Security and privacy

Security built for organisations with high demands for control.

Brigg is built to meet strict requirements for confidentiality and data security. Your data is never used to train AI models, raw audio is never stored, and processing happens inside the EU/EEA.

Certifications and security standardsThe certifications belong to the providers running each layer.

ISO 27001ISO 27001Infrastructure and database
SOC 2SOC 2 Type IIInfrastructure and database
PCI DSSPCI DSS Level 1Card payments
GDPRGDPRProcessing in the EU/EEA, Art. 28 agreement

The basics

The fundamentals, done properly

No single feature makes a system safe. It is the sum of the boring parts: encryption, isolation, permissions, logs and backups — in place before the first customer.

01

Encrypted in transit and at rest

All traffic is encrypted in transit. Data is stored encrypted at our providers, and integration keys are encrypted again at the application layer with AES-256-GCM.

TLS 1.2+AES-256-GCM
02

Row-Level Security

Data is isolated per company inside the database itself. The isolation is enforced by the database on every single query — for the agent, search and sync alike.

Row-level securityEnforced in the database
03

Passwordless sign-in

You sign in with a time-limited link by email. We never store passwords, so there is no password database to steal.

Magic linkExpires after 10 minutes
04

Fast revocation of access

Remove a person, or suspend an account, and the server stops answering them within a minute, without anyone having to sign out. Open editing sessions are dropped immediately.

Under 60 secondsDecided on the server
05

Tamper-evident audit log

Every write and every agent tool leaves a row that cannot be edited afterwards. The log is yours, and you can read it yourself.

Append-onlyVisible to you
06

Continuous backups

The database is backed up continuously, with point-in-time recovery so a state can be restored if something goes wrong.

Point-in-timeInside the EU/EEA
07

Rate limiting and abuse protection

Automatic per-company limits on the APIs protect against brute force and overload, and keep the service up for everyone else.

Rate limitsPer organisation

EU/EEA

Data is processed in the EU

Every layer your data passes through runs inside the EU/EEA: the database, the files, the agent's workspace, the language models, speech transcription and email.

DatabaseCustomers, meetings, tasks, documents
EU
FilesUploads, documents, apps
EU
The agent's workspaceAn isolated sandbox per user
EU
Language modelsThe agent's thinking and writing
EU endpoint
Speech transcriptionMeeting audio in real time
EU endpoint
EmailLinks, meeting notes, newsletters
EU

Certifications

We stand on certified ground

Brigg is a small team. So we buy the security work where it is done best — from infrastructure providers with independent audits — and pick the EU region at every one of them.

Infrastructure · Database

ISO/IEC 27001

The international standard for information security management systems. The providers running servers, storage and the database are certified and audited annually.

Infrastructure · Database

SOC 2 Type II

An independent audit that security, availability and confidentiality are genuinely practised over time — not merely described on paper.

Infrastructure

SOC 1 and SOC 3

Controls for financial reporting, and the public trust report. Relevant when your auditor asks about the systems your accounts rest on.

Payments

PCI DSS Level 1

The highest level for handling card data. Card numbers go straight to the payment processor and are never stored with us — we only ever see a reference.

The whole service

GDPR and data processing agreement

Nora Software AS is the processor for your content. Our standard Art. 28 data processing agreement, with the sub-processor list attached, is available on request.

The certifications above belong to the providers running each layer. Brigg does not yet hold its own SOC 2 or ISO 27001 certification. If you need the details for a vendor assessment — including named sub-processors and audit reports — we share them under NDA.

The agent

The agent works on your terms

It has exactly the access you have — never more. And anything that goes out in your name goes through you.

Asks first, by default

Sending email, booking meetings, contacting people: the agent proposes, and you press “Allow” on a card showing the whole action. You can grant standing permission — and withdraw it again.

You control network access

Open, limited to sites you approve, or closed entirely. With access closed the agent can neither search, read web pages nor reach external services.

Your access, and no more

The agent reads the database as you. Private documents, other people's meeting notes and data your role cannot see are as invisible to the agent as they are to you. It holds no standing keys.

Automatic runs always ask

A rule that fires overnight, or a reply to an incoming email, can never spend a standing permission. With nobody at the screen it becomes a card — not an action.

