Detected country: US
logo
Open AppStatusSubmit Ticket
GuideAPI References
‌
‌
‌
logo

Powered by

  • Home
  • Security & Compliance
  • Privacy & Data
  • Data Security

Data Security

2min read

Share

Data storages

All data storages are not accessible to the outside/internet and are protected within our Virtual Private Network. Access to data stores with customer data is limited to systems that require this access. All data is encrypted while in transport by using enhanced encryption mechanisms like SSL etc.

All our connections are encrypted via Transport Layer Security (TLS) with version v1.2. We have implemented encryption of all data in rest.

All production environments are separated from testing environments.

Compliant with General Data Protection Regulation (GDPR) for EU region customers We are compliant with the EU General Data Protection Regulation (GDPR) which should help to protect personal data and give individual users more rights and control of their personal data. We are a processor in terms of GDPR. We are storing some personal data (Personally Identifiable Information (PII)) in the form of name and email of users, browser information, operating system, screen sizes, URL, location / IP address (only in specific cases) and screenshots of browser content.

All customer data is stored in the United States (US) by default. Enterprise customers can request EU data residency — please contact hello@brainfi.sh to arrange this for your account.

If we have a sub-processor that is not processing in the agreed region, we ensure through an EU-SCC and a DPA that the sub-processor has an adequate security standard.

For more information and our Data Privacy Agreement, please read our GDPR page.

PII-protection

You can protect sensitive data in all subscription plans by using our PII-protection feature to black-out confidential information from your website or web application before a screenshot is taken.

Privacy policy

We demonstrate our company's commitment to privacy. Please read our privacy statement.

Data segregation and data access

All accounts and data of each customer are separated by unique IDs. These can only be accessed by the customers' team members. Our customer success team will only access a customer's account after a clear request by the customer.

Backups & disaster recovery

All data is backed up daily, secured by encryption, and stored for 30 days.

Deleted data is not removed from backups to allow for the possibility to recover in case of deletion. All previous backup data is removed after 90 days. We are reviewing our backups at least annually and simulate a full backup recovery**.**

Security Logs ‍Our system is storing logs to reproduce any faults or track security breaches. No personal data is stored within our logs. Activity logs are kept for 90 days.

Authentication & Login

We do not save passwords on our system. Instead, users log in with a one-time code sent to their email, or via Google OAuth. To secure access to our application, we use sessions that expire after a specific time of inactivity or unauthorized access.

SSO/SAML support is currently in development and will be available for enterprise customers in a future release.

Permissions and roles ‍ Brainfish offers different roles with different permissions within our system. Team owners have all access and managing permissions, while team members can manage all items within a project. Users are allowed to submit feedback and send in messages.

Encryption

Secure transport via HTTPS

Our system enforces traffic via HTTPS (port 443). Requests to web resources and access to our REST API can only be obtained via SSL.

Encryption at transport and at rest.

Our platform uses industry-standard encryption algorithms for encrypting your data in transport, as well as at rest.

What security certifications do you hold?

Brainfish holds ISO 27001:2022 and SOC 2 Type II certifications to comply with enterprise-grade global security and compliance requirements. We are also GDPR compliant.For education customers with questions about FERPA obligations, see our FERPA Compliance article.

Share