Roles and permissions
Access to data and actions follows from the user's role and their responsibility in a specific process.
Security
Brillnet products help people work with data, decisions and evidence. Access control, action history and data minimisation are therefore part of the design — not an add-on after deployment.
Controls
We prefer simple mechanisms that can be explained to a process owner and checked in an audit.
Access to data and actions follows from the user's role and their responsibility in a specific process.
Material decisions, status changes and operations leave a readable record for later verification.
AI features support the work; they do not decide. Where it matters, a human approval step remains.
We collect the data a process needs. We avoid gathering information without a clear purpose.
We assume failures and edge cases: input validation, logs, backups and a predictable rollback are part of the job.
During onboarding we discuss concrete risks: integrations, access, retention, data location and the team's duties. Report a vulnerability or incident directly to security@brillnet-app.com — receipt confirmed within one working day.
Security evidence
A person assessing a supplier usually needs documents, not just declarations. During the onboarding conversation we go through the materials needed for a vendor risk review.
We provide a template data processing agreement and the list of providers that may take part in delivering the service.
The backup model, service recovery and incident communication are confirmed for the specific scope of a deployment.
The security management system is maintained as a process. Certification is not an active public offer; the document scope is confirmed after qualification.
Maintenance
Maintenance covers support, hosting, backups, security procedures and a development plan. The scope is confirmed at onboarding; responsibility for how the process is used stays with the customer.
The customer gets an agreed contact channel for operational questions, reports and decisions about further development.
Before launch we discuss access, roles, personal data, exports and how incidents are handled.
Brillnet can support configuration, first scenarios and clarifying responsibilities, but process decisions stay with the customer.
Sources and limits of our claims
Brillnet materials reference recognised sources such as the OWASP Application Security Verification Standard and the NIST AI Risk Management Framework. These are reference points — not a declaration of certification, nor of full compliance of every product with every requirement.