French Mistral AI · GDPR by design European AI · GDPR-compliant Enterprise-grade security · audit log

Security, GDPR and sovereign AI: the technical documentation for CIOs, CISOs and DPOs.

Brifay is built to pass a security review with no blind spots: European Union hosting, AES-256 encryption in transit and at rest, strict multi-tenant isolation, granular permissions, exportable audit log, and a French Mistral AI that never learns from your data.a European Mistral AI that never learns from your data.an AI assistant that never learns from your data.

Hosted in the EU GDPR by design AES-256 · TLS 1.3 Exportable audit log

Brifay hosts your maintenance data in the EU, encrypted in AES-256 and isolated multi-tenant, with an exportable audit log. The Brio AI assistant never reuses your data to train any model and remains switchable off by role. GDPR by design: rights of access, erasure, portability and objection from the interface; DPO at [email protected].

Brifay hosts your maintenance data in France and the EU, encrypted in AES-256 and isolated multi-tenant, with an exportable audit log. Brio AI is powered by Mistral, a French model, and never reuses your data. GDPR by design: access, erasure, portability, objection from the interface; DPO at [email protected].

Brifay hosts your maintenance data in the European Union, encrypted in AES-256 and isolated multi-tenant, with an exportable audit log. Brio AI is powered by Mistral, a European model, and never reuses your data. GDPR by design: access, erasure, portability, objection from the interface; DPO at [email protected].

Hosting & infrastructure

Where your data lives, how it is protected.

The technical foundation is documented, not implied. Here, brick by brick, is the infrastructure hosting your requests, assets, maintenance plans and attachments.

European Union region

Managed PostgreSQL database hosted by Supabase in an EU region. No primary storage outside the European Union. Automatic backups and availability replica are also kept in the EU.

AES-256 encryption + TLS 1.3

Data encrypted at rest in AES-256, in transit via mandatory TLS 1.3 (HSTS enabled). Encryption keys are managed by the hosting provider, outside the application instance. Attachments (photos, PDFs) follow the same policy.

Strict multi-tenant isolation

Each organisation is isolated at the PostgreSQL Row Level Security (RLS) layer. A malformed query cannot expose another tenant's data — the database itself rejects access. Policy tested by fuzzing at every release.

Daily automatic backups

Daily snapshots retained 7 to 30 days depending on the plan, restorable to a specific point in time (point-in-time recovery down to 2 minutes on Pro and Business plans). Restore tested monthly by the operations team.

Anti-DDoS & WAF Cloudflare EU

Incoming traffic filtered through Cloudflare with EU-priority routing. Active bot management, IP rate limiting, protection against SQL injection and XSS. No dependency on a CDN under non-European jurisdiction for critical resources.

Observability and incidents

Application errors captured by Sentry (EU region), infrastructure logs retained 30 days. Security incident notification procedure within 72 hours in line with GDPR article 33, sent to the CNIL (French data protection authority) and to the affected organisations.

AI policy

A French AI that stays in its lane.A European AI that stays in its lane.An embedded AI that stays in its lane.

Brifay runs on Mistral, a French model hosted in the EU. No silent fallback to OpenAI, Anthropic or Google. No training on your data. And a kill switch at the role level.Brifay runs on Mistral, a European model hosted in the EU. No silent fallback to OpenAI, Anthropic or Google. No training on your data. And a kill switch at the role level.The Brifay assistant never reuses your data to train a model. Switchable off at organisation or role level.

French Mistral modelEuropean Mistral modelTargeted inference model

Brifay runs on Mistral, an artificial intelligence model developed and hosted in France. Inference runs on European endpoints. No provider subject to the CLOUD Act is involved in the product's AI features.

Brifay runs on Mistral, an artificial intelligence model developed and hosted in the European Union. Inference runs on European endpoints. No provider subject to the CLOUD Act is involved in the product's AI features.

The Brifay AI assistant runs inference on dedicated endpoints, isolated from public traffic, and does not use your prompts to retrain a foundation model.

No training on your data

Prompts sent by Brio (request creation, category suggestion, cost estimation, morning briefing) are never used to train any model, internal or third-party. Explicit contractual clause, logged in the processing register.

Switchable off by role

AI can be disabled for the entire organisation by an administrator, or for a whole role via the permissions matrix. A role whose AI is disabled issues no inference call: zero data sent, zero Brio consumed.

Explicit Brios scope

Every AI scenario is documented: what data is sent to the model, what output is expected, what retention applies to inference traces. Available on the Artificial Intelligence page, updated whenever a new Brio ships.

Regulatory source: the European AI Act (regulation 2024/1689) requires transparency for general AI systems from August 2026. Brifay already documents its model, hosting, usage policy and inference endpoints — traceability is in place ahead of the obligation.

GDPR article by article

Your users' rights, implemented in the product.

GDPR is not a promise: it is a list of actionable rights. Here is how each one is delivered, concretely, inside Brifay.

