Security & Trust Center

Security is not an add-on. It is part of the platform.

Brilliance One is designed around customer isolation, strong authentication, controlled access, encrypted communications, audit-oriented visibility, privacy-aware workflows, and security-focused operational practices.

From dedicated customer databases and role-based permissions to credential protection, logging, monitoring, configuration controls, and compliance-aware settings, security is considered across the architecture rather than treated as a single feature.

Isolation Access Control Encryption Auditability
Brilliance One security architecture and platform protection

Defense in Depth

Multiple layers. One security model.

Brilliance One uses overlapping safeguards across identity, application access, customer data, infrastructure, communication, configuration, and operational visibility so security does not depend on a single control.

Identity

Protect Access to the Platform

Authentication, password protection, multi-factor authentication, lockout controls, rate limiting, permissions, and security policies can work together to reduce unauthorized access risk.

Isolation

Dedicated Customer Databases

Customer environments can use dedicated database architecture to create clearer logical separation, customer-specific backup boundaries, and stronger operational isolation.

Visibility

Audit & Monitoring Awareness

Logging, activity visibility, monitoring, security events, and operational review can help authorized teams investigate activity and identify conditions requiring attention.

Identity & Authentication

Security begins with identity.

Access controls are most effective when identity, authentication, authorization, account protection, and user lifecycle management work together.

  • Strong password protection
  • Multi-factor authentication
  • Account lockout controls
  • Rate limiting
  • Session and authentication controls
  • User-level permissions
  • Role-based access
  • Security groups
  • Administrative restrictions
  • User access review

Access Governance

Authentication answers who you are. Authorization determines what you can do.

Brilliance One is designed to separate authentication from authorization so access can be controlled according to user responsibility rather than assuming every authenticated user should see the same information.

Credential Protection

Passwords should be protected as credentials, not stored as data.

Brilliance One uses modern