Security and trust

Where your compliance data lives, and how it is protected.

Brehon is a compliance product, so the first fair question is how it treats your own data. Here is the actual posture, in plain language, built and reviewed by a CISSP and CISM. No badges we have not earned.

The model

You get your own instance, not a seat in a shared cloud.

Most compliance SaaS pools every customer into one large multi-tenant environment and asks you to trust it. Brehon does the opposite. Each customer runs on a dedicated, single-tenant instance: your own database, your own encryption keys, your own backups. No other customer's data has ever touched it, and your SSP, POA&M, SPRS score, and audit trail are your documents to export whenever you want.

  • Dedicated deployment. A separate instance per customer, not a row in a shared database.
  • Your own database and keys. Your data and its encryption keys are provisioned only for you.
  • Yours to export. Your compliance record leaves with you, in the formats the government expects.

The controls

What actually protects it.

Every item below is a control that is live in the platform today, not a roadmap promise.

Mandatory multi-factor authentication

MFA is enforced from the first login on every instance. Signing a compliance attestation requires a second step-up verification at the moment of signing, not just at login.

Tenant isolation by row-level security

Your records are isolated in the database by PostgreSQL row-level security, so access is scoped to your tenant at the data layer, not just in the application.

Per-instance encryption keys

Every instance is provisioned with its own independent set of secrets: its own database credentials, its own JWT signing key, its own service keys. No secret is shared across customers.

Signed attestations

When an attestation or affirmation is signed, the signer is pinned to a registered signing official and the result is a cryptographic signature, so the record shows who signed and that it has not been altered.

Encrypted secrets at rest

Integration and webhook secrets are envelope-encrypted at rest with key rotation, so a database snapshot never exposes a usable secret in the clear.

Encrypted backups

Nightly database backups are encrypted before they ever leave the instance, so the backup copy is protected in transit and at rest.

Locked-down outbound egress

Outbound requests are checked against an allow-list and fail closed against internal and private addresses, closing the server-side request forgery paths a compliance tool must not leave open.

Audited privileged operations

Privileged, service-level operations are written to an audit trail with a typed purpose, so there is a record of every elevated action taken on the system.

What we do not claim

Straight about the badges.

Brehon does not hold a FedRAMP authorization or a SOC 2 report today, and we will not imply otherwise. Our answer to the data-residency question is a different one: instead of asking you to trust a single shared cloud, we give you your own instance. If a specific certification becomes a contract requirement for you, raise it on the fit call and we will be straight about exactly where we stand.