No training on your data

Your content is used only to deliver the service to you. It is not used to train models, ours or anyone else's.

The agentCustomers

I have drafted the follow-up to Kari after the meeting. It will not be sent until you say so.

Send email as you
Tokari.lund@nordvik.no
SubjectSummary and next steps
Hi Kari, thank you for a good meeting today. As agreed I will send a proposal for the framework agreement by Friday, and we will do a short review the week after …
Allow onceAllow alwaysDecline

The card always shows the whole action — never a summary.

Meetings and audio

No recordings to look after

The meeting feature is built so that the most sensitive material — the voices in the room — exists for as little time as possible.

01

Audio recordings are not stored

We never store recordings. The audio stream is processed continuously in real time for transcription, and is gone as soon as the text exists.

02

The transcript is private

The verbatim text is always private to whoever started the meeting. The meeting notes are shared with the team only if you choose to share them.

03

No bot in the meeting

The desktop app transcribes from your own machine, independently of Teams, Meet or Zoom. No third party is let into the meeting, and no video is stored.

GDPR and your rights

European rules, in practice

Nora Software AS follows the GDPR, and your data does not leave the EU/EEA.

Data processing agreement

Our standard GDPR Art. 28 agreement, with the sub-processor list attached. Signed digitally — in Brigg.

Access and portability

You can get a copy of the information we hold about you in a common format, and ask us to correct anything that is wrong.

Deletion you do yourself

Delete your account from your account settings. Everything we hold about you, the agent's workspace included, is deleted — and every active session ends.

Breach notification

Security incidents are documented, risk-assessed and reported to the supervisory authority within 72 hours where the law requires it. You are told directly if the incident poses a high risk to you.

Web analytics without a cookie banner

Visit statistics are collected without cookies, without storing IP addresses and without tracking across sites.

Short retention where we can

Website logs are deleted after 30 days, error reports after 30 days, and meeting audio is never stored. Everything else for as long as you are a customer — and no longer.

Operations

Security as routine

Continuous

Monitoring and alerts

Error rates, queues, email delivery and AI calls are tracked on their own dashboards, with alerts that reach the team before customers notice anything.

Daily

Vulnerability scanning

Every dependency is checked against known vulnerabilities each day. A serious finding trips the daily run, and is fixed as an ordinary, reviewed change.

Regularly

AI-assisted security review

The codebase is reviewed regularly for security defects using the best available AI models, on top of static analysis. Findings are fixed through small, reviewed changes.

On suspicion

Key rotation

Signing keys and secrets can be rotated without downtime, and are rotated immediately if we suspect anything has been exposed.

Common questions

What customers ask

Do you train AI models on our data?

No. Your content is used only to deliver the service to you, and not to train models — ours or anyone else's.

Is data stored and processed in the EU?

Yes. The database, the files, the agent's workspace, the language models, speech transcription and email all run inside the EU/EEA. Every sub-processor is covered by a data processing agreement and a confidentiality undertaking.

Which sub-processors do you use?

The complete list, with name, role and place of processing, comes with the data processing agreement. If we take on a new sub-processor, customers with an agreement are told in advance.

Can my colleagues see everything I do?

No. Your own documents, private meetings and your own transcript are yours alone. Permissions are enforced in the database and apply to the agent exactly as they do to search and sync.

What happens when someone leaves?

An administrator removes the person, and access closes within a minute. What they shared with the team stays; what was private follows nobody.

Can the agent send something without me knowing?

Not by default. Email, calendar and contacting other people all require you to press “Allow” on a card showing the whole content. A standing permission applies only while you are in the conversation yourself — automatic runs always ask.

How do I report a security issue?

Send the details to the address below. We confirm receipt as quickly as we can and follow up on the case as it develops.

Data processing agreement

Our standard GDPR Art. 28 agreement, ready to sign.

legal@brigg.no

Privacy questions

Access, correction, deletion, or anything we should have explained better.

legal@brigg.no

Report a security issue

Found a vulnerability or a technical fault? We follow up as it develops.

info@brigg.no

Try Brigg for free

Enter your work email and we will send you a sign-in link. No passwords, no forms — your company's workspace is ready when you click.

Free for the whole team. No card, no commitment.