Brivio
Loading…

Your data, your call

Choose what we may store on your device

  • No analytics or marketing script runs before you decide — not even in the background.
  • Each category is a separate decision. Accepting one does not accept the rest.
  • You can change or withdraw your choice at any time, in one click.

Choose what we may store on your device

We use essential cookies to run the platform and, only with your consent, functional, analytics or marketing cookies. Nothing non-essential loads without your consent. Details in our Cookie Policy

Strictly necessary

Authentication, security (CSRF), language and theme preference, remembering your consent choice. Always active.

Functional

Remember additional preferences (e.g. display settings) for an improved experience.

Analytics

Help us understand how the site is used (aggregated statistics). Not loaded without your consent.

Marketing

Used for personalized advertising by third parties. Not loaded without your consent.

Skip to main content
Brivio
  • Pricing
Sign InGet Started
Brivio

The complete platform for managing your business. Projects, invoices, contracts and documents in one place.

ANAF e-FacturaeIDASGDPREU hosting

Product

  • Features
  • Pricing
  • Integrations
  • Apps
  • Changelog
  • Brivio AI

Solutions

  • For freelancers & sole traders
  • For small businesses & SRLs
  • For accountants & firms
  • For online stores
  • For construction firms
  • Company setup in Romania
  • For accounting firms
  • Alternatives to other software
  • Integrations

Free tools

  • VAT calculator
  • Salary calculator
  • PFA tax calculator
  • Invoice template
  • VAT number check
  • Company directory
  • Company rankings
  • Legislation

Resources

  • Documentation
  • Blog
  • Fiscal news
  • Community
  • Help center
  • API
  • Apps
  • Changelog
  • Status
  • Security & Trust
  • Affiliate program

Company

  • About us
  • Careers
  • Contact
  • For accounting firms

Legal

  • Legal center
  • Privacy
  • Terms
  • Cookies
  • GDPR
  • Sub-processors
  • Consumer disputes (ANPC/SAL)
  • Complaints
  • AI transparency
  • Security
  • Company details
  • Affiliate program terms
  • Security & Trust
Brivio

© 2026 Brivio. All rights reserved.

Interactive Media Solutions S.R.L. · CUI 37237457 · Str. 23 August nr. 1B, Et. 1, Ap. 8, Târgu Jiu, jud. Gorj, România · J18/241/2017 · +40 755 667 632

ANPC — Alternative Dispute Resolution (SAL)ANPC — National Authority for Consumer Protection
TwitterLinkedInGitHub

Brivio is operated by Interactive Media Solutions S.R.L. • CUI 37237457 • Reg. Com. J18/241/2017 • Registered office: Str. 23 August nr. 1B, Târgu Jiu, Gorj, Romania • Contact: legal@brivio.ro • Data supervisory authority: ANSPDCP (dataprotection.ro) • Consumer protection: ANPC (anpc.ro)

Trust Center

How we protect our customers' data and how you can verify it at any time.

Data hosted exclusively in the EU

All data at rest is stored in Google Cloud EU. Tenants can opt into the ro_sovereign regime, which forbids any external processor (only ANAF + BNR remain connected).

Envelope encryption with a rotatable KEK

Integration tokens and sensitive payloads are encrypted with AES-256-GCM using per-payload data keys, wrapped with a multi-version rotatable KEK. See ADR-0009 and ADR-0011.

Append-only, hash-chained audit log

Every privileged action produces a chained, signed audit entry. Integrity verification runs automatically via the audit-verify cron.

DSR within 30 days maximum

GDPR Art. 15-22 requests (access, rectification, erasure, portability, restriction, objection) are tracked with a legal deadline of 30 days. The Art. 20 export produces a ZIP with all of the tenant's data.

Public ADRs for architecture decisions

All decisions impacting privacy are documented as ADRs in the repo, for auditors and enterprise customers.

Sub-processors

The list is versioned in a public repo and is updated at least 30 days before any material change. Tenants are notified by email at their DPO contact address.

