European Union region
Managed PostgreSQL database hosted by Supabase in an EU region. No primary storage outside the European Union. Automatic backups and availability replica are also kept in the EU.
Brifay is built to pass a security review with no blind spots: European Union hosting, AES-256 encryption in transit and at rest, strict multi-tenant isolation, granular permissions, exportable audit log, and a French Mistral AI that never learns from your data.a European Mistral AI that never learns from your data.an AI assistant that never learns from your data.
Brifay hosts your maintenance data in the EU, encrypted in AES-256 and isolated multi-tenant, with an exportable audit log. The Brio AI assistant never reuses your data to train any model and remains switchable off by role. GDPR by design: rights of access, erasure, portability and objection from the interface; DPO at [email protected].
Brifay hosts your maintenance data in France and the EU, encrypted in AES-256 and isolated multi-tenant, with an exportable audit log. Brio AI is powered by Mistral, a French model, and never reuses your data. GDPR by design: access, erasure, portability, objection from the interface; DPO at [email protected].
Brifay hosts your maintenance data in the European Union, encrypted in AES-256 and isolated multi-tenant, with an exportable audit log. Brio AI is powered by Mistral, a European model, and never reuses your data. GDPR by design: access, erasure, portability, objection from the interface; DPO at [email protected].
Hosting & infrastructure
The technical foundation is documented, not implied. Here, brick by brick, is the infrastructure hosting your requests, assets, maintenance plans and attachments.
Managed PostgreSQL database hosted by Supabase in an EU region. No primary storage outside the European Union. Automatic backups and availability replica are also kept in the EU.
Data encrypted at rest in AES-256, in transit via mandatory TLS 1.3 (HSTS enabled). Encryption keys are managed by the hosting provider, outside the application instance. Attachments (photos, PDFs) follow the same policy.
Each organisation is isolated at the PostgreSQL Row Level Security (RLS) layer. A malformed query cannot expose another tenant's data — the database itself rejects access. Policy tested by fuzzing at every release.
Daily snapshots retained 7 to 30 days depending on the plan, restorable to a specific point in time (point-in-time recovery down to 2 minutes on Pro and Business plans). Restore tested monthly by the operations team.
Incoming traffic filtered through Cloudflare with EU-priority routing. Active bot management, IP rate limiting, protection against SQL injection and XSS. No dependency on a CDN under non-European jurisdiction for critical resources.
Application errors captured by Sentry (EU region), infrastructure logs retained 30 days. Security incident notification procedure within 72 hours in line with GDPR article 33, sent to the CNIL (French data protection authority) and to the affected organisations.
AI policy
Brifay runs on Mistral, a French model hosted in the EU. No silent fallback to OpenAI, Anthropic or Google. No training on your data. And a kill switch at the role level.Brifay runs on Mistral, a European model hosted in the EU. No silent fallback to OpenAI, Anthropic or Google. No training on your data. And a kill switch at the role level.The Brifay assistant never reuses your data to train a model. Switchable off at organisation or role level.
Brifay runs on Mistral, an artificial intelligence model developed and hosted in France. Inference runs on European endpoints. No provider subject to the CLOUD Act is involved in the product's AI features.
Brifay runs on Mistral, an artificial intelligence model developed and hosted in the European Union. Inference runs on European endpoints. No provider subject to the CLOUD Act is involved in the product's AI features.
The Brifay AI assistant runs inference on dedicated endpoints, isolated from public traffic, and does not use your prompts to retrain a foundation model.
Prompts sent by Brio (request creation, category suggestion, cost estimation, morning briefing) are never used to train any model, internal or third-party. Explicit contractual clause, logged in the processing register.
AI can be disabled for the entire organisation by an administrator, or for a whole role via the permissions matrix. A role whose AI is disabled issues no inference call: zero data sent, zero Brio consumed.
Every AI scenario is documented: what data is sent to the model, what output is expected, what retention applies to inference traces. Available on the Artificial Intelligence page, updated whenever a new Brio ships.
Regulatory source: the European AI Act (regulation 2024/1689) requires transparency for general AI systems from August 2026. Brifay already documents its model, hosting, usage policy and inference endpoints — traceability is in place ahead of the obligation.
