BrizoConsol is built for finance teams handling sensitive group financial data. Here is exactly how we protect it — no marketing claims, just the facts.
Every layer is designed with security as a first principle, from login to data storage to payments.
2FA enforced for all customer logins. Internally, 2FA is also mandated across cloud infrastructure, code repositories, email, and all admin tooling.
All data encrypted in transit via SSL at all times.
Sensitive data fields encrypted at rest using AES-256-CBC at the application layer. Unreadable without proper authorisation.
Control who can view, edit, or export data per user and entity. Manage access without support.
Card details never stored. All payment processing handled by Stripe PCI DSS Level 1.
Delete company removes all data, tokens, and records immediately and permanently.
Hosted exclusively on Akamai Linode — infrastructure independently audited and certified to industry standards.
Infrastructure hosted exclusively on Akamai Linode — SOC 2 Type II and ISO 27001 certified. BrizoConsol's operations benefit from Akamai's independently audited security posture, not our own SOC claim.
Three rotating backups (daily, weekly, bi-weekly) with a 24-hour Recovery Point Objective (RPO). Your data can be restored to within 24 hours of any incident.
Continuous scanning via Aikido Security. Critical vulnerabilities patched within 14 days; high-severity within 30 days. Patches tracked to closure.
Built to support compliance under strict regulatory requirements.
Every change logged with timestamp and user ID. Full visibility for auditors and compliance.
Financial data never sold, shared, or used outside BrizoConsol service provision.
Set view-only, edit, or admin access per user and entity without exposing sensitive data.
Found a vulnerability? Contact info@brizosystem.com — 48-hour response.
Sessions time out on inactivity, prompting re-authentication to prevent unattended access.
OAuth tokens encrypted and scoped to read-only. Revoked instantly when connection removed.
In the event of a confirmed data breach, affected customers are notified within 72 hours — aligned with GDPR and PDPA obligations.
All credentials, system access, and admin permissions are revoked within 24 hours of staff offboarding — no residual access.
Your data is in safe hands from day one.