ProcessorRoleLocationDataSafeguards
Stripe Payments Europe Ltd.Payments / subscriptionsIreland (EU)name, email, card billing (tokenized)DPA + EU SCC 2021/914
Salt Edge LimitedOpen banking (PSD2 AIS) — optionalLithuania (EU)IBAN, bank transactions, balanceDPA + EU SCC; enabled only on explicit consent
Cloudflare, Inc.CDN + DDoS protectionUSA / Anycast EUIP, user-agent, request metadataEU SCC 2021/914 + EU-US DPF
OpenAI Ireland Ltd.AI Copilot assistant + OCR — optionalIreland (EU)text prompts, document images (when the user uploads)DPA + EU SCC; zero-retention via Enterprise endpoint; enabled only if the tenant has AI_PROVIDER=openai
Google Cloud EMEA Ltd.Infrastructure hosting (compute + storage) — productionEU (multi-region)all data at restDPA + EU SCC; envelope encryption with a dedicated KMS

Resilience and verification

We answer the questions every practice asks in due diligence: how often we back data up, how long a restore takes, and what security auditing exists. We publish only figures we can evidence from our infrastructure.

Backups, RPO and RTO

The database runs on Cloud SQL in a REGIONAL configuration (synchronous standby in a second zone), served from europe-central2 + europe-west1. Automated daily backup at 03:00 UTC, 14 copies retained, stored in the EU multi-region — not in the region that just failed. Point-in-time recovery is enabled, with 7 days of transaction logs.

  • RPO target (backup only): at most 24h
  • RPO target (with PITR): on the order of minutes
  • RTO target (database restore): under 10m
  • RTO target (full platform): under 1h

Last verified: 2026-09-08

Backup verification

An automated job runs daily at 06:15 UTC and checks the Cloud SQL API for a successfully completed backup. It alerts if the newest successful copy is older than 26 hours, if no successful copy exists, or if the check itself fails three times in a row.

  • Full restore drill: last run 2026-07-29, quarterly cadence. The restore was performed onto a fresh instance from a real production backup.
  • Automated restore verification: scheduled, first run pending. Until it reports for the first time, the only evidence we claim is the manual drill above.

Last verified: 2026-09-08

Penetration testing and vulnerability reporting

We have not yet had a penetration test performed by an independent third party, and we claim nothing else. What runs today is automated security scanning in CI, weekly: gitleaks, Semgrep, pnpm audit, plus container image scanning (ADR-0026).

  • The first independent pentest is planned before general availability; a summary of the report will be published on this page.
  • Coordinated vulnerability disclosure at security@brivio.ro, per /.well-known/security.txt. We do not run a bug bounty programme.

Last verified: 2026-09-08

Per-organization isolation

The organization is the tenant boundary in Brivio. Below is how that is enforced technically, where it is checked automatically, and what that check does not cover.

The boundary is the organization

Every business-data table carries an organization column, and queries go through the org-scoped helper rather than direct database access. The decisions are documented publicly in ADR-0004 and ADR-0007. There is no "see all companies" mode for our staff: access to an organization's data goes through the same checks as for its own users.

Checked in CI, not promised in a policy

The script scripts/check-org-context.mjs analyses the code and fails the build if a query over tenant data does not go through the org-scoped helper. The practical consequence: a lapse of that kind does not reach production, because the version containing it cannot be built. It is an automated gate, not a statement of intent.

What the gate does not cover

The gate checks exactly one thing: that an organization's data is never read without the organization filter. It does not check whether, inside the same organization, a document reaches the right person. Those rules are hand-written and, like any hand-written code, can be wrong.

A real case, from the inside: on 4 September 2026 we found and fixed an issue in the client portal: documents were filtered by organization and by the "visible in portal" flag, but not by the contact who had uploaded them, so one client could see another client's uploads within the same organization. No organization saw another organization's data. We publish the case because it shows exactly the limit above: a gate proves what it checks, and no more.

Certifications and auditing

These are the questions asked by a practice that is professionally accountable for its clients' data. We answer them directly, including when the answer is "no".

