Security

How Brekfuz handles your organization's data

Brekfuz uses read-only access scopes and processes metadata, not message content. Data resides in the Mumbai region. This page describes our security architecture and data principles honestly, without certification claims we do not yet hold.

Data principles

What Brekfuz reads, and what it does not

Brekfuz processes activity metadata to build the knowledge graph. It does not read message content, document body text, or code diffs.

Processed

What Brekfuz reads

  • Channel membership and message frequency counts (not content)
  • Document authorship, page creation, and edit history
  • Ticket assignment history and project membership
  • Commit authorship by file path (not code content)
  • PR review participation (not review text)
  • User identifiers and team membership
Not processed

What Brekfuz does not read

  • Message or DM content in Slack or any messaging tool
  • Document body text in Confluence, Notion, or wikis
  • PR review comments or code diff content in GitHub
  • Ticket descriptions, comments, or attachments in Jira or Linear
  • Email content in any connected mail system
  • Any file content from connected storage

Architecture

How your data is stored and protected

Encryption in transit and at rest

All data in transit is protected with TLS 1.2 or above. Data stored in Brekfuz databases is encrypted at rest with AES-256. Encryption keys are managed by the hosting provider's key management service.

Mumbai region data residency

All Brekfuz production infrastructure runs in the Mumbai (ap-south-1) AWS region. Customer activity data is stored in India and does not leave the Mumbai region unless explicitly requested for export by a customer administrator.

Read-only OAuth scopes

Every integration uses the minimum read-only OAuth scopes required for the signal it collects. Brekfuz does not request write, admin, or delete scopes for any connected tool, and cannot post, create, or modify data in your connected systems.

Tenant isolation

Each customer organization's knowledge graph data is isolated at the database level. Tenant isolation is enforced by row-level security policies. One customer cannot access another customer's data.

Access control

Brekfuz supports role-based access control within an organization. Administrators control which team members can view the knowledge graph, run reports, or manage integrations. All access is authenticated over HTTPS.

Data deletion

Customers can request full deletion of their organization's data at any time by contacting the Brekfuz team. On account closure, all customer data is deleted from production systems within 30 days. Backups are purged within 90 days of deletion request.

Compliance and certifications

Where we are and where we are heading

We are an early-stage company. Below is an honest statement of our current compliance posture and planned next steps.

India DPDP Act 2023

Aligned

Our data handling, retention, and deletion practices are designed in alignment with India's Digital Personal Data Protection Act 2023.

GDPR

GDPR-aware processing

We apply GDPR-aligned data minimization and purpose limitation principles to all processing. Brekfuz is not a certified GDPR processor and does not represent formal EU certification.

SOC 2 Type II

Planned

We plan to pursue SOC 2 Type II certification as the company grows. We do not currently hold this certification and will update this page when we do.

Questions about security

Talk to the team before you sign up

If you have specific security questions that are not answered here, reach out. We will answer directly and add anything substantive to this page for future readers.