a text transcript. Audio submitted for transcription is not stored in been's database, conversation history, or Journal. The resulting transcript is returned to the participant's composer for review and editing before the participant decides whether to send it.
The Companion does not maintain cross-conversation memory within the underlying AI model. AI requests include only the conversation history necessary for the current interaction, together with the methodological guidance and application context required to generate an appropriate response.
The behavior of the Companion is guided by the methodology of Naming Intact Perception (NIP) and the Governance Framework for been, rather than by the underlying AI model alone.
As the Companion evolves, changes to the underlying AI infrastructure may occur. Where such changes materially affect participant information, privacy practices, or the operation of the Companion, they will be reflected through updated governance documentation where appropriate.
Security Monitoring
Security is reviewed continuously throughout the development and operation of been.
At the time of publication, the Companion relies primarily on platform-managed security features together with application-level safeguards designed to support the secure operation of the service.
Security reviews may consider:
- emerging security risks;
- operational experience;
- participant feedback;
- technological developments;
- recognized security practices;
- research findings; and
- applicable legal or regulatory requirements.
As the Companion develops, additional monitoring, auditing, logging, and operational controls may be introduced where they strengthen the security, reliability, and trustworthy operation of the service.
Security monitoring is intended to support continuous improvement rather than imply that all risks can be eliminated. The objective is to identify opportunities to strengthen the Companion while remaining transparent about the current implementation.
Backup and Recovery
To support the reliability, continuity, and recovery of the Companion, been relies on the managed database and infrastructure services provided by its hosting environment.
At the time of publication, the Companion does not implement a separate backup or disaster recovery system beyond the managed services provided by the underlying platform.
Backup and recovery capabilities are therefore provided primarily through the managed infrastructure supporting the Companion. These services are intended to support operational continuity, system recovery, and the resilience of the application.
As the Companion evolves, additional backup, recovery, and business continuity measures may be introduced where they strengthen the reliability and security of the service.
The management of backup data remains subject to the commitments described throughout the Governance Framework, including the Privacy Policy and Data Retention & Deletion Policy.
Continuous Improvement
Security is reviewed as an ongoing part of the governance, development, and operation of been.
As the Companion evolves, security practices may be revised in response to:
- technological developments;
- emerging security risks;
- advances in recognized security practices;
- legal or regulatory requirements;
- operational experience;
- participant feedback;
- research findings; and
- updates to related governance documentation.
Where meaningful improvements are identified, they will be implemented in ways that strengthen participant privacy, responsible stewardship, and the trustworthy operation of the Companion while remaining proportionate to the current implementation.
Significant changes affecting the protection of participant information or the operation of the Companion will be reflected through version-controlled governance documentation where appropriate.
Security within been is understood as a process of continuous improvement rather than a fixed technical achievement.
Conclusion
Protecting participant information and maintaining the integrity of the Companion are fundamental responsibilities of been.
Security is more than protecting systems or infrastructure. It is an essential part of protecting the trust that participants place in the Companion and supporting a safe, reliable, and responsible environment for reflection.
This Security & Infrastructure Statement reflects been's commitment to implementing security measures that are proportionate to the Companion's purpose, transparent about their current implementation and limitations, and continuously reviewed as the Companion evolves.
As been develops, security practices will continue to evolve alongside advances in technology, changes in recognized security standards, participant needs, and responsible governance. Every improvement should strengthen—not weaken—the Companion's commitment to participant privacy, transparency, responsible stewardship, and trustworthy operation.