Brilliance One Security

Security belongs at the foundation.

Protect business data with customer-specific data separation, authentication, permissions, encryption, session controls, monitoring, audit visibility, and security-conscious platform architecture.

Brilliance One Security provides shared controls across CRM, ERP, CMS, communications, accounting, HR, documents, firearms, point of sale, projects, and the other operational modules using the platform.

Data Separation • Authentication • Permissions • Encryption • Audit Visibility
Brilliance One business software security architecture authentication permissions encryption and audit controls

Layered Security Architecture

Protect the platform with more than one control.

Brilliance One combines data separation, credential protection, authentication, authorization, encryption, session handling, logging, monitoring, and administrative controls as layers of a broader security model.

Separate

Customer Data Architecture

Use customer-specific database architecture where configured to provide database-level separation between customer environments.

Control

Identity & Access

Use authentication, roles, permissions, security groups, module access, session controls, and administrative rules to help determine who can access protected functionality and information.

Observe

Logging & Monitoring

Maintain supported access, administrative, security, and operational activity to provide additional context when investigating important events or changes.

Defense in Layers

No single security control should carry the entire responsibility.

Stronger platform security comes from multiple controls working together across the data, identity, application, session, administrative, and operational layers.

  • Separate customer data
  • Verify user identity
  • Limit access by responsibility
  • Protect sensitive information
  • Secure application communication
  • Protect credentials and secrets
  • Control active sessions
  • Rate-limit sensitive endpoints
  • Record important activity
  • Monitor for suspicious behavior

Layered Security

Security is stronger when one failed control does not automatically expose everything behind it.

Database separation does not replace application security. Encryption does not replace permissions. Authentication does not replace session controls. Logging does not replace prevention.

Brilliance One is designed around multiple security layers that address different parts of the risk.

Data Separation

Shared software does not require one shared customer database.

Brilliance One can use customer-specific database architecture to provide database-level separation rather than relying exclusively on tenant identifiers inside one shared customer-data store.

  • Customer-specific databases
  • Database-level tenant separation
  • Customer-specific configuration
  • Controlled application access
  • Authentication and authorization
  • Module-level security
  • Operational logging
  • Infrastructure controls

Customer Isolation

A tenant identifier does not have to be the only boundary between customers.

Customer-specific databases can reduce certain classes of shared-database exposure by maintaining data separation at the database layer.

That separation remains only one part of the overall security model. Application access, credentials, configuration, infrastructure, permissions, monitoring, and administration remain important.

Authentication

Verify identity before granting access.

Authentication helps establish that a request belongs to an expected user before authorization determines which information and functionality that user may access.

Passwords

Argon2id Credential Protection

Brilliance One uses Argon2id password hashing with unique salts and additional application-level protection to help defend stored credentials against offline attacks.

Multi-Factor

Additional Verification

Where enabled, multi-factor authentication provides another verification requirement beyond the primary account credential.

Protection

Login Controls

Account lockout, rate limiting, credential checks, and other supported controls help reduce exposure to repeated or automated unauthorized-access attempts.

Credential Security

Passwords should be verified. Not stored as readable secrets.

Brilliance One uses modern password-hashing practices designed to make captured credential databases more difficult to attack than databases containing plaintext or reversibly encrypted passwords.

  • Argon2id password hashing
  • Unique password salts
  • Application-level pepper protection
  • Compromised-password screening where supported
  • Login rate limiting
  • Account lockout controls
  • Multi-factor authentication
  • Secure password-validation workflow

Password Design

The application should not need to know the user's original password.

Password hashing allows authentication to verify credentials without storing the original password in readable form.

Additional controls around authentication help address risks that password storage alone cannot solve.

Authorization

Authentication answers who. Authorization answers what.

Successfully signing in should not automatically provide access to every customer, employee, financial, administrative, operational, or industry-specific record in the platform.

  • Roles
  • Permissions
  • Security groups
  • Module access
  • Record access
  • Administrative privileges
  • Sensitive actions
  • Business responsibilities
  • Permission-aware workflows

Least Necessary Access

Access should follow responsibility.

A salesperson, accountant, HR administrator, project manager, firearms employee, customer-service representative, and system administrator may all use the same platform while requiring different access.

Brilliance One's permission model helps organizations separate those responsibilities instead of assuming every authenticated user should see everything.

Module-Aware Security

One platform. Different levels of sensitivity.

A connected platform can contain information with very different access requirements. Security controls should reflect the sensitivity and responsibility associated with each business area.

CRM

Customer Information

Control appropriate access to accounts, contacts, leads, communication history, customer records, and relationship information.

Accounting

Financial Information

Restrict access to appropriate financial, payment, banking, accounting, vendor, and reporting information according to responsibility.

Human Resources

Workforce Information

Use permission-aware controls around employee records, HR documents, reviews, leave, training, and other sensitive workforce information.

Firearms

Regulated Records

Apply appropriate access controls around FFL records, serialized inventory, e4473 workflows, bound-book activity, corrections, and supporting documentation.

