Security & compliance

Screen at the door. Account for everyone. Keep the data yours.

BeckonDesk treats the gate as a control point, not a guestbook. Names are checked before entry, people are accounted for during an evacuation, and every tenant’s records stay walled off from every other’s.

Denied-party screening

Banned, sanctioned, or barred, caught before the badge prints.

Every sign-in is matched against your own watchlist and the public OFAC, UN, and EU consolidated sanctions lists, 53,067 records, refreshed and fuzzy-matched so a near-spelling still trips. A hit holds the visitor and alerts your team.

  • Three public lists, no add-on. OFAC SDN, UN Security Council, and the EU consolidated list, kept current.
  • Your own watchlist. Ban or flag a person once; every gate enforces it on arrival.
  • Fuzzy matching catches transliterations and misspellings, with a confidence score on each hit.
Screen a name
•••••• •••••••
● Block, denied-party match
OFAC SDNDenied-party match93%
EU ConsolidatedDenied-party match93%
Lab BD. MercerMissing
Loading BayJ. OkaforUnaccounted
ReceptionA. OkaforSafe

Evacuation & mustering

A roll call that knows where people were.

Start an evacuation and everyone on site lands on one live board, each with the last zone their badge was seen in. Staff mark people safe from any phone; the count syncs instantly and exports as an incident report.

  • Last-known zone from your access events, search the right place first.
  • Collaborative roll call across devices, with a timer and a shareable report.

Active security

For when the threat is already inside

Silent duress

A code reception can enter under coercion locks the site down and alerts security, while the screen carries on as if nothing happened.

Site lockdown

Broadcast a lockdown to your door controller in one action, and release it just as quickly when the all-clear comes.

Anomaly watch

Overstays, visitors who never checked out, odd-hours arrivals, and repeated denied attempts surface to security on their own.

Data & tenancy

Your visitors’ data stays yours.

BeckonDesk is multi-tenant by design. Each organization’s records are isolated at the database, so one customer can never read another’s, even when the same visitor is invited by both. And with no facial recognition, there’s no biometric data to leak in the first place.

Ask about our data model

Isolation by default

A tenant filter is enforced on every query, cross-tenant reads are impossible, not just discouraged.

No biometric data

BeckonDesk doesn’t use facial recognition or store biometric identifiers, nothing to breach, and you stay clear of US state biometric-privacy laws.

Retention controls

Set how long visit records live; old data is purged on your schedule, not ours.

Encrypted secrets & audit

Integration secrets are encrypted at rest; the audit log is append-only.

Platform & infrastructure

Your data is protected on Microsoft Azure

BeckonDesk runs entirely on Microsoft Azure. Azure holds ISO 27001, SOC 2, and other independent audit reports for the platform layer. Our own product-level security controls are documented below.

Encrypted end to end

Data is encrypted in transit with TLS and at rest with AES-256. Your information is never transmitted or stored in the clear.

Secure sign-in

Administrator access is protected by Microsoft Entra identity with multi-factor authentication, and role-based permissions keep staff to only what they need.

Locked down by default

Our database is not reachable from the public internet, and every credential lives in Azure Key Vault, never in code, with access limited to our services over encrypted connections.

Backed up & monitored

Your data is backed up automatically and can be restored if ever needed. The platform is monitored around the clock, so issues are caught and handled fast.

Private, safe AI

AI-assisted screening runs inside our own Azure environment. Your data is never shared with third parties or used to train AI models.

Privacy by design

We collect only what’s needed to manage access, don’t scan or store government-ID documents, and never send visitor passes by email or text. Aligned with UK GDPR and the Data Protection Act.

Identity

Sign-in your IT team will actually approve

SSO

SAML or OpenID Connect against your own identity provider, per tenant.

Directory sync & SCIM

Provision and deprovision staff automatically from Entra and other IdPs.

Invitation-only access

Joining a tenant is by invite only, no self-service back door into another company’s site.

Run a screening and an evacuation, live.

We’ll screen a real sanctioned name and walk a full muster on a call.