Security, on one page.
How our software runs inside your business. What is specific to you is settled in the audit and written into the agreement.
Where it runs and what it reaches
- Where it runs
- In your cloud account, under your access controls. We work there by invitation, and you can remove us at any time.
- What it can reach
- Only the systems named in the audit. Each has its own account with the least access the work needs: read-only wherever possible, and the audit lists every write.
- How it connects
- Through the connections each system already offers. Where a system offers none, the audit says so before you commit, with the alternative and its risks.
- Credentials
- Held in your secrets manager. Not in code, and not on our machines.
The AI and your data
- Which AI
- The audit names the AI service and where it processes data, for your approval before anything is built.
- Training
- We use only services whose terms bar training on your data.
- Confidentiality
- We sign an NDA before the audit starts and, for health data, a business associate agreement.
- What it reads
- A PDF or an email is treated as content, never as instructions. The software can take only the actions the audit lists.
- Ownership
- You own the code, its documentation and every record it produces.
Control while it runs
- What leaves
- Nothing reaches a customer, a supplier, an insurer or your books until one of your people approves it.
- When it is unsure
- The item is held for a person, with the reason. If the software fails, work drops back to your team’s normal process.
- The record
- Every action is logged: what was read, what was prepared, who approved it and when. The log is yours.
- Switching off
- One switch stops it. Nothing was migrated or replaced, so your team carries on in the same systems, and work already approved stays in them.
Change, support and leaving
- Your review
- Your security review and questionnaire come first, before we are given any access. They sit outside the build timeline.
- Changes
- Each change is tested against past cases before release, and you approve the release.
- Support
- A named person, one of the two who built it, with automated monitoring around the clock.
- If you leave
- A 30-day handover plan. The code and its documentation are already yours.
- Certificates
- We are a two-person firm and hold no SOC 2 or ISO 27001 certificate. The design keeps control with you instead: your cloud, your access controls, your log.
Brightwork Digital · brightworkdigital.co/consulting/security
Questions from your security team? Book a discovery call and bring them.