GDPR right Mechanism in Brifay Deadline
Article 15 — Right of access JSON export of user data from the admin interface. Exhaustive list of personal fields, activities, Brios consumed. Immediate
Article 16 — Rectification The user edits their profile themselves. The admin can step in if the person no longer has access to their account. Immediate
Article 17 — Erasure User deletion by the admin (purge of personal data, anonymisation of historical contributions). Public procedure at /en/delete-account.html. 30 days max
Article 20 — Portability Full organisation export in JSON and CSV: assets, requests, preventive plans, users, files. Open, reusable format. ≤ 7 days
Article 21 — Objection AI disabled by role (zero inference calls). One-click marketing unsubscribe (List-Unsubscribe header). Immediate
Article 30 — Register Processing register maintained by the Brifay DPO, shareable on motivated request (customer internal audit, CNIL inspection). ≤ 30 days
Article 33 — Breach notification Procedure in place: CNIL (French data protection authority) notification and communication to affected organisations within 72 hours of detection. 72 hours

Reference: regulation (EU) 2016/679. To exercise a right outside the interface or ask a DPO question, write to [email protected]. You may lodge a complaint with the CNIL (French data protection authority) if the response does not satisfy you.

Permissions & audit

Who can do what, and who did it when.

A system that doesn't trace is a system that doesn't stand up in audit. Brifay applies the principle of least privilege from role creation, and keeps a workable trail for every sensitive action.

Granular RBAC — 30+ permissions

Over thirty atomic permissions: asset read, request write, preventive validation, stock management, data export, audit log access, AI configuration. Combinable into custom roles beyond the six standard ones.

Exportable CSV audit log

Every sensitive action is logged: user ID, UTC timestamp, IP address, action type, target resource, old and new value when relevant. CSV export from the admin interface, default retention 12 months, configurable up to 5 years for regulated sectors (healthcare, defence, energy).

Admin access traceability

Every admin login is logged. High-impact actions (user deletion, plan change, RBAC change, AI configuration) generate a dedicated audit entry, usable in response to a CNIL inspection or an ISO 27001 review.

Strong authentication (2FA)

Two-factor authentication available via TOTP (Google Authenticator, Authy, 1Password). Organisation policy to enforce 2FA on administrator roles. Sessions remotely revocable from the admin dashboard.

Alignment: Brifay's access management and logging practices align with ISO/IEC 27001:2022 controls (A.5.15, A.8.15, A.8.16) and with CNIL recommendations on traceability.

Subprocessors and transfers

The up-to-date list, in one place.

Brifay relies on a limited number of technical subprocessors, all documented. To avoid divergent sources of truth, the list lives in the privacy policy — one file, updated at every change.

The Privacy policy page publishes three exhaustive tables:

  • Hosting & infrastructure subprocessors (database, CDN, observability)
  • Communication & marketing subprocessors (transactional and marketing email)
  • Product operations subprocessors (payment, support, analytics)

Each line shows the role, country of hosting, legal basis for the transfer and the signed DPA. For residual transfers outside the EU, Standard Contractual Clauses and supplementary measures are in place, in line with the CJEU Schrems II ruling (16 July 2020).

Frequently asked questions

Seven answers to pass the security review.

The questions we get most in CIO, CISO or DPO reviews. No detours.

Can my data be read by a US AI model?

No. Brifay runs on Mistral AI, a European model hosted in the European Union. No customer data is transferred to OpenAI, Anthropic, Google or any other provider subject to the US CLOUD Act. Brios (AI calls) are executed on European inference endpoints, and Brifay never uses your data to train any model, internal or third-party.

Is Brifay GDPR by design?

Yes. The Brifay architecture applies GDPR from the design stage: data minimisation, documented legal basis for each processing activity, up-to-date register, rights of access, rectification, erasure, portability and objection implemented in the application. The DPO is reachable at [email protected]. The full policy and the list of subprocessors are published on /en/privacy.html.

How do I exercise a right to erasure on Brifay?

An organisation administrator can delete a user and purge their personal data from the interface in a few clicks. For full account erasure (GDPR article 17), the public procedure is documented at /en/delete-account.html. Any external request sent to [email protected] is processed within 30 days maximum, in line with the legal deadline.

Can AI be disabled for part of the team?

Yes. Brio access is managed by role: you enable or disable the AI assistant per role (administrator, manager, technician…). A role with AI disabled issues no inference call: no data is sent to the model, no Brio is consumed. This granularity supports even the strictest internal AI policies.

Who hosts Brifay?

Brifay runs on Supabase (managed PostgreSQL) in a European Union region. Network infrastructure, CDN and anti-DDoS are operated by Cloudflare with EU-priority routing. Mistral AI models are also hosted in the EU. The complete, named list of technical subprocessors is published on /en/privacy.html, updated at each change.

Can my data leave the European Union?

No for storage and AI processing: the database, backups and AI inference remain in the EU. A few technical subprocessors (anti-bot, analytics, observability) may process metadata outside the EU under Standard Contractual Clauses with supplementary measures consistent with the Schrems II ruling. Subprocessor-level detail is in the privacy policy.

Does Brifay maintain an exportable audit log?

Yes. All sensitive actions (read, write, delete, permission change, export, admin login) are logged with timestamp, user ID and IP address. The log is viewable from the admin interface and exportable as CSV. Default retention is twelve months, configurable for longer in regulated sectors.

The most honest security test is your own.

Create a Free account, import a few assets, open the audit log, disable AI for one user, export a user as JSON. Thirty minutes — and you'll have your own conclusion in hand. For DPO questions, write to [email protected].