Fictional startup · A Plyco onboarding & compliance demo About Plyco
← Back to Brieflane

SECURITY & PROVIDERS

A foundation
we can explain.

Documented practices, clear provider responsibilities, and an honest view of what is still being built.

Illustrative security profileThese controls describe the fictional Brieflane product. The actual website is a static Firebase-hosted demo with synthetic records and no customer-data processing application.
01 / PROTECT

Encryption & access

The fictional product uses TLS in transit and encryption at rest for databases, files, and backups. Role-based access distinguishes agency admins, staff, and invited client reviewers.

Tenant authorization is checked on each request. Clients only access explicitly shared projects; staff production access is limited, logged, and protected with MFA.

02 / RECOVER

Regional backups

Daily backups stay in the workspace’s selected AWS region and expire after 35 days. Recovery is restricted to authorized operators; no EU-to-US backup replication is used.

Restore checks are part of the documented operating process. Usage and security logs stay in-region for 90 days.

03 / BUILD

Safer development

Code changes receive peer review and automated checks before deployment. Dependency and secret scanning are enabled. Production deployment approval is required.

Development and testing use synthetic records rather than production customer data. Brieflane does not use AI or send customer data to AI providers.

04 / RESPOND

Incident handling

A named incident owner investigates alerts, coordinates containment, and records follow-up work. Affected agencies are notified by email without undue delay so they can meet their controller obligations.

Where Brieflane acts as controller, reportable personal-data breaches are notified to the supervisory authority within the applicable GDPR deadline, where feasible within 72 hours of awareness. Report concerns to security@brieflane.example (example only).

Still in progress

Our first formal incident-response exercise and independent penetration test are pending. Brieflane has no SOC 2 report, ISO 27001 certification, or claim of guaranteed GDPR compliance.

Choose where your
customer data lives.

EU or US hosting for both Brieflane Workspace and Brieflane Customer Portal. Pick a region when creating your workspace; your portal follows that choice.

European Union

Ireland

EU application hosting and customer-data storage in Ireland.

AWS · eu-west-1

United States

Northern Virginia

US application hosting and customer-data storage in Northern Virginia.

AWS · us-east-1

Application compute, databases, uploaded files, security logs, and backups remain in the selected AWS region. We do not replicate customer content between EU and US regions. Billing through Stripe and email through Resend can involve processing outside that region, including in the US. Read about transfers and safeguards

THE SERVICES BEHIND THE SERVICE

Providers, without surprises.

This is the fictional provider inventory used for demos. Regional customer-data storage and supporting billing/email processing have different boundaries.

Illustrative Brieflane provider inventory
ProviderPurpose & dataProcessing location
Amazon Web Services (AWS)Application compute, PostgreSQL database, object storage, logs, and backups.Accounts, client contacts, requests/documents, approvals, and logs.Ireland or Northern Virginia, following the selected workspace region.
StripeSubscription billing and payment processing.Billing contacts, invoice details, and payment information; no project documents.EU and US processing; not restricted to the workspace region.
ResendTransactional notifications and opted-in marketing emails.Recipient names/emails and minimal notification content; no document attachments.US processing; not restricted to the workspace region.

Processor agreements and documented transfer assessments support the fictional operating model. Provider locations above are scenario assumptions, not verified vendor guarantees. Read the privacy policy for retention, rights, and transfer safeguards →