1. Security objectives
BREAIX treats security as a condition of trustworthy operations: information should be available to authorized people when needed, protected from unauthorized disclosure and kept accurate enough to support the decision that depends on it.
Controls are selected according to the sensitivity of the information, the role of the participant, the threat model and the impact of a failure. The final policy will be aligned to the actual production architecture and contractual commitments in force at publication.
2. Access, identity and data protection
Access should be granted according to role and operational need, reviewed when responsibilities change and removed when the relationship ends. Authentication, session protection, permission boundaries and audit records work together; no single control is treated as sufficient on its own.
Data should be protected in transit and at rest using measures appropriate to the environment. Sensitive documents should not be copied to personal accounts, shared through unapproved channels or made public merely to make a workflow faster.
- Least privilege for users, services and administrators.
- Separation of duties for sensitive approval and administrative actions.
- Logging of security-relevant actions with controlled access to the logs.
- Backups and recovery procedures tested according to the service's actual risk profile.
3. Vendors, changes and testing
Service providers that can access BREAIX systems or data should be selected, contracted and reviewed according to the access and risk they create. Their responsibilities should be clear before production data is introduced.
Changes to code, infrastructure, permissions and integrations should follow a controlled process that includes review, testing, monitoring and rollback where appropriate. Security testing should be proportionate to the affected surface and findings should be tracked to closure or an accepted risk decision.
4. Reporting and response
A suspected vulnerability, exposed credential, phishing attempt, unauthorized disclosure or suspicious account event should be reported promptly through the BREAIX contact channel. Do not exploit a suspected weakness, access another user's data or publish evidence containing personal or confidential information.
BREAIX will assess, contain, investigate, recover and learn from incidents. When personal data is involved, the responsible party will evaluate notification and cooperation duties under the applicable law and agreements. A vulnerability report is not itself proof that an incident occurred.