Documents

Sensitive Files

Use appropriate document access controls so files can remain connected with business records without automatically becoming visible to every user.

Administration

Privileged Actions

Limit sensitive configuration, user, security, licensing, integration, and administrative functionality to appropriately authorized personnel.

Encryption & Data Protection

Protect sensitive information at the appropriate layers.

Brilliance One can apply encryption and secure-transport controls to appropriate data, credentials, secrets, and application communication while keeping access governed by authentication and authorization.

Stored Data

Sensitive Field Protection

Apply supported encryption to sensitive stored information where the data model and workflow require additional protection.

Transport

Protected Connections

Use secure transport for supported application, API, browser, and service communication to help protect data while it moves between systems.

Secrets

Credentials, Keys & Tokens

Protect appropriate API credentials, application secrets, tokens, service credentials, and sensitive configuration through dedicated security workflows.

Application Security

Protect more than the database.

Data also moves through browsers, APIs, services, authentication endpoints, embedded experiences, integrations, and other application surfaces that require their own security controls.

  • TLS-protected connections
  • HTTPS enforcement
  • HSTS where configured
  • Content Security Policy controls
  • Protected API endpoints
  • Authentication requirements
  • Authorization enforcement
  • Rate limiting
  • Request validation
  • Secure application configuration

Application Layer

A protected database does not automatically make an application secure.

Application security also depends on how users authenticate, how APIs authorize requests, how sessions are handled, how browsers connect, how inputs are validated, and how sensitive administrative functionality is protected.

Session Security

Protect access after the login succeeds.

Authentication establishes identity at login. Session controls help determine whether ongoing requests should continue to be treated as part of an authorized authenticated session.

  • Session validation
  • Token validation
  • Authentication state
  • Automatic expiration
  • Timeout controls
  • Contextual checks
  • Protected endpoints
  • Authorization enforcement

Ongoing Access

A successful login should not imply unlimited permanent access.

Session expiration, validation, authorization checks, and other controls help reduce the risk created by abandoned, stolen, shared, or otherwise compromised authenticated sessions.

Abuse Protection

Valid endpoints can still be abused.

Rate limits and request controls can help reduce repeated automated attempts against login, shared, public, API, and other sensitive application surfaces.

Authentication

Login Protection

Apply supported limits and account-security controls to reduce repeated authentication attempts against user accounts.

APIs

Endpoint Protection

Apply appropriate rate-limiting policies to authenticated, shared, or public endpoints according to the sensitivity and use case.

Monitoring

Repeated Activity

Use available request and authentication information to identify patterns that may warrant defensive action or administrative review.

Monitoring

Prevention matters. Visibility matters too.

Security monitoring can provide additional context around failed access attempts, unusual behavior, rate-limit activity, account protection events, and other security-relevant application behavior.

Failed Access

Review supported failed login and authentication activity that may warrant investigation.

Repeated Requests

Use available rate-limit and request information to identify excessive or potentially abusive behavior.

Account Protection

Maintain appropriate context around lockouts and other supported account-security events.

Administrative Activity

Provide authorized administrators with visibility into important platform and security activity.

Application Events

Use available security and operational signals to provide context when application behavior requires investigation.

Incident Review

Use logged activity as one source of evidence when investigating access, configuration, user, or application concerns.

Audit Visibility

Important actions should leave useful history.

Supported security, administrative, configuration, automation, module, and operational logs can help authorized users understand important activity that occurred throughout the platform.

  • Login activity
  • Authentication events
  • Configuration changes
  • Permission changes
  • Administrative activity
  • Security events
  • Module activity
  • Sensitive actions
  • User context
  • Recorded timestamps

Accountability

“What happened?” should have a better answer than guesswork.

Audit and operational history can help organizations investigate important changes, understand administrative actions, review security events, and support broader governance procedures.

Logging provides evidence and context. It does not replace prevention, monitoring, access control, or good administration.

API Security

API-first does not mean access-first.

Brilliance One's API-first architecture still requires supported endpoints to apply appropriate authentication, authorization, validation, rate limiting, and business rules according to how each endpoint is intended to be used.

  • Authenticated endpoints
  • Authorization enforcement
  • API credentials where required
  • Rate limiting
  • Request validation
  • Tenant context
  • Permission-aware actions
  • Public/shared endpoint controls
  • Operational logging

Secure Extensibility

Extensible systems still need boundaries.

APIs make it easier to extend business capabilities across websites, portals, applications, and integrations.

Those same interfaces need intentional access controls so exposing capability does not mean exposing unrestricted data or actions.

Deployment Architecture

Infrastructure requirements are not identical for every organization.

Brilliance One can support deployment and data-isolation approaches intended for organizations with different security, control, operational, privacy, and infrastructure requirements.

Managed

Hosted Environment

Use Brilliance One through a managed platform environment with the underlying application infrastructure operated as part of the service.

Data

Customer-Specific Database

Use customer-specific database architecture where configured to provide database-level separation of tenant business information.

