Security in Software Development
Code Reviewing
The Brainfish development team uses a modern software development approach to ensure the development of secure, reliable, fast and flexible software.
We are using a revision control system (git). Any changes to our source code base go through a suite of automated tests and are reviewed & approved by authorised persons in a code review. When code changes pass the automated testing system and manual reviews, the changes are deployed to a staging server. In this staging server, Brainfish employees are able to test changes before an eventual push to production servers and our customer base.
We also add a specific security review for particularly sensitive changes and features. Brainfish engineers can pick critical updates and push them immediately to production servers.
In addition to a list where all access control changes are published, we have a suite of automated unit tests that checks whether access control rules are written correctly and enforced as expected. We also work with third-party security professionals to protect your data. Annual penetration testing is conducted by AstraSecurity, and our application and cloud environments are continuously scanned by them throughout the year.
Additional Security Measures
Incident response
In case of a security or performance incident, customers are encouraged to subscribe to our status page at status.brainfi.sh, through which an email notification will be sent when an incident occurs. A resolution report with full detail will be shared with impacted customers.
Security training
Security is only effective if it is practiced regularly. That's why our team and employees have to conduct security training outlined in our policies regularly after joining.
Payment processing & PCI compliance
All credit card payments paid to Brainfish are processed by our payment partner Stripe. Find more information about their security protection and PCI certification on their Security page. We have no access to your credit card information.
Requests regarding security
If you have questions regarding the security of Brainfish, please contact our security team via security@brainfi.sh
