generated: '2026-07-19' method: searched source: https://www.imbee.io/data-governance summary: >- imBee publishes a data-governance and security posture centered on an ISO/IEC 27001 certification, message-level sensitive-data masking, role-based access control, two-factor authentication, force-logout, and enforced data-retention policies. The platform is hosted on AWS. No public OpenAPI is available (the developer console at chat.imbee.io/doc is login-gated), so cross-cutting API standards below are asserted only where the provider documents them; unknowns are recorded as conforms:false rather than assumed. standards: - id: iso-27001 conforms: true evidence: >- Provider states "certified with ISO 27001" on the data-governance page and in the published llms.txt ("ISO 27001-certified security"). source: https://www.imbee.io/data-governance - id: gdpr conforms: false evidence: Not claimed on the data-governance page. - id: soc2 conforms: false evidence: Not claimed on the data-governance page. - id: pci-dss conforms: false evidence: Not claimed. - id: hipaa conforms: false evidence: Not claimed (healthcare vertical is served but no HIPAA certification is stated). - id: oauth2 conforms: false evidence: No public OpenAPI/securitySchemes to confirm; API console is login-gated. - id: rfc9457-problem-details conforms: false evidence: No public OpenAPI to confirm error format. compliance_program: certifications: - ISO/IEC 27001 hosting: Amazon Web Services (AWS) regulatory_guidance: - Hong Kong SFC (Securities and Futures Commission) - HKSA (Hong Kong Securities Association) data_governance_controls: - message-level sensitive-data masking - role-based access control / team hierarchy - two-factor authentication (2FA) - force log out - data retention policies - audit logs of agent actions