Security & reliability

Serious Infrastructure, Built To Be Trusted.

You are handing BrainDesk read access to your customer data and your billing history. Here is exactly how that access is protected — and what we do not claim.

Encryption in transit and at rest

HTTPS everywhere. OAuth tokens, database credentials, and Stripe keys are encrypted at rest and never exposed to the browser.

Password hashing

Account passwords are hashed with bcrypt. Plaintext credentials are never stored or logged.

Server-side RBAC

Super Admin, Support Lead, and Agent permissions are enforced on every request server-side — the UI is a convenience, not the control.

Rate limiting

Authentication, widget, and API endpoints are rate limited to blunt brute-force and abuse.

99.5% uptime target

Monitored continuously, with error tracking and alerting wired in from day one.

Automated daily backups

Database backups run daily with restore procedures documented and tested.

Graceful degradation

If one product’s database or mailbox is unreachable, that product degrades in isolation — every other product keeps working.

Immutable audit logging

Every action on a ticket — approval, edit, rejection, escalation, resolution — is appended to a log that cannot be edited after the fact.

What We Do Not Claim.

We state only the certifications and compliance we actually hold. If a certification is not listed on this page, we do not have it.

GDPR data export and deletion tooling is on the roadmap, per the product spec. Teams with an EU rollout should confirm current status with us before signing.

Request the current security overview →

Infrastructure your operators can trust.

Read-only by default, encrypted throughout, and auditable end to end.

Get Started See how it works