Security and privacy
Brigg is built to meet strict requirements for confidentiality and data security. Your data is never used to train AI models, raw audio is never stored, and processing happens inside the EU/EEA.
Certifications and security standardsThe certifications belong to the providers running each layer.
The basics
No single feature makes a system safe. It is the sum of the boring parts: encryption, isolation, permissions, logs and backups — in place before the first customer.
All traffic is encrypted in transit. Data is stored encrypted at our providers, and integration keys are encrypted again at the application layer with AES-256-GCM.
Data is isolated per company inside the database itself. The isolation is enforced by the database on every single query — for the agent, search and sync alike.
You sign in with a time-limited link by email. We never store passwords, so there is no password database to steal.
Remove a person, or suspend an account, and the server stops answering them within a minute, without anyone having to sign out. Open editing sessions are dropped immediately.
Every write and every agent tool leaves a row that cannot be edited afterwards. The log is yours, and you can read it yourself.
The database is backed up continuously, with point-in-time recovery so a state can be restored if something goes wrong.
Automatic per-company limits on the APIs protect against brute force and overload, and keep the service up for everyone else.
EU/EEA
Every layer your data passes through runs inside the EU/EEA: the database, the files, the agent's workspace, the language models, speech transcription and email.
Certifications
Brigg is a small team. So we buy the security work where it is done best — from infrastructure providers with independent audits — and pick the EU region at every one of them.
The international standard for information security management systems. The providers running servers, storage and the database are certified and audited annually.
An independent audit that security, availability and confidentiality are genuinely practised over time — not merely described on paper.
Controls for financial reporting, and the public trust report. Relevant when your auditor asks about the systems your accounts rest on.
The highest level for handling card data. Card numbers go straight to the payment processor and are never stored with us — we only ever see a reference.
Nora Software AS is the processor for your content. Our standard Art. 28 data processing agreement, with the sub-processor list attached, is available on request.
The certifications above belong to the providers running each layer. Brigg does not yet hold its own SOC 2 or ISO 27001 certification. If you need the details for a vendor assessment — including named sub-processors and audit reports — we share them under NDA.
The agent
It has exactly the access you have — never more. And anything that goes out in your name goes through you.
Sending email, booking meetings, contacting people: the agent proposes, and you press “Allow” on a card showing the whole action. You can grant standing permission — and withdraw it again.
Open, limited to sites you approve, or closed entirely. With access closed the agent can neither search, read web pages nor reach external services.
The agent reads the database as you. Private documents, other people's meeting notes and data your role cannot see are as invisible to the agent as they are to you. It holds no standing keys.
A rule that fires overnight, or a reply to an incoming email, can never spend a standing permission. With nobody at the screen it becomes a card — not an action.
Your content is used only to deliver the service to you. It is not used to train models, ours or anyone else's.
I have drafted the follow-up to Kari after the meeting. It will not be sent until you say so.
The card always shows the whole action — never a summary.
Meetings and audio
The meeting feature is built so that the most sensitive material — the voices in the room — exists for as little time as possible.
We never store recordings. The audio stream is processed continuously in real time for transcription, and is gone as soon as the text exists.
The verbatim text is always private to whoever started the meeting. The meeting notes are shared with the team only if you choose to share them.
The desktop app transcribes from your own machine, independently of Teams, Meet or Zoom. No third party is let into the meeting, and no video is stored.
GDPR and your rights
Nora Software AS follows the GDPR, and your data does not leave the EU/EEA.
Our standard GDPR Art. 28 agreement, with the sub-processor list attached. Signed digitally — in Brigg.
You can get a copy of the information we hold about you in a common format, and ask us to correct anything that is wrong.
Delete your account from your account settings. Everything we hold about you, the agent's workspace included, is deleted — and every active session ends.
Security incidents are documented, risk-assessed and reported to the supervisory authority within 72 hours where the law requires it. You are told directly if the incident poses a high risk to you.
Visit statistics are collected without cookies, without storing IP addresses and without tracking across sites.
Website logs are deleted after 30 days, error reports after 30 days, and meeting audio is never stored. Everything else for as long as you are a customer — and no longer.
Operations
Error rates, queues, email delivery and AI calls are tracked on their own dashboards, with alerts that reach the team before customers notice anything.
Every dependency is checked against known vulnerabilities each day. A serious finding trips the daily run, and is fixed as an ordinary, reviewed change.
The codebase is reviewed regularly for security defects using the best available AI models, on top of static analysis. Findings are fixed through small, reviewed changes.
Signing keys and secrets can be rotated without downtime, and are rotated immediately if we suspect anything has been exposed.
Common questions
No. Your content is used only to deliver the service to you, and not to train models — ours or anyone else's.
Yes. The database, the files, the agent's workspace, the language models, speech transcription and email all run inside the EU/EEA. Every sub-processor is covered by a data processing agreement and a confidentiality undertaking.
The complete list, with name, role and place of processing, comes with the data processing agreement. If we take on a new sub-processor, customers with an agreement are told in advance.
No. Your own documents, private meetings and your own transcript are yours alone. Permissions are enforced in the database and apply to the agent exactly as they do to search and sync.
An administrator removes the person, and access closes within a minute. What they shared with the team stays; what was private follows nobody.
Not by default. Email, calendar and contacting other people all require you to press “Allow” on a card showing the whole content. A standing permission applies only while you are in the conversation yourself — automatic runs always ask.
Send the details to the address below. We confirm receipt as quickly as we can and follow up on the case as it develops.
Access, correction, deletion, or anything we should have explained better.
legal@brigg.noFound a vulnerability or a technical fault? We follow up as it develops.
info@brigg.no