Trust & Security Center

Security controls you can verify.

Brolly holds the records your organization may one day defend in court. That responsibility shapes how the platform is built, audited and operated — and everything on this page is verifiable.

Certifications

Independently certified, not self-declared.

ISO/IEC 27001:2022 certification badge — SouthPac Certifications Certified

ISO/IEC 27001:2022

Certified information security management system — the international information-security management standard, audited independently.

Certificate available under NDA
CSA STAR Level One Self-Assessment badge Registered

CSA STAR

Registered with the Cloud Security Alliance's Security, Trust & Assurance Registry.

Public registry listing
NIST SP 800-53 alignment badge Aligned

NIST SP 800-53

Controls aligned to NIST SP 800-53, the framework many US state and local procurement standards reference.

Control mapping on request
Compliance alignment

Built for the rules your records live under.

Your obligationWhat it demandsHow Brolly answers
FOIA & state public records lawsProduce responsive, unaltered records on request — including edited and deleted contentNear-real-time capture, revision history, response-ready exports with digital checksums
FINRA 10-06 / 11-39 & SEC 17a-4Retain business communications on social media as recordsRecords retained until you authorize disposal, with audit trails
HIPAA & FERPA contextsHandle regulated communities' communications with care and accountabilityRole-based access, moderation with preserved records, audit logs
Records retention schedulesKeep records for mandated periods, then disposition defensiblyRecords retained; disposition on your instruction
Platform security

The controls, in plain English.

Encryption everywhere

AES-256 at rest, TLS 1.3+ in transit. Records carry audit logs; exports carry digital checksums.

Access control

Multi-factor authentication and role-based access — records staff, communications and counsel each see what their role requires.

Tested by attackers

Independent penetration testing and a secure development lifecycle guided by OWASP practices.

Reliable by design

99.9% uptime SLA on AWS across multiple availability zones, with monitored backups.

Privacy

Your records are yours.

Brolly never sells customer data and never shares it for third-party advertising. Approved subprocessors, such as our hosting providers, process it only to provide and secure the service under contractual safeguards. Privacy practices are designed to meet CCPA/CPRA and GDPR expectations, with data deletion honored per our published process.

CCPA / CPRAGDPR-ready practicesNo data selling — everDocumented deletion processAudit trails on every action
Security review

What your security team will ask.

Is Brolly ISO 27001 certified?
Yes — Brolly is certified against ISO/IEC 27001:2022, the international standard for information security management, and registered with the Cloud Security Alliance STAR program.
Which frameworks do Brolly’s controls align to?
Brolly’s controls are aligned to NIST SP 800-53, which many state and local procurement frameworks reference. Certification documents and completed security reviews are available under NDA for your assessment.
How is our data protected?
Records are encrypted with AES-256 at rest and TLS 1.3+ in transit, with digital checksums on every export, and protected by multi-factor authentication, role-based access controls and audit trails covering sign-ins, exports, moderation actions and role changes. Records are retained until your organization authorizes disposal. The platform runs on AWS across multiple availability zones.
Do you sell or share our data?
No. Brolly never sells customer data and never shares it for third-party advertising. Approved subprocessors, such as our hosting providers, process it only to provide and secure the service under contractual safeguards. Privacy practices are designed to meet CCPA/CPRA and GDPR expectations.
What uptime do you commit to?
A 99.9% uptime service level, backed by service credits, on redundant AWS infrastructure.
Can our security team review your controls?
Yes — certification documents, penetration-test summaries and completed security questionnaires are available under NDA. Reach out through the contact page and we’ll route you to the right people.

Send us the questionnaire. We like them.

Certification documents, pen-test summaries and completed security reviews are available under NDA.