Separate
Customer Data Architecture
Use customer-specific database architecture where configured to provide database-level separation between customer environments.
Brilliance One Security
Protect business data with customer-specific data separation, authentication, permissions, encryption, session controls, monitoring, audit visibility, and security-conscious platform architecture.
Brilliance One Security provides shared controls across CRM, ERP, CMS, communications, accounting, HR, documents, firearms, point of sale, projects, and the other operational modules using the platform.

Layered Security Architecture
Brilliance One combines data separation, credential protection, authentication, authorization, encryption, session handling, logging, monitoring, and administrative controls as layers of a broader security model.
Separate
Use customer-specific database architecture where configured to provide database-level separation between customer environments.
Control
Use authentication, roles, permissions, security groups, module access, session controls, and administrative rules to help determine who can access protected functionality and information.
Observe
Maintain supported access, administrative, security, and operational activity to provide additional context when investigating important events or changes.
Defense in Layers
Stronger platform security comes from multiple controls working together across the data, identity, application, session, administrative, and operational layers.
Layered Security
Database separation does not replace application security. Encryption does not replace permissions. Authentication does not replace session controls. Logging does not replace prevention.
Brilliance One is designed around multiple security layers that address different parts of the risk.
Data Separation
Brilliance One can use customer-specific database architecture to provide database-level separation rather than relying exclusively on tenant identifiers inside one shared customer-data store.
Customer Isolation
Customer-specific databases can reduce certain classes of shared-database exposure by maintaining data separation at the database layer.
That separation remains only one part of the overall security model. Application access, credentials, configuration, infrastructure, permissions, monitoring, and administration remain important.
Authentication
Authentication helps establish that a request belongs to an expected user before authorization determines which information and functionality that user may access.
Passwords
Brilliance One uses Argon2id password hashing with unique salts and additional application-level protection to help defend stored credentials against offline attacks.
Multi-Factor
Where enabled, multi-factor authentication provides another verification requirement beyond the primary account credential.
Protection
Account lockout, rate limiting, credential checks, and other supported controls help reduce exposure to repeated or automated unauthorized-access attempts.
Credential Security
Brilliance One uses modern password-hashing practices designed to make captured credential databases more difficult to attack than databases containing plaintext or reversibly encrypted passwords.
Password Design
Password hashing allows authentication to verify credentials without storing the original password in readable form.
Additional controls around authentication help address risks that password storage alone cannot solve.
Authorization
Successfully signing in should not automatically provide access to every customer, employee, financial, administrative, operational, or industry-specific record in the platform.
Least Necessary Access
A salesperson, accountant, HR administrator, project manager, firearms employee, customer-service representative, and system administrator may all use the same platform while requiring different access.
Brilliance One's permission model helps organizations separate those responsibilities instead of assuming every authenticated user should see everything.
Module-Aware Security
A connected platform can contain information with very different access requirements. Security controls should reflect the sensitivity and responsibility associated with each business area.
CRM
Control appropriate access to accounts, contacts, leads, communication history, customer records, and relationship information.
Accounting
Restrict access to appropriate financial, payment, banking, accounting, vendor, and reporting information according to responsibility.
Human Resources
Use permission-aware controls around employee records, HR documents, reviews, leave, training, and other sensitive workforce information.
Firearms
Apply appropriate access controls around FFL records, serialized inventory, e4473 workflows, bound-book activity, corrections, and supporting documentation.
Documents
Use appropriate document access controls so files can remain connected with business records without automatically becoming visible to every user.
Administration
Limit sensitive configuration, user, security, licensing, integration, and administrative functionality to appropriately authorized personnel.
Encryption & Data Protection
Brilliance One can apply encryption and secure-transport controls to appropriate data, credentials, secrets, and application communication while keeping access governed by authentication and authorization.
Stored Data
Apply supported encryption to sensitive stored information where the data model and workflow require additional protection.
Transport
Use secure transport for supported application, API, browser, and service communication to help protect data while it moves between systems.
Secrets
Protect appropriate API credentials, application secrets, tokens, service credentials, and sensitive configuration through dedicated security workflows.
Application Security
Data also moves through browsers, APIs, services, authentication endpoints, embedded experiences, integrations, and other application surfaces that require their own security controls.
Application Layer
Application security also depends on how users authenticate, how APIs authorize requests, how sessions are handled, how browsers connect, how inputs are validated, and how sensitive administrative functionality is protected.
Session Security
Authentication establishes identity at login. Session controls help determine whether ongoing requests should continue to be treated as part of an authorized authenticated session.
Ongoing Access
Session expiration, validation, authorization checks, and other controls help reduce the risk created by abandoned, stolen, shared, or otherwise compromised authenticated sessions.
Abuse Protection
Rate limits and request controls can help reduce repeated automated attempts against login, shared, public, API, and other sensitive application surfaces.
Authentication
Apply supported limits and account-security controls to reduce repeated authentication attempts against user accounts.
APIs
Apply appropriate rate-limiting policies to authenticated, shared, or public endpoints according to the sensitivity and use case.
Monitoring
Use available request and authentication information to identify patterns that may warrant defensive action or administrative review.
Monitoring
Security monitoring can provide additional context around failed access attempts, unusual behavior, rate-limit activity, account protection events, and other security-relevant application behavior.
