Bentley Trust Center: Compliance

Read Bentley’s statement regarding the Privacy Shield ruling.

Bentley’s cloud offerings are designed with operational best practices and robust controls to deliver compliance that you can rely on. Bentley partners with leading cloud service providers so that you can benefit from data centers and network architecture built to satisfy the most stringent industry standards and country-specific requirements. The following compliance standards and information attests to the security and dependability of Bentley’s named cloud services offerings.

Bentley Cloud Services Status

Bentley has an array of cloud services and sites that can be monitored by users around the world at any time. The Bentley Cloud Services Status Dashboard lists available services and their current status. This capability allows users to check for service availability prior to contacting technical support.

ISO 27001
Bentley Managed Services

The systems and processes that support Bentley Managed Services are ISO/IEC 27001:2013 certified. ISO/IEC 27001:2013 is one of the most widely recognized information security standards. Compliance with ISO/IEC 27001:2013 is certified by A-LIGN, an ANAB accredited ISO 27001 certification body. View the Bentley Managed Services ISO/IEC 27001:2013 certificate and the current ISO/IEC 27001:2013 Statement of Applicability

Products in scope of Bentley’s ISO 27001 certification for Managed Services include AssetWise (eB Insight V8i), ConstructSim Work Package Server, and ProjectWise.

ISO 27001:2013 surveillance audit completed: September 13, 2019. A-LIGN conducted a full audit from the company’s corporate facility in Exton, Pennsylvania. A-LIGN conducted on-site audit procedures including interviews of key personnel, observation of processes and controls, review of documentation, and analysis of documentation of audit findings during the site visits.

Cloud Security Alliance 

Bentley Systems is a Cloud Security Alliance (CSA) Security, Trust & Assurance Registry (STAR) registrant. Bentley has completed the Consensus Assessments Initiative Questionnaire (CAIQ) for multiple products and services to provide answers to nearly 300 questions a cloud user or a cloud security auditor may wish to ask of a cloud provider. The CSA STAR is a publicly accessible registry that documents the security controls provided by various cloud computing offerings. The registry helps users assess the security of the cloud providers they currently use or are considering contracting with. View the CAIQ's for Bentley Systems.

Government Cloud

AssetWise CONNECT Edition
Bentley Connected Data Environment (CDE)
Bentley Success Plans
iTwin Services
OpenCities Planner
ProjectWise CONNECT Edition
Reality Modeling Cloud Services
SYNCHRO Workgroup Project
Government Cloud (G-Cloud) is a UK initiative to promote government-wide adoption of cloud computing. The Crown Commercial Service (an agency that works to improve commercial and procurement activity by the government) awarded Bentley Systems International Limited G-Cloud 11 status for the following cloud software offerings and associated implementation and Success Plan services: AssetWise CONNECT Edition, Bentley Connected Data Environment (CDE), Bentley Success Plans, ComplyPro, iTwin Services, OpenCities Planner, ProjectWise CONNECT Edition, Reality Modeling Cloud Services, and SYNCHRO Workgroup Project. 

Service Organization Control (SOC)
Bentley CONNECT Cloud Services

Bentley CONNECT Cloud Services are designed to keep user data secure with enterprise grade security, which is demonstrated with the granting of a SOC2 Type I and a Type II report by a certified AICPA auditing body. Bentley CONNECT Cloud Services are audited annually against the SOC reporting framework by qualified independent computer-security auditors. The scope of audit for Bentley CONNECT Cloud Services covers controls applicable to in-scope trust principles for each service. In general, the availability of these reports is restricted to customers who have signed non-disclosure agreements with Bentley.  

To request a SOC 2 report, contact your Account Manager. If you do not currently have a Bentley account and would like to request a SOC 2 report, contact us.

EU General Data Protection Regulation

On May 25, 2018, the European Union’s General Data Protection Regulation (GDPR) went into effect.  The GDPR imposes new obligations that will impact companies and other organizations around the world that offer goods and services to European Union residents or that collect and process data tied to EU residents.

Bentley believes that the GDPR is an important step to strengthen and harmonize data protection of EU residents’ personal data. Learn more about Bentley’s Compliance with the GDPR. Review Bentley’s list of subprocessors.

Report a security concern

Bentley’s security team investigates all reports of security vulnerabilities affecting Bentley products and services. If you have a security concern or are a security researcher and believe you have found a security vulnerability involving Bentley products and services, please use the web form to contact us or send us an email at so that we can protect the integrity of our products and services. Use this PGP key when sending email.