Your data. Secured. Certified. Compliant.
Brolly holds the records your organization may one day defend in court. That responsibility shapes how the platform is built, audited and operated — and everything on this page is verifiable.
Independently certified, not self-declared.
ISO/IEC 27001:2022
Certified information security management system — the international gold standard, audited independently.
CSA STAR
Registered with the Cloud Security Alliance's Security, Trust & Assurance Registry.
NIST SP 800-53
Controls aligned to NIST SP 800-53, the framework many US state and local procurement standards reference.
Built for the rules your records live under.
| Your obligation | What it demands | How Brolly answers |
|---|---|---|
| FOIA & state public records laws | Produce complete, unaltered records on request — including edited and deleted content | Real-time capture, revision history, checksums, response-ready exports |
| FINRA 10-06 / 11-39 & SEC 17a-4 | Retain business communications on social media as records | Immutable storage, retention settings, audit trails |
| HIPAA & FERPA contexts | Handle regulated communities' communications with care and accountability | Role-based access, moderation with preserved records, complete audit logs |
| Records retention schedules | Keep records for mandated periods, then disposition defensibly | Configurable retention aligned to your schedule |
The controls, in plain English.
Encryption everywhere
AES-256 at rest, TLS 1.2+ in transit. Records are stored immutably with digital checksums.
Access control
Multi-factor authentication and role-based access — records staff, communications and counsel each see what their role requires.
Tested by attackers
Independent penetration testing and a secure development lifecycle guided by OWASP practices.
Reliable by design
99.95% uptime SLA on AWS across multiple availability zones, with monitored backups.
Your records are yours.
Brolly never sells or shares customer data with third parties. Privacy practices are designed to meet CCPA/CPRA and GDPR expectations, with data deletion honored per our published process.
What your security team will ask.
Is Brolly ISO 27001 certified?
Is Brolly FedRAMP authorized?
How is our data protected?
Do you sell or share our data?
What uptime do you commit to?
Can our security team review your controls?
Send us the questionnaire. We like them.
Certification documents, pen-test summaries and completed security reviews are available under NDA.