Trust centre

The answers your procurement team is about to ask for.

Every enterprise engagement begins with the same security questionnaire. Rather than answer it forty times a year, we publish the answers here, including the questions where the honest answer is that we do not hold that certification yet.

ISO
9001

Certified

Quality management, 2015 revision, reassessed on its published cycle.

CMMI
L4

Appraised

Quantitatively managed. Process performance is measured, not asserted.

SOC 2

In progress

Type II readiness underway. We will not claim it before the report exists.

24h

Disclosure response

Acknowledgement of any reported vulnerability, inside one business day.

The questionnaire

Twelve questions we get every time, answered once.

Where is our data processed?

In the region you specify, on infrastructure you can name in the contract. We do not move client data between regions for operational convenience.

Who on your side can access it?

Only engineers assigned to your engagement, through named accounts with multi-factor authentication. Access is granted for the engagement and revoked at handover, and the grant and revocation are both logged.

Do you use client data to train models?

No. Never, on any engagement, under any arrangement. Where a model is involved, the boundary is agreed in writing before work starts.

What are your subprocessors?

A short list, disclosed in full before contract, with the function each performs. We tell you before it changes rather than after.

How do you handle secrets?

In a managed secret store, never in the repository, never in a ticket, never in a message. Rotation is automated and credentials issued to us are scoped to the minimum required.

What is your vulnerability process?

Dependencies are scanned continuously and critical findings are patched inside 72 hours. Anything we cannot patch is reported to you with the mitigation in place.

Do you carry insurance?

Professional indemnity and cyber liability, with certificates available on request during procurement.

What happens if you have a breach?

You are notified within 24 hours of confirmation, with what we know, what we do not yet know, and what we are doing. We do not wait for a complete picture before telling you.

Can we audit you?

Yes. Client security reviews are part of enterprise engagements and we will complete your questionnaire, take the call and host the review.

What about the engineering floor in Pakistan?

Same controls, same named accounts, same logging. Location does not change the access model, and we will say plainly which team members are where.

Do you subcontract?

No. Every engineer is salaried and permanent. There is no contractor bench and no undisclosed third party writing your code.

What happens to our data when we leave?

Deleted on a schedule agreed in the contract, with written confirmation. Backups age out on their documented cycle and we tell you what that cycle is.

AI data policy

The part most vendors are vague about.

What we commit to

  • Client code and data are never used to train any model, ours or a vendor’s.
  • Model providers are named in the contract, with their data retention terms attached.
  • Where you require it, we work with zero-retention endpoints and say so in writing.
  • Anything a model contributed to is reviewed and approved by a named engineer before it merges.

What you decide

  • Whether AI-assisted delivery is used on your engagement at all. Some clients say no, and the price changes accordingly.
  • Which classes of data may leave your environment, if any.
  • Which providers are acceptable to you, including the option of a self-hosted model.
  • Whether generated contributions must be labelled in the codebase for your own audit.

Report a vulnerability

If you have found something in our systems or in software we built, tell us. Acknowledged within one business day, and we will not threaten you for it.

hello@brilliantsystems.io
Red patch cables connected into a network switch

Next step

Talk to the engineer who would run your build.

No discovery call with a salesperson, no deck. A senior engineer reads what you send and replies with a real assessment, including when we think you shouldn’t build it.

Tell us what you’re building

We reply within one business day. No sales sequence, no newsletter.

Certified, partnered and awarded