Security controls you can verify.
Brolly holds the records your organization may one day defend in court. That responsibility shapes how the platform is built, audited and operated — and everything on this page is verifiable.
Independently certified, not self-declared.
Certified
ISO/IEC 27001:2022
Certified information security management system — the international information-security management standard, audited independently.
✓Certificate available under NDA
Registered
CSA STAR
Registered with the Cloud Security Alliance's Security, Trust & Assurance Registry.
✓Public registry listing
Aligned
NIST SP 800-53
Controls aligned to NIST SP 800-53, the framework many US state and local procurement standards reference.
✓Control mapping on requestBuilt for the rules your records live under.
| Your obligation | What it demands | How Brolly answers |
|---|---|---|
| FOIA & state public records laws | Produce responsive, unaltered records on request — including edited and deleted content | Near-real-time capture, revision history, response-ready exports with digital checksums |
| FINRA 10-06 / 11-39 & SEC 17a-4 | Retain business communications on social media as records | Records retained until you authorize disposal, with audit trails |
| HIPAA & FERPA contexts | Handle regulated communities' communications with care and accountability | Role-based access, moderation with preserved records, audit logs |
| Records retention schedules | Keep records for mandated periods, then disposition defensibly | Records retained; disposition on your instruction |
The controls, in plain English.
Encryption everywhere
AES-256 at rest, TLS 1.3+ in transit. Records carry audit logs; exports carry digital checksums.
Access control
Multi-factor authentication and role-based access — records staff, communications and counsel each see what their role requires.
Tested by attackers
Independent penetration testing and a secure development lifecycle guided by OWASP practices.
Reliable by design
99.9% uptime SLA on AWS across multiple availability zones, with monitored backups.
Signed in to Brolly — MFA verified
203.0.113.24Willowdale, USSuccessConnected Facebook Page — Willowdale County
203.0.113.24Willowdale, USSuccessExported archive — Q1 records package (PDF)
203.0.113.61Willowdale, USSuccessChanged M. Okafor's role from Member to Owner
203.0.113.24Willowdale, USSuccessIncorrect password — 3 attempts
198.51.100.7UnknownFailedYour records are yours.
Brolly never sells customer data and never shares it for third-party advertising. Approved subprocessors, such as our hosting providers, process it only to provide and secure the service under contractual safeguards. Privacy practices are designed to meet CCPA/CPRA and GDPR expectations, with data deletion honored per our published process.
What your security team will ask.
Is Brolly ISO 27001 certified?
Which frameworks do Brolly’s controls align to?
How is our data protected?
Do you sell or share our data?
What uptime do you commit to?
Can our security team review your controls?
Send us the questionnaire. We like them.
Certification documents, pen-test summaries and completed security reviews are available under NDA.