Trust & Security

Security and trust, engineered in from day one

The systems we build run in regulated, high-stakes environments — so security, privacy and compliance aren't a checklist at the end. They're designed into the architecture, enforced in code, and evidenced by default.

Encryption everywhere Least-privilege access Audit-ready by default
Certifications & compliance

Mapped to the standards your auditors answer to

We design and operate engagements around the security and compliance frameworks our clients are held to. For details of the certifications, attestations and audit documentation that apply to your review, please request them via the contact options on this page.

Security practices

How we keep systems — and your data — safe

The same engineering discipline we apply to building platforms governs how we secure and operate them.

Encryption

Data encrypted in transit with TLS 1.2+ and at rest with AES-256. Keys managed in a dedicated KMS with rotation and strict access policies.

TLS 1.2+AES-256KMS

Access control & SSO

Single sign-on via SAML/OIDC, enforced MFA and role-based, least-privilege access. Every grant is reviewed and time-bound.

SSOMFARBAC

Secure SDLC

Security woven into delivery: code review, SAST/DAST, dependency scanning and signed builds gate every release.

SAST/DASTCode reviewSigned builds

Vulnerability management

Continuous scanning, prioritized remediation SLAs and routine third-party penetration tests with tracked findings.

ScanningPen testingPatch SLAs

Monitoring & incident response

Centralized logging, anomaly detection and a documented incident response plan with defined severities and on-call rotations.

SIEM24/7Runbooks

Business continuity & DR

Automated backups, tested restore procedures and multi-region resilience targets so critical systems recover fast.

BackupsRPO/RTOMulti-region
Data handling & privacy

Clear about what we collect and why

How we process, store and protect data is documented in plain language. The full terms live in our policies.

Privacy Policy

What personal data we collect, the lawful basis for processing it, how long we keep it, and the rights you can exercise over it.

Read the Privacy Policy

Cookie Policy

The cookies and similar technologies we use, what each category does, and how to manage your consent at any time.

Read the Cookie Policy
Subprocessors & data residency

Where your data lives, and who touches it

We maintain a current list of the subprocessors we rely on and the regions data is processed in, and hosting region can be scoped per engagement. Please request our up-to-date subprocessor list and data-residency details for your review.

Responsible disclosure

Found a vulnerability? Tell us.

We welcome reports from security researchers and treat them seriously. Report a suspected vulnerability in good faith and we'll work with you to verify and resolve it — and we won't pursue action against researchers who follow this policy.

1

Report privately

Email security@braindoos.com with steps to reproduce, impact and any proof-of-concept. Please don't disclose publicly before we've responded.

2

We acknowledge & triage

We aim to acknowledge within two business days, validate the report and assign a severity and owner.

3

Fix & coordinate

We remediate, keep you updated on progress, and coordinate timing on any public acknowledgement of your finding.

Due diligence

Need our security documentation?

Request our security overview, latest reports, a completed questionnaire, or a mutual NDA. Our team will route you to the right materials for your review.

NDA on request Reports under review Response within 2 business days