Security and Compliance at Brexy
Brexy is SOC 2 Type I compliant, with ISO 27001 certification under way, and built for firms that work with confidential financial information.
Control Domains We Operate
High-level control families we operate against. The SOC 2 Type I report covers how these controls are designed and run.
- Production access reviewed
- Incidents detected and responded to
- Vulnerabilities tracked to remediation
- Identity verified before access
- Least-privilege production database access
- Access revoked at offboarding
- Restricted inbound and outbound connections
- External system connections reviewed
- Network changes assessed before rollout
- Code changes peer reviewed
- Approval required before release
- Privacy notices kept current
- Anti-malware on every device
- Full device and container encryption
- Endpoint compliance validated
- Code of business conduct
- Defined security roles and responsibilities
- Documented security ownership
Full control lists, monitoring status, and evidence sit behind our SOC 2 audit. See how the platform itself is built for confidential work.
What We Do Every Day
Certifications are a point in time. These are the practices behind them: written down, reviewed, and followed between audits. Our team will walk you through any of them.
- Incident response
- Access control and periodic access reviews
- Encryption in transit and at rest
- Vulnerability management
- Secure development lifecycle
- Privacy by design
- +32 more documented practices and procedures
Subprocessors
The third parties that process customer data on our behalf, what each one is used for, and the category it sits in. Every one is reviewed before it is brought in and again as part of our vendor reviews.
Need the Report?
Request Access.
Tell us who you are and what you need it for. Once we approve the request we email the SOC 2 Type I report.
