Legal and trust

Security

Brenix is designed for sensitive inspection evidence, multi-tenant isolation, attributable review, and reports that may be relied on in financial, insurance, or regulatory decisions.

Tenant isolation

Every tenant-owned table carries an organization identifier. PostgreSQL row-level security is forced for tenant tables so isolation does not depend on application developers remembering a filter.

Evidence and report integrity

Original evidence is write-once and carries a SHA-256 integrity value. Derived transformations reference the original. Rendered report versions are immutable and retain their own integrity hash.

Access and accountability

Membership roles are organization-scoped. Authentication is designed for password, Google OAuth, magic links, and MFA expansion. Mutations are recorded in an audit log with actor, entity, action, before-and-after state, time, and available IP context.

Infrastructure

Production architecture uses managed PostgreSQL, private S3-compatible buckets with short-lived signed URLs, isolated web and background-worker containers, error monitoring, and product analytics with an EU option. Independent security certification and penetration-test claims will not be made until completed.

Last updated: 28 July 2026.