Skip to main content

Trust & Security

Security & Compliance

SOC 2 Type II certified security built into every layer of the platform.

SOC 2 Type II

Independently audited

PCI DSS Level 1

Via Stripe

End-to-End Encryption

TLS 1.2+ & AES-256

Real-Time Monitoring

24/7 automated alerting

SOC 2 Type II Attestation

Brikl first achieved SOC 2 Type II attestation in 2022, the gold standard for organizational security controls, and has successfully renewed it each year since. This attestation is earned through a rigorous six-month audit conducted by an independent third-party firm. This is not a one-time certification. Brikl maintains compliance through ongoing, regular third-party audits.

“Achieving SOC 2 Type II compliance demonstrates Brikl's ability to meet the strict security standards required by enterprise organizations.”

— Maarten Boone, CEO of Brikl

PCI DSS Level 1 Compliance

Brikl is fully PCI DSS Level 1 compliant through Stripe — the highest standard of payment data protection in the industry.

  • Credit card data is never stored on Brikl's servers
  • All payment processing handled through Stripe's certified infrastructure
  • Stripe maintains PCI DSS Level 1 certification — the most rigorous level of compliance
  • Tokenized payment data ensures sensitive information never touches the Brikl platform

Data Protection

Every layer of Brikl's infrastructure is designed to protect your data with industry-leading encryption and access controls.

End-to-end encryption for data in transit (TLS 1.2+) and at rest (AES-256)
Strict access control policies with multi-factor authentication
Web application firewall with bot and DDoS mitigation at the network edge
Regular penetration testing and vulnerability assessments
Data stored in SOC 2 compliant cloud infrastructure

Monitoring & Incident Response

Brikl's security team maintains continuous visibility into the platform's health and responds swiftly to any potential threats.

Real-time monitoring and threat detection
Dedicated incident response procedures
Proactive security updates and patching
24/7 automated alerting

Secure Development

Security is built into how we ship software, not bolted on afterward. Automated checks run on every change before it can reach production.

Static, dynamic, and container scanning built into our CI/CD pipeline
Security gates that code must pass before it reaches production
Centralized vulnerability management with remediation SLAs by severity
Every finding tracked from detection through verified remediation

Resilience & Business Continuity

Brikl is engineered to stay available and to recover quickly. Backups and disaster recovery are documented, and regularly tested rather than assumed.

Highly available, redundant infrastructure
Automated, versioned backups of critical data
A formally documented disaster recovery plan, tested twice a year under simulated scenarios
Defined recovery time and recovery point objectives by system criticality

Compliance Framework

Security is not a one-time event. Brikl operates under a comprehensive compliance framework with continuous oversight and improvement.

Comprehensive internal controls and risk management
Regular third-party evaluations
Transparent reporting mechanisms
Continuous improvement initiatives

In the Press

Read the official announcement about Brikl's SOC 2 Type II achievement:

Brikl Achieves SOC 2 Type II Attestation — PR Newswire

Questions about our security practices?

Our team is happy to discuss Brikl's security posture, compliance documentation, and how we protect your data.