Review supported failed login and authentication activity that may warrant investigation.
Use available rate-limit and request information to identify excessive or potentially abusive behavior.
Maintain appropriate context around lockouts and other supported account-security events.
Provide authorized administrators with visibility into important platform and security activity.
Use available security and operational signals to provide context when application behavior requires investigation.
Use logged activity as one source of evidence when investigating access, configuration, user, or application concerns.
Audit Visibility
Supported security, administrative, configuration, automation, module, and operational logs can help authorized users understand important activity that occurred throughout the platform.
Accountability
Audit and operational history can help organizations investigate important changes, understand administrative actions, review security events, and support broader governance procedures.
Logging provides evidence and context. It does not replace prevention, monitoring, access control, or good administration.
API Security
Brilliance One's API-first architecture still requires supported endpoints to apply appropriate authentication, authorization, validation, rate limiting, and business rules according to how each endpoint is intended to be used.
Secure Extensibility
APIs make it easier to extend business capabilities across websites, portals, applications, and integrations.
Those same interfaces need intentional access controls so exposing capability does not mean exposing unrestricted data or actions.
Deployment Architecture
Brilliance One can support deployment and data-isolation approaches intended for organizations with different security, control, operational, privacy, and infrastructure requirements.
Managed
Use Brilliance One through a managed platform environment with the underlying application infrastructure operated as part of the service.
Data
Use customer-specific database architecture where configured to provide database-level separation of tenant business information.
Specialized
Organizations with specialized infrastructure requirements can discuss available deployment and customer-specific architecture options with Brilliance One.
Security Controls
Brilliance One combines multiple controls across different parts of the platform rather than treating any single mechanism as complete security.
Identity
Use protected credentials, multi-factor authentication where enabled, login controls, account protection, and session validation.
Access
Limit supported records, modules, administrative functionality, and actions according to roles, permissions, security groups, and responsibility.
Data
Combine customer-specific database architecture with appropriate encryption and application-level controls around sensitive information.
Application
Use secure transport, protected APIs, request validation, authentication, authorization, and rate limiting across supported application surfaces.
Activity
Maintain visibility into supported access, application, account, and security events that may require investigation.
Accountability
Preserve appropriate administrative, configuration, access, module, and security history for authorized review.
Security + Compliance
Organizations may use Brilliance One in environments affected by privacy, healthcare, payment, contractual, government, industry, or organizational security requirements.
Compliance-Aware Architecture
Brilliance One can provide technical controls that help organizations implement security and governance requirements across supported workflows.
Customers remain responsible for determining which laws, regulations, contractual standards, certifications, policies, and operational safeguards apply to their organization.
Shared Responsibility
Platform controls can reduce risk, but security also depends on how organizations manage users, devices, credentials, permissions, integrations, policies, retention, training, and incident response.
Security Is a Process
Brilliance One provides security capabilities and architecture that organizations can incorporate into their broader security program.
Customers should configure those controls appropriately and maintain their own policies, procedures, training, endpoint protection, identity management, integration security, and incident-response practices.
Platform Security Strategy
Established customer platforms already provide mature authentication, permissions, encryption, logging, security programs, and administrative controls. Brilliance One applies its security foundation across a broader combination of customer, financial, workforce, document, commerce, industry, and operational workflows.
Customer
Apply identity, access, data, and logging controls to customer records, contacts, communications, leads, and relationship history.
Business
Extend security controls into accounting, employees, projects, inventory, documents, scheduling, commerce, and other operational workflows.
Specialized
Apply the broader platform security model to specialized records such as firearms, drug testing, courses, and other industry or regulatory workflows.
Brilliance One Core
Core provides the relationship, communication, automation, identity, security, configuration, and administrative capabilities that support the broader Brilliance One Business Operating System.
CRM & Relationships
Manage customers, prospects, leads, organizations, contacts, vendors, suppliers, partners, and relationship history through one connected business record.
Explore AccountsLocations
Maintain billing, shipping, service, customer, employee, vendor, job-site, and operational locations as reusable records connected to the business activity that depends on them.
Explore AddressesEmail, SMS & Messaging
Connect email, SMS, MMS, campaigns, templates, lists, replies, delivery activity, and communication history with the customers and business records behind every conversation.
Explore CommunicationsWorkflow Automation
Automate supported email, SMS, tagging, notifications, delays, follow-up, and repeatable processes so people can focus on decisions while software handles routine work.
Explore AutomationsIdentity & Access
Manage identities, roles, permissions, security groups, profiles, account relationships, module access, authentication, and operational responsibilities across Brilliance One.
Explore UsersPlatform Protection
Protect business information with authentication, authorization, roles, permissions, security groups, encryption, session controls, logging, monitoring, and administrative safeguards.
Explore SecurityPlatform Configuration
Configure organization defaults, branding, permissions, communication providers, payment services, AI preferences, integrations, module behavior, and shared platform settings.
Explore SettingsData Operations
Import, export, map, validate, review, migrate, clean, and maintain supported business information with administrative workflows designed for controlled data operations.
Explore ToolsBrilliance One Security
Use customer-specific data architecture, authentication, permissions, credential protection, encryption, secure application communication, session controls, rate limiting, monitoring, and audit visibility as shared security layers across the Brilliance One Business Operating System.
Brilliance One • Security • Data Separation • Access Control • Audit Visibility