01 // POSTURE
Security overview
TLS 1.2+ everywhere, AES-GCM column encryption for PHI/PII, signed Stripe webhooks, hardware-key MFA for engineering access.
READ →00_TRUST // CONSOLIDATED_HUB
Security, privacy, compliance, subprocessors, and incident response — every public document we maintain, in one index. We document what we actually run, including the gaps. No cert theatre.
UPDATED CONTINUOUSLY // CHANGELOG AT /CHANGELOG // VULN REPORTS WELCOME
01 // POSTURE
TLS 1.2+ everywhere, AES-GCM column encryption for PHI/PII, signed Stripe webhooks, hardware-key MFA for engineering access.
READ →02 // VENDORS
Every third-party that touches customer data, with BAA and DPA status per vendor. Updated within 30 days of any change.
READ →03 // PRIVACY
What we collect, why we collect it, how long we keep it, and how to delete it. GDPR and CCPA aware. No dark patterns.
READ →04 // CHOICE
Honors Global Privacy Control (GPC). Granular consent, no pre-ticked boxes, and a real reject-all that actually rejects.
MANAGE →05 // COMPLIANCE
Per-product compliance pages — HIPAA-aware products document PHI handling, BAA execution, and data-flow boundaries.
READ →06 // STATUS
Live health endpoint and the IR runbook (sev classification, comms template, evidence preservation, customer-notification timing).
STATUS →07_PRINCIPLES // ENGINEERING_DEFAULTS
REPORT A VULN // SECURITY@BRAINIACSTECHSOLUTIONS.COM