1. Technical and Organizational Measures
- Encryption in transit (TLS 1.2+) and at rest for databases and file storage.
- Strict tenant isolation at the organization boundary, enforced in every data-access path.
- Role-based access control, passkeys (WebAuthn) and two-factor authentication.
- Hash-chained, append-only audit logs for sensitive mutations.
- Immutable posted accounting entries (corrections via reversal only).
- Automated dependency scanning and security patching.
- Daily backups with a 35-day rolling window and restoration testing.
- Principle of least privilege for production access; all access logged.
2. Compliance Orientation
We align our practices with GDPR art. 32, and monitor obligations under the NIS2 framework as transposed in Romania (GEO 155/2024). Sub-processors are selected with EU hosting and recognized certifications (e.g., ISO 27001, SOC 2) where available.
3. Responsible Disclosure
If you believe you have found a vulnerability, email security@brivio.ro with reproduction details. Please do not access other users' data, degrade the service, or publicly disclose before we remediate. We acknowledge within 2 business days, keep you informed, and do not pursue legal action for good-faith research within these rules.
- In scope: brivio.ro and its subdomains, the public APIs.
- Out of scope: denial of service, social engineering, physical attacks, third-party services.
- Safe harbor applies only to good-faith testing respecting these boundaries.
4. Incident Response
We maintain an incident response process covering triage, containment, forensics, and notification. Personal data breaches are notified per GDPR art. 33/34 and per the DPA (customer notice within 48 hours of awareness for affected Customer Data).