Trust & Security

Security you can actually read.

BrytIO holds the data you run your business on. Here is exactly how we protect it: stated plainly, with nothing claimed that isn’t true yet. What’s in progress is marked as such.

Where we stand on certifications. BrytIO does not hold a SOC 2 or ISO 27001 certification today, and we won’t imply otherwise. We’re a focused team building toward one; see the roadmap below. In the meantime, the controls here are real, in place, and verifiable.

Infrastructure & network

Where BrytIO runs and how traffic reaches it.

Encryption in transitLive
All connections are served over TLS, with certificates issued and renewed automatically. Plain HTTP is redirected to HTTPS.
Edge protectionLive
Traffic passes through Cloudflare for TLS termination, DDoS mitigation, and edge filtering before it reaches the application.
US-based hostingLive
Application and database run on DigitalOcean infrastructure in the United States.
Isolated network surfaceLive
The application container is not published to the host; only the reverse proxy is internet-facing.

Application security

How the product keeps one customer's data separate from another's.

Strict tenant isolationLive
Every record is scoped to your workspace, and every query is filtered by organization. This is enforced per-query and independently audited.
AuthenticationLive
Sign-in is handled by Clerk, a dedicated identity provider. BrytIO never stores your account password.
Two-factor authenticationLive
Time-based one-time-password (TOTP) 2FA is available on every account, and workspace owners can require it for all members.
Role-based accessLive
Owner, admin, and member roles gate who can see financial data, manage the team, and change workspace settings.
Input validationLive
External input (API bodies, form submissions, connector responses) is schema-validated at the boundary.
Signed webhooks & rate limitsLive
Inbound webhooks are signature-verified, and public endpoints are rate-limited per client.

Data protection

How your data is protected at rest and in our custody.

Credentials encrypted at restLive
Integration tokens and 2FA secrets are encrypted at rest with AES-256-GCM, under a key held outside the database.
Card data never touches BrytIOLive
Card payments are handled entirely by Stripe. No card number, expiry, or CVV is ever stored in, or transmitted through, BrytIO.
No special-category dataLive
BrytIO has no fields for health, biometric, racial, or other special-category data. It is a business-contact and operations system by design.
Encrypted off-site backupsLive
The database is backed up nightly, encrypted before it leaves the host, and stored off-site. Restores are periodically tested end-to-end.

Monitoring & change management

How we catch problems and how changes reach production.

Error monitoringLive
Application errors are captured and alerted on. Request bodies, cookies, and auth headers are scrubbed before anything leaves our systems; session replay is disabled.
Dependency scanningLive
Dependencies are continuously scanned for known vulnerabilities. Critical advisories are patched promptly.
Reviewed, gated releasesLive
Changes pass automated type-checking and build verification before they can ship. No change reaches production untested.
Breach notificationLive
If we become aware of a security incident affecting your data, we notify you without undue delay with what we know and what we're doing.

Privacy & your data rights

You own your data. Here is what that means in practice.

You control, we processLive
For the customer data in your workspace, you are the controller and BrytIO is the processor. We act only on your instructions.
Data Processing AgreementLive
A signed DPA, with our subprocessor list as an annex, is available on request for customers who need one.
Export anytimeLive
You can export your data from the product whenever you want, without asking us.
Deletion on closeLive
Delete a record and it's removed from active systems; close your workspace and we delete your data from production, then from backups on their rotation.

On the roadmap

Committed, not yet complete. This page updates when each ships.

Database encryption at restPlanned
Migrating the database to managed Postgres, which adds full at-rest encryption and automated point-in-time backups. Today, credentials and tokens are encrypted at rest; the full database is not yet.
Independent penetration testPlanned
A third-party penetration test, with a summary report available to customers under NDA.
SOC 2 Type IIPlanned
Evaluating a formal SOC 2 Type II program. We'd rather ship it than claim it; this page will say so the day it's real.

Subprocessors

The third parties that help us run the service, each bound by contract to protect your data. Opt-in integrations only process data if you connect them. The full list, with roles and notice terms, is in our Data & Security Policy.

SubprocessorRole
DigitalOceanHosting, compute, and database
CloudflareCDN, edge security, and file storage
ClerkAuthentication and identity
StripeBilling and card payments
Anthropic (Claude)AI assistant features
ResendEmail delivery
SentryError monitoring
MicrosoftMail & calendar sync (opt-in)
Intuit (QuickBooks)Accounting sync (opt-in)
ShippoShipping & tracking (opt-in)

Security questions, or found something?

Security and compliance questions, questionnaires, and DPA requests: privacy@brytio.com. If you believe you’ve found a vulnerability, email us with the details and steps to reproduce, and we’ll acknowledge and work with you on it.