Specialized

Controlled Deployment Options

Organizations with specialized infrastructure requirements can discuss available deployment and customer-specific architecture options with Brilliance One.

Security Controls

Security across identity, data, access, applications, and activity.

Brilliance One combines multiple controls across different parts of the platform rather than treating any single mechanism as complete security.

Identity

Authentication

Use protected credentials, multi-factor authentication where enabled, login controls, account protection, and session validation.

Access

Authorization

Limit supported records, modules, administrative functionality, and actions according to roles, permissions, security groups, and responsibility.

Data

Separation & Protection

Combine customer-specific database architecture with appropriate encryption and application-level controls around sensitive information.

Application

Endpoint Security

Use secure transport, protected APIs, request validation, authentication, authorization, and rate limiting across supported application surfaces.

Activity

Monitoring

Maintain visibility into supported access, application, account, and security events that may require investigation.

Accountability

Audit History

Preserve appropriate administrative, configuration, access, module, and security history for authorized review.

Security + Compliance

Security controls can support compliance. They do not create it automatically.

Organizations may use Brilliance One in environments affected by privacy, healthcare, payment, contractual, government, industry, or organizational security requirements.

  • Access controls
  • Authentication
  • Audit visibility
  • Encryption
  • Customer data separation
  • Security logging
  • Administrative controls
  • Data-handling policies
  • Retention decisions
  • Organizational governance

Compliance-Aware Architecture

A secure feature is not the same thing as a compliance certification.

Brilliance One can provide technical controls that help organizations implement security and governance requirements across supported workflows.

Customers remain responsible for determining which laws, regulations, contractual standards, certifications, policies, and operational safeguards apply to their organization.

Shared Responsibility

Good technology still requires good administration.

Platform controls can reduce risk, but security also depends on how organizations manage users, devices, credentials, permissions, integrations, policies, retention, training, and incident response.

  • User access reviews
  • Strong credential practices
  • Multi-factor authentication
  • Permission management
  • Secure endpoint devices
  • Integration review
  • Administrative policies
  • Employee security training
  • Data retention decisions
  • Incident-response procedures

Security Is a Process

No software platform eliminates security risk.

Brilliance One provides security capabilities and architecture that organizations can incorporate into their broader security program.

Customers should configure those controls appropriately and maintain their own policies, procedures, training, endpoint protection, identity management, integration security, and incident-response practices.

Platform Security Strategy

Enterprise platforms need strong security. Brilliance extends the same foundation into operations.

Established customer platforms already provide mature authentication, permissions, encryption, logging, security programs, and administrative controls. Brilliance One applies its security foundation across a broader combination of customer, financial, workforce, document, commerce, industry, and operational workflows.

Customer

CRM & Communications

Apply identity, access, data, and logging controls to customer records, contacts, communications, leads, and relationship history.

Business

ERP & Workforce

Extend security controls into accounting, employees, projects, inventory, documents, scheduling, commerce, and other operational workflows.

Specialized

Industry Workflows

Apply the broader platform security model to specialized records such as firearms, drug testing, courses, and other industry or regulatory workflows.

Brilliance One Core

One shared foundation. Used throughout the platform.

Core provides the relationship, communication, automation, identity, security, configuration, and administrative capabilities that support the broader Brilliance One Business Operating System.

CRM & Relationships

Accounts

Manage customers, prospects, leads, organizations, contacts, vendors, suppliers, partners, and relationship history through one connected business record.

Explore Accounts

Locations

Addresses

Maintain billing, shipping, service, customer, employee, vendor, job-site, and operational locations as reusable records connected to the business activity that depends on them.

Explore Addresses

Email, SMS & Messaging

Communications

Connect email, SMS, MMS, campaigns, templates, lists, replies, delivery activity, and communication history with the customers and business records behind every conversation.

Explore Communications

Workflow Automation

Automations

Automate supported email, SMS, tagging, notifications, delays, follow-up, and repeatable processes so people can focus on decisions while software handles routine work.

Explore Automations

Identity & Access

Users

Manage identities, roles, permissions, security groups, profiles, account relationships, module access, authentication, and operational responsibilities across Brilliance One.

Explore Users

Platform Protection

Security

Protect business information with authentication, authorization, roles, permissions, security groups, encryption, session controls, logging, monitoring, and administrative safeguards.

Explore Security

Platform Configuration

Settings

Configure organization defaults, branding, permissions, communication providers, payment services, AI preferences, integrations, module behavior, and shared platform settings.

Explore Settings

Data Operations

Tools

Import, export, map, validate, review, migrate, clean, and maintain supported business information with administrative workflows designed for controlled data operations.

Explore Tools

Brilliance One Security

Separate the data. Control the access.

Use customer-specific data architecture, authentication, permissions, credential protection, encryption, secure application communication, session controls, rate limiting, monitoring, and audit visibility as shared security layers across the Brilliance One Business Operating System.

Brilliance One • Security • Data Separation • Access Control • Audit Visibility