Trust & Security
Security & Compliance
Brikl is SOC 2 Type II certified, with security built into every layer of the platform.
SOC 2 Type II
Independently audited
PCI DSS Level 1
Via Stripe
End-to-End Encryption
TLS 1.2+ & AES-256
Real-Time Monitoring
24/7 automated alerting
Attestations
SOC 2 Type II Attestation
Brikl first achieved SOC 2 Type II attestation in 2022, the gold standard for organizational security controls, and has successfully renewed it each year since. This attestation is earned through a rigorous six-month audit conducted by an independent third-party firm. This is not a one-time certification. Brikl maintains compliance through ongoing, regular third-party audits.
“Achieving SOC 2 Type II compliance demonstrates Brikl's ability to meet the strict security standards required by enterprise organizations.”
— Maarten Boone, CEO of Brikl
PCI DSS Level 1 Compliance
Brikl is fully PCI DSS Level 1 compliant through Stripe — the highest standard of payment data protection in the industry.
- Credit card data is never stored on Brikl's servers
- All payment processing handled through Stripe's certified infrastructure
- Stripe maintains PCI DSS Level 1 certification — the most rigorous level of compliance
- Tokenized payment data ensures sensitive information never touches the Brikl platform
Data Protection
Every layer of Brikl's infrastructure is designed to protect your data with industry-leading encryption and access controls.
End-to-end encryption for data in transit (TLS 1.2+) and at rest (AES-256)
Strict access control policies with multi-factor authentication
Web application firewall with bot and DDoS mitigation at the network edge
Regular penetration testing and vulnerability assessments
Data stored in SOC 2 compliant cloud infrastructure
Monitoring & Incident Response
Brikl's security team maintains continuous visibility into the platform's health and responds swiftly to any potential threats.
Real-time monitoring and threat detection
Dedicated incident response procedures
Proactive security updates and patching
24/7 automated alerting
Secure Development
Security is built into how we ship software, not bolted on afterward. Automated checks run on every change before it can reach production.
Static, dynamic, and container scanning built into our CI/CD pipeline
Security gates that code must pass before it reaches production
Centralized vulnerability management with remediation SLAs by severity
Every finding tracked from detection through verified remediation
Resilience & Business Continuity
Brikl is engineered to stay available and to recover quickly. Backups and disaster recovery are documented, and regularly tested rather than assumed.
Highly available, redundant infrastructure
Automated, versioned backups of critical data
A formally documented disaster recovery plan, tested twice a year under simulated scenarios
Defined recovery time and recovery point objectives by system criticality
Compliance Framework
Security is not a one-time event. Brikl operates under a comprehensive compliance framework with continuous oversight and improvement.
Comprehensive internal controls and risk management
Regular third-party evaluations
Transparent reporting mechanisms
Continuous improvement initiatives
Questions about our security practices?
Our team is happy to discuss Brikl's security posture, compliance documentation, and how we protect your data.

