BrewMy{Code}

Security & trust

Your data, your permissions, your rules.

BrewMy{Code} is built for operations, finance and support teams that handle sensitive data every day. Security is a property of the architecture, not a checkbox.

EU data residency

Customer data is processed and stored in EU regions (Stockholm, Helsinki). Language model providers are used under zero-data-retention terms; EU-hosted models are available.

Encryption

TLS 1.2+ in transit, AES-256 at rest. Secrets and connector credentials are stored in a dedicated vault, never in logs.

Permission-aware by design

Access rights are synced with content. Retrieval is filtered per user at query time, so nobody can ask their way into a document they couldn't open.

Identity

Email + password with MFA, Google and Microsoft sign-in. SSO (SAML/OIDC) and SCIM provisioning on Enterprise.

Audit & observability

Every query and every agent run is logged: who asked, what was retrieved, which tool was called, what changed. Export to your SIEM.

Approvals & limits

Write actions can require human approval. Volume, spend and time-of-day limits per agent. Emergency stop for any agent or the whole workspace.

Compliance

GDPR from the ground up.

  • We act as a data processor for customer content; a Data Processing Agreement is part of every paid plan. Read the DPA.
  • Sub-processors are listed publicly and customers are notified before changes. Current list.
  • Data subject requests (access, deletion, export) are handled within 30 days; deletion is propagated to backups within 35 days.
  • Customer content is never used to train models — ours or anyone else's.
  • Retention is configurable per knowledge base and per agent; default 90 days for run traces.
Operations

How we run the platform.

  • Infrastructure as code, least-privilege access, MFA enforced for all staff.
  • Continuous dependency scanning and independent penetration testing before major releases.
  • Encrypted daily backups with tested restore procedures.
  • Incident response: customers notified within 72 hours of a confirmed personal-data breach, as required by GDPR — usually far sooner.
  • Responsible disclosure: report vulnerabilities to security@brewmycode.com.
Questions

Security review?

We're used to security questionnaires. Send yours, or book a call with our engineering team.

Ready to take the manual work off your team?

Get a demo. We'll show a Knowledge Search Agent answering from your own documents and an Enterprise Agent running a real workflow, live.