1. Information Security and Program Overview
BROSH takes information security seriously and maintains administrative, technical, organizational, and physical safeguards designed to protect BROSH's platform applications, customer accounts, customer data, and service operations.
BROSH continually evaluates ways to improve security in the product and in the way BROSH conducts business on a daily basis. Because BROSH operates with a distributed team, BROSH requires employees to understand the role they play in securing BROSH and uses tools and internal controls to help enforce compliance with internal security policies.
2. Compliance Statements
BROSH is compliant with the international ISO 27001 standard and with the SOC 2 standard as defined by the AICPA.
BROSH complies with CCPA and GDPR regulations. Customer use of BROSH may also be governed by the BROSH Data Protection Attachment at /page/data-protection-attachment where applicable.
BROSH online payment options may include Google Pay, Apple Pay, and PayPal. Payment-card processing is handled by third-party payment providers, including providers certified as Level 1 Service Providers under PCI DSS, and BROSH never has access to sensitive payment-card details.
3. Legal and Privacy Documents
The following legal and privacy documents form part of the legal framework governing BROSH, customer data, privacy choices, cookies, data processing, and customer obligations:
If there is a conflict between this page and a signed agreement accepted by BROSH, the signed agreement controls only for the specific subject matter it expressly modifies. Product features, safeguards, integrations, and service levels may vary by plan, configuration, region, and written agreement.
4. Internal Security Measures
Personnel Security. All employees complete background checks and are required to acknowledge BROSH security policy and sign a confidentiality agreement.
Identity and Access Management. Employees have unique logins for business-critical systems, and two-factor authentication is enforced wherever possible. BROSH conducts regular access audits and operates on the principle of least privilege.
Hardware Security. Employee laptops are managed, have encrypted hard drives, and are monitored with antivirus software.
Physical Security. BROSH's office is secured by key-fob access doors. Entrances and exits are observed and captured on closed-circuit television (CCTV). The office is monitored and protected by an alarm system.
Network Security. The internal network is restricted, segmented, and password protected.
Security Education. BROSH provides ongoing security training throughout the year, including periodic phishing tests. Each new employee attends security training within the first two weeks of hire to help identify threats such as social engineering and phishing. Employees and contractors with coding responsibilities are required to complete secure-code training courses.
5. BROSH Application Security
BROSH is hosted in public cloud environments, including AWS and Google Cloud, which provide infrastructure benefits such as physical security, redundancy, scalability, and key management. BROSH backend infrastructure is monitored to detect downtime.
In addition to the benefits provided by public cloud infrastructure, the BROSH application includes additional built-in security features:
- Role-based permissions
- Automation
- Backups and versioning
- Two-factor authentication*
- SSO capabilities with G Suite*
- Single Sign-On*
* Capabilities vary based on subscription tier.
6. Customer Data and Privacy
BROSH stores customer data in its cloud in order to provide the service. Depending on Customer use and account configuration, this may include the following categories:
- Names
- Usernames and email addresses
- Billing email address
- Payment history and invoices
- Phone number, where provided
- Billing address
- Company, where provided
- Location, including city and country
- Job title, where provided
- Personal website, where provided
- Referred-by information, where provided by a person who referred the user to BROSH
BROSH uses a range of third-party service providers to assist with data processing, customer engagement, analytics, payments, and hosting. The type of data a Subprocessor may access is limited to what is reasonably necessary to perform the service provided. Please refer to the BROSH Data Protection Attachment and Subprocessor page for more information.
BROSH recommends that customers who need to comply with HIPAA integrate a third-party form provider rather than using a BROSH form.
7. Encryption
Encryption is used throughout BROSH to protect personally identifiable information and non-public data from unauthorized access.
- All communication between BROSH users and the BROSH-provided web application is encrypted in transit using TLS while using the application.
- All databases and database backups are encrypted at rest.
8. Data Retention, Deletion, and Access to Data
Customers may request all of their data, or request that it be deleted, by sending an email to support@brosh.io, provided that the data is not subject to a legal hold, investigation, security need, regulatory obligation, backup cycle, or other lawful retention requirement.
Once an account or project is deleted, all associated data, including account settings, is removed from the system according to the applicable product behavior and retention practices. This action is irreversible.
Customer data is limited to personnel with roles that require access to perform their job duties. For example, BROSH Support may access customer data where access is required to provide support, troubleshoot, investigate, secure, or administer the service.
9. Third-Party Subprocessors
BROSH uses third-party service providers to help with analytics, payments, and hosting the service.
All third-party services undergo a due-diligence check to help ensure that customer data stays secure. The data provided to those services is limited to the minimum required to perform their processing duties.
Subprocessor terms, customer rights, notice procedures, and objection procedures are addressed in the BROSH Data Protection Attachment at /page/data-protection-attachment.
10. Infrastructure Availability and Service Levels
BROSH backend infrastructure is hosted in public cloud environments, including AWS and Google Cloud, and is monitored to detect downtime.
Service level agreements for BROSH hosting and the BROSH application are available through the BROSH Master Service Agreement for Enterprise Plan customers.
11. Penetration Testing, Security Scans, and Responsible Disclosure
BROSH conducts third-party penetration tests at least annually. In addition to regular penetration testing, BROSH uses scanning tools to monitor and detect vulnerabilities.
It is against BROSH Terms of Service to probe, scan, or test the vulnerability of the service or any content, or any system or network connected to the service, except as expressly authorized by BROSH in writing.
If you believe you have discovered a vulnerability within the BROSH application, submit a report by emailing support@brosh.io.
BROSH does not participate in a public bug bounty program at this time and does not provide monetary rewards for publicly reported findings.
If you believe your account has been compromised or you see suspicious activity on your account, report it to support@brosh.io.
12. Customer Account Security Best Practices
Customers are responsible for protecting account credentials and configuring account security features appropriate to their business, risk profile, and legal obligations. BROSH recommends the following practices:
- Never, under any circumstances, give another person credentials for your account.
- Create a long and strong password, recommended as twelve (12) or more characters with uppercase and lowercase letters, numbers, and special characters.
- Use Multi-Factor Authentication or Single Sign-On where available and appropriate.
- Never share sensitive account details, including payment information or username information, with third parties.
13. Contact
If you have additional questions regarding security, send an email to support@brosh.io. Enterprise customers may also reach out to their Account Executive for more information about the BROSH security program.
14. Legal Notice and Warranty Disclaimer
This page is provided for transparency regarding BROSH privacy, security, and compliance practices. It does not create any representation, warranty, service level, indemnity, or contractual commitment except to the extent expressly stated in a signed agreement, the BROSH Terms of Service, the Data Protection Attachment, or another written document accepted by BROSH.
Except as expressly stated in a binding agreement and to the maximum extent permitted by applicable law, BROSH and its licensors make no representation, warranty, or guaranty as to the reliability, timeliness, quality, suitability, truth, availability, accuracy, or completeness of the service or any content. BROSH and its licensors do not represent or warrant that: (a) use of the service will be secure, timely, uninterrupted, or error-free, or operate in combination with any other hardware, software, system, or data; (b) the service will meet customer requirements or expectations; (c) stored data will be accurate or reliable; (d) the quality of products, services, information, or other material purchased or obtained through the service will meet customer requirements or expectations; (e) errors or defects will be corrected; or (f) the service or servers that make the service available are free of viruses or harmful components. The service and all content are provided strictly on an "as is" basis, and all conditions, representations, and warranties, whether express, implied, statutory, or otherwise, including implied warranties of merchantability, fitness for a particular purpose, and non-infringement of third-party rights, are disclaimed to the maximum extent permitted by applicable law.
