Trust Center

Security and Compliance at Brexy

Brexy is SOC 2 Type I compliant, with ISO 27001 certification under way, and built for firms that work with confidential financial information.

ISO 27001In progressInternational standard for an information security management system. Confirms how Brexy identifies risk, protects data, and continuously improves security operations.Available once certification completes

Control Domains We Operate

High-level control families we operate against. The SOC 2 Type I report covers how these controls are designed and run.

Product security
  • Production access reviewed
  • Incidents detected and responded to
  • Vulnerabilities tracked to remediation
Data security
  • Identity verified before access
  • Least-privilege production database access
  • Access revoked at offboarding
Network security
  • Restricted inbound and outbound connections
  • External system connections reviewed
  • Network changes assessed before rollout
Application security
  • Code changes peer reviewed
  • Approval required before release
  • Privacy notices kept current
Endpoint security
  • Anti-malware on every device
  • Full device and container encryption
  • Endpoint compliance validated
Corporate security
  • Code of business conduct
  • Defined security roles and responsibilities
  • Documented security ownership

Full control lists, monitoring status, and evidence sit behind our SOC 2 audit. See how the platform itself is built for confidential work.

What We Do Every Day

Certifications are a point in time. These are the practices behind them: written down, reviewed, and followed between audits. Our team will walk you through any of them.

  • Incident response
  • Access control and periodic access reviews
  • Encryption in transit and at rest
  • Vulnerability management
  • Secure development lifecycle
  • Privacy by design
  • +32 more documented practices and procedures

Subprocessors

The third parties that process customer data on our behalf, what each one is used for, and the category it sits in. Every one is reviewed before it is brought in and again as part of our vendor reviews.

AWS
IT infrastructure
Hosts the Brexy platform and stores customer documents and deal data.
Google Workspace
Identity providers
Company email, files, and the identity our team signs in with.
GitHub
Version control systems
Holds the Brexy source code and the review history behind every release.
Fireworks AI
AI model providers
Serves the language models behind Brexy's AI features.
Sprinto
Compliance automation
Monitors our controls continuously and collects the evidence behind our SOC 2 report and ISO 27001 certification.

Need the Report?
Request Access.

Tell us who you are and what you need it for. Once we approve the request we email the SOC 2 Type I report.