Architecture, identity, encryption, isolation and operations.
The platform runs in EU cloud regions (Stockholm, Helsinki/Sweden Central). Each workspace's data is logically isolated with workspace-scoped encryption keys; Enterprise customers can choose dedicated infrastructure.
TLS 1.2+ for all traffic; AES-256 at rest for databases, indexes, files and backups. Connector credentials and tool secrets are stored in a dedicated vault (KMS-backed) and are never exposed to models or logs.
Access rights are synced with content and enforced inside every retrieval query. See Permissions & access control.
Requests to model providers are made under zero-data-retention terms; providers do not train on your data. EU-hosted models and customer-owned model deployments are available. Prompts are constructed from retrieved passages the asking user is allowed to see.
Read/write scopes, approval policies, limits, hand-offs and emergency stop. See Guardrails & approvals.
Query logs, run traces and an immutable audit log of security events. Export to S3-compatible storage or SIEM (Splunk, Sentinel, Elastic) via continuous export.
Infrastructure as code, peer-reviewed changes, least-privilege access with MFA for staff, dependency scanning in CI, independent penetration testing before major releases, encrypted daily backups with tested restores, and documented incident response with customer notification within 48 hours of a confirmed breach affecting their data.
Email security@brewmycode.com. We acknowledge within one business day and keep you informed until resolution.