Trust center

Safe, secure, and private.

We hold OAuth tokens to your Shopify, ad accounts and email tools. We take that seriously. Here's exactly how those credentials, and the data they unlock, are protected.

How it works

Six layers, none of them optional.

Each layer is a separate control. Each card opens for the technical detail your IT lead will ask about.

Encryption

Encrypted at rest, in transit, and at the key level.

Every OAuth token and third-party credential is wrapped with AES-256-GCM before it touches the database. Connections run over TLS 1.2+ only. Keys rotate without downtime.

Tenant isolation

Your data, fenced off at the database.

Briezo runs on Postgres with row-level security policies enforcing per-store and per-user boundaries. Production refuses to run a query without an authenticated context.

Authentication

Sessions you can revoke. Passwords we never see.

Authentication runs on NextAuth with hashed credentials, secure HTTP-only cookies, and one-click session revocation. OAuth state tokens use timing-safe comparisons.

Infrastructure

Hosted on managed, hardened platforms.

Compute, Postgres, and Redis are managed by Railway with nightly backups and point-in-time recovery. The marketing site sits behind a CDN with strict headers.

Privacy

GDPR, CCPA, and Australian Privacy Act ready.

We process data as a Processor under GDPR Article 28. You can export or delete every byte we hold. We don't train AI models on your customer data. We don't sell it.

Monitoring

Errors and anomalies, watched continuously.

Sentry tracks every server error with PII scrubbing. Structured logs flow into a queryable pipeline. Failed logins, rate limits, and admin actions are recorded.

The stack, in detail

For the security-curious. Or your IT lead.

Forward this page to procurement. Everything they need is here.

Encryption at rest
AES-256-GCM (per-row token wrapping)
Encryption in transit
TLS 1.2+ enforced, HSTS preload
Database
Postgres + row-level security
Auth
NextAuth · OAuth 2.0 · bcrypt-hashed credentials
Hosting
Railway (managed Postgres, Redis, compute)
Monitoring
Sentry · structured logs · uptime checks
Backups
Nightly automated · point-in-time recovery
Headers
CSP, HSTS, X-Frame-Options DENY, nosniff
SOC 2 — readiness underway

We're building to SOC 2 Type II controls. We're not attested yet.

SOC 2 is an attestation, not a certificate — an independent auditor confirms that your security controls operated effectively over an observation window. We're designing every control on this page to that bar, but until an auditor has signed the report, we won't claim it.

Need answers sooner? Request a security review below — we'll share our current control matrix, sub-processor list, and incident response policy under NDA.

Need more detail?

Request a security review.

For prospects with security or procurement requirements, we'll share our control matrix, sub-processor list, and incident response policy under NDA. One business-day turnaround.

Responsible disclosure

Found a vulnerability?

Email security@briezo.com with a description and proof of concept. We acknowledge every report within one business day, fix verified issues in priority order, and credit you publicly if you'd like.

Security — Briezo — Briezo