Trust & Security Center

Your data. Secured. Certified. Compliant.

Brolly holds the records your organization may one day defend in court. That responsibility shapes how the platform is built, audited and operated — and everything on this page is verifiable.

Certifications

Independently certified, not self-declared.

Certified

ISO/IEC 27001:2022

Certified information security management system — the international gold standard, audited independently.

Registered

CSA STAR

Registered with the Cloud Security Alliance's Security, Trust & Assurance Registry.

Aligned

NIST SP 800-53

Controls aligned to NIST SP 800-53, the framework many US state and local procurement standards reference.

Compliance alignment

Built for the rules your records live under.

Your obligationWhat it demandsHow Brolly answers
FOIA & state public records lawsProduce complete, unaltered records on request — including edited and deleted contentReal-time capture, revision history, checksums, response-ready exports
FINRA 10-06 / 11-39 & SEC 17a-4Retain business communications on social media as recordsImmutable storage, retention settings, audit trails
HIPAA & FERPA contextsHandle regulated communities' communications with care and accountabilityRole-based access, moderation with preserved records, complete audit logs
Records retention schedulesKeep records for mandated periods, then disposition defensiblyConfigurable retention aligned to your schedule
Platform security

The controls, in plain English.

Encryption everywhere

AES-256 at rest, TLS 1.2+ in transit. Records are stored immutably with digital checksums.

Access control

Multi-factor authentication and role-based access — records staff, communications and counsel each see what their role requires.

Tested by attackers

Independent penetration testing and a secure development lifecycle guided by OWASP practices.

Reliable by design

99.95% uptime SLA on AWS across multiple availability zones, with monitored backups.

Privacy

Your records are yours.

Brolly never sells or shares customer data with third parties. Privacy practices are designed to meet CCPA/CPRA and GDPR expectations, with data deletion honored per our published process.

CCPA / CPRAGDPR-ready practicesNo data selling — everDocumented deletion processComplete audit trails
Security review

What your security team will ask.

Is Brolly ISO 27001 certified?
Yes — Brolly is certified against ISO/IEC 27001:2022, the international standard for information security management, and registered with the Cloud Security Alliance STAR program.
Is Brolly FedRAMP authorized?
No. Brolly’s controls are aligned to NIST SP 800-53, which many state and local procurement frameworks reference, but Brolly does not hold a FedRAMP authorization.
How is our data protected?
Records are encrypted with AES-256 at rest and TLS 1.2+ in transit, stored immutably with digital checksums, and protected by multi-factor authentication, role-based access controls and complete audit trails. The platform runs on AWS across multiple availability zones.
Do you sell or share our data?
No. Brolly never sells or shares customer data with third parties. Privacy practices are designed to meet CCPA/CPRA and GDPR expectations.
What uptime do you commit to?
A 99.95% uptime service level, backed by service credits, on redundant AWS infrastructure.
Can our security team review your controls?
Yes — certification documents, penetration-test summaries and completed security questionnaires are available under NDA. Reach out through the contact page and we’ll route you to the right people.

Send us the questionnaire. We like them.

Certification documents, pen-test summaries and completed security reviews are available under NDA.