Clicky

Security and compliance

Overview

Data security and privacy are built into Brolly. Our platform was originally intended as a tool for government, so compliance and data protection are at the core of what we do.

This page provides a high-level overview of the security practices that Brolly has put in place.

If you have questions or feedback please reach out to us at security@brolly.com.au

Infrastructure

Network level security monitoring and protection

Our network security architecture consists of multiple security zones. We monitor and protect our network, to make sure no unauthorised access is performed using:

DDoS protection

We use Distributed Denial of Service (DDoS) mitigation services powered by an industry-leading solution.

Data encryption

Encryption in transit

  • All data sent to or from our infrastructure is encrypted in transit via industry best-practices using Transport Layer Security (TLS).
  • View our SSLLabs report.

Encryption at rest

Data retention and removal

We retain our users data for a period of 90 days after the trials end. All data is then completely removed from the dashboard and server. Every user can request the removal of usage data by contacting support.

Read more about our privacy settings.

Business continuity and disaster recovery

We back up all our critical assets and regularly attempt to restore the backup to guarantee a fast recovery in case of disaster. All our backups are encrypted.

Application security monitoring

Secure development

We develop the following security best practices and frameworks (OWASP Top 10, SANS Top 25). We use the following best practices to ensure the highest level of security in our software:

User protection

Account takeover protection

We protect our users against data breaches by monitoring and blocking brute force attacks.

Employee access

  • Our strict internal procedure prevents any employee or administrator from gaining access to user data. Limited exceptions can be made for customer support.
  • Our employees sign a Non-Disclosure and Confidentiality Agreement to protect our customers sensitive information.