Is Beam HIPAA compliant?
Beam isn't a covered entity or a business associate by default, and it makes no HIPAA compliance claim. It's a local-first activity recorder for AI coding agents; whether and how it fits your HIPAA program is a decision your compliance team makes, not something this page asserts for you.
Does Beam scan for PHI in code or logs?
No. Beam redacts known credential formats — API keys, tokens, auth headers — before writing an event. It does not detect or redact patient data. Review any export before it leaves your team.
Can it stop an agent from touching a clinical system?
Not in v1. Beam observes and alerts only — it emits no allow/deny response and can't block a command mid-flight.
Where does the activity data get stored?
Locally, on the machine that generated it. The collector binds to loopback only, and nothing leaves until someone runs an export.