GDPR article by article
GDPR is not a promise: it is a list of actionable rights. Here is how each one is delivered, concretely, inside Brifay.
Reference: regulation (EU) 2016/679. To exercise a right outside the interface or ask a DPO question, write to [email protected]. You may lodge a complaint with the CNIL (French data protection authority) if the response does not satisfy you.
Permissions & audit
A system that doesn't trace is a system that doesn't stand up in audit. Brifay applies the principle of least privilege from role creation, and keeps a workable trail for every sensitive action.
Over thirty atomic permissions: asset read, request write, preventive validation, stock management, data export, audit log access, AI configuration. Combinable into custom roles beyond the six standard ones.
Every sensitive action is logged: user ID, UTC timestamp, IP address, action type, target resource, old and new value when relevant. CSV export from the admin interface, default retention 12 months, configurable up to 5 years for regulated sectors (healthcare, defence, energy).
Every admin login is logged. High-impact actions (user deletion, plan change, RBAC change, AI configuration) generate a dedicated audit entry, usable in response to a CNIL inspection or an ISO 27001 review.
Two-factor authentication available via TOTP (Google Authenticator, Authy, 1Password). Organisation policy to enforce 2FA on administrator roles. Sessions remotely revocable from the admin dashboard.
Alignment: Brifay's access management and logging practices align with ISO/IEC 27001:2022 controls (A.5.15, A.8.15, A.8.16) and with CNIL recommendations on traceability.
Subprocessors and transfers
Brifay relies on a limited number of technical subprocessors, all documented. To avoid divergent sources of truth, the list lives in the privacy policy — one file, updated at every change.
The Privacy policy page publishes three exhaustive tables:
Each line shows the role, country of hosting, legal basis for the transfer and the signed DPA. For residual transfers outside the EU, Standard Contractual Clauses and supplementary measures are in place, in line with the CJEU Schrems II ruling (16 July 2020).
Frequently asked questions
The questions we get most in CIO, CISO or DPO reviews. No detours.
No. Brifay runs on Mistral AI, a European model hosted in the European Union. No customer data is transferred to OpenAI, Anthropic, Google or any other provider subject to the US CLOUD Act. Brios (AI calls) are executed on European inference endpoints, and Brifay never uses your data to train any model, internal or third-party.
Yes. The Brifay architecture applies GDPR from the design stage: data minimisation, documented legal basis for each processing activity, up-to-date register, rights of access, rectification, erasure, portability and objection implemented in the application. The DPO is reachable at [email protected]. The full policy and the list of subprocessors are published on /en/privacy.html.
An organisation administrator can delete a user and purge their personal data from the interface in a few clicks. For full account erasure (GDPR article 17), the public procedure is documented at /en/delete-account.html. Any external request sent to [email protected] is processed within 30 days maximum, in line with the legal deadline.
Yes. Brio access is managed by role: you enable or disable the AI assistant per role (administrator, manager, technician…). A role with AI disabled issues no inference call: no data is sent to the model, no Brio is consumed. This granularity supports even the strictest internal AI policies.
Brifay runs on Supabase (managed PostgreSQL) in a European Union region. Network infrastructure, CDN and anti-DDoS are operated by Cloudflare with EU-priority routing. Mistral AI models are also hosted in the EU. The complete, named list of technical subprocessors is published on /en/privacy.html, updated at each change.
No for storage and AI processing: the database, backups and AI inference remain in the EU. A few technical subprocessors (anti-bot, analytics, observability) may process metadata outside the EU under Standard Contractual Clauses with supplementary measures consistent with the Schrems II ruling. Subprocessor-level detail is in the privacy policy.
Yes. All sensitive actions (read, write, delete, permission change, export, admin login) are logged with timestamp, user ID and IP address. The log is viewable from the admin interface and exportable as CSV. Default retention is twelve months, configurable for longer in regulated sectors.
Create a Free account, import a few assets, open the audit log, disable AI for one user, export a user as JSON. Thirty minutes — and you'll have your own conclusion in hand. For DPO questions, write to [email protected].