Are you ISO 27001 certified?
No. Brivio is not ISO 27001 certified and is not currently undergoing certification, so we cannot announce a date. What we do instead are the controls described on this page: EU-only hosting, envelope encryption with a rotatable KEK, an append-only hash-chained audit log, per-organization isolation checked in CI, backups with published RPO/RTO, and weekly automated security scanning. Those are verifiable controls, not a certificate — and we name them as such.
Do you have a confirmation from DNSC?
No. DNSC does not issue a security certification for software vendors, and we hold no attestation from it. We report security incidents in line with the applicable legal obligations and handle vulnerability reports through the coordinated disclosure channel above.
Is there an independent penetration test?
The first independent pentest is planned before general availability; a summary of the report will be published on this page.
Is there a bug bounty programme?
No. We do not run a bug bounty programme and do not pay rewards. We accept reports through coordinated disclosure, at the security address in the section above, and we respond to them.

We claim no certification we do not hold. If a statement on this page cannot be verified, treat it as an error and tell us.

GDPR Rights & DSR

Data subjects (end users) and customers (controllers) can exercise any of the GDPR rights under Art. 15-22.

  • Art. 15 — access to personal data.
  • Art. 16 — rectification.
  • Art. 17 — erasure ("right to be forgotten").
  • Art. 18 — restriction of processing.
  • Art. 20 — portability (ZIP export with all of the organization's data).
  • Art. 21 — objection to processing.

Beyond GDPR requests, any organization can download its own complete archive, per company, from Settings → Company archive. The archive contains that company's business data — not the other companies in the account — and includes a per-section digest, so its contents can be verified as unmodified since export. It is available at any time, without asking us, without approval from us, and at no charge.

Send your request to dpo@brivio.ro or, if you are a customer, open a ticket at Settings → Compliance.

Documents

  • Full sub-processor list (versioned)
  • Privacy Policy
  • Terms and Conditions

Last updated: June 2026. Compliance: GDPR (EU 2016/679), Law 190/2018, GEO 70/2024 (e-Factura/e-Transport).

Brivio

The complete platform for managing your business. Projects, invoices, contracts and documents in one place.

ANAF e-FacturaeIDASGDPREU hosting

Product

  • Features
  • Pricing
  • Integrations
  • Apps
  • Changelog
  • Brivio AI

Solutions

  • For freelancers & sole traders
  • For small businesses & SRLs
  • For accountants & firms
  • For online stores
  • For construction firms
  • Company setup in Romania
  • For accounting firms
  • Alternatives to other software
  • Integrations

Free tools

  • VAT calculator
  • Salary calculator
  • PFA tax calculator
  • Invoice template
  • VAT number check
  • Company directory
  • Company rankings
  • Legislation

Resources

  • Documentation
  • Blog
  • Fiscal news
  • Community
  • Help center
  • API
  • Apps
  • Changelog
  • Status
  • Security & Trust
  • Affiliate program

Company

  • About us
  • Careers
  • Contact
  • For accounting firms

Legal

  • Legal center
  • Privacy
  • Terms
  • Cookies
  • GDPR
  • Sub-processors
  • Consumer disputes (ANPC/SAL)
  • Complaints
  • AI transparency
  • Security
  • Company details
  • Affiliate program terms
  • Security & Trust
Brivio

© 2026 Brivio. All rights reserved.

Interactive Media Solutions S.R.L. · CUI 37237457 · Str. 23 August nr. 1B, Et. 1, Ap. 8, Târgu Jiu, jud. Gorj, România · J18/241/2017 · +40 755 667 632

ANPC — Alternative Dispute Resolution (SAL)ANPC — National Authority for Consumer Protection
TwitterLinkedInGitHub

Brivio is operated by Interactive Media Solutions S.R.L. • CUI 37237457 • Reg. Com. J18/241/2017 • Registered office: Str. 23 August nr. 1B, Târgu Jiu, Gorj, Romania • Contact: legal@brivio.ro • Data supervisory authority: ANSPDCP (dataprotection.ro) • Consumer protection: ANPC (anpc.ro)

Brivio
  • Pricing
Sign InGet Started