Mandatory multi-factor authentication
MFA is enforced from the first login on every instance. Signing a compliance attestation requires a second step-up verification at the moment of signing, not just at login.
Security and trust
Brehon is a compliance product, so the first fair question is how it treats your own data. Here is the actual posture, in plain language, built and reviewed by a CISSP and CISM. No badges we have not earned.
The model
Most compliance SaaS pools every customer into one large multi-tenant environment and asks you to trust it. Brehon does the opposite. Each customer runs on a dedicated, single-tenant instance: your own database, your own encryption keys, your own backups. No other customer's data has ever touched it, and your SSP, POA&M, SPRS score, and audit trail are your documents to export whenever you want.
The controls
Every item below is a control that is live in the platform today, not a roadmap promise.
MFA is enforced from the first login on every instance. Signing a compliance attestation requires a second step-up verification at the moment of signing, not just at login.
Your records are isolated in the database by PostgreSQL row-level security, so access is scoped to your tenant at the data layer, not just in the application.
Every instance is provisioned with its own independent set of secrets: its own database credentials, its own JWT signing key, its own service keys. No secret is shared across customers.
When an attestation or affirmation is signed, the signer is pinned to a registered signing official and the result is a cryptographic signature, so the record shows who signed and that it has not been altered.
Integration and webhook secrets are envelope-encrypted at rest with key rotation, so a database snapshot never exposes a usable secret in the clear.
Nightly database backups are encrypted before they ever leave the instance, so the backup copy is protected in transit and at rest.
Outbound requests are checked against an allow-list and fail closed against internal and private addresses, closing the server-side request forgery paths a compliance tool must not leave open.
Privileged, service-level operations are written to an audit trail with a typed purpose, so there is a record of every elevated action taken on the system.
What we do not claim
Brehon does not hold a FedRAMP authorization or a SOC 2 report today, and we will not imply otherwise. Our answer to the data-residency question is a different one: instead of asking you to trust a single shared cloud, we give you your own instance. If a specific certification becomes a contract requirement for you, raise it on the fit call and we will be straight about exactly where we stand.
Hi! I'm the Solas AI assistant. I can answer questions about our services, pricing, and how we help service businesses save time with AI automation. What can I help you with?