Skip to content
Brand254
Trust

Security, stated without theatre

An intelligence product should be boring about security. This page lists practices we intend to operate — and the certifications we will not invent.

What this product processes

Brand254 processes customer account data and public (or otherwise lawfully accessible) listening data that customers configure. We do not present private inbox interception, closed WhatsApp groups, or “all of the internet” as a capability.

Controls we intend to run

  • HTTPS for the website and, when live, the application.
  • Encryption in transit for API traffic.
  • Least-privilege access to production systems and customer workspaces.
  • Authentication and, on Enterprise, SSO as a contracted capability.
  • Logging and backup practices appropriate to a SaaS workspace.
  • Processor contracts with infrastructure and, if used, model providers.

What we will not claim yet

We do not list SOC 2, ISO 27001, penetration-test logos or uptime percentages on this page because those artefacts are not published here. When they exist, they should be linked with dates, not implied by a badge pack.

Vulnerability reports

If you believe you have found a security issue in the public website or product, email [email protected] with enough detail to reproduce it. Do not include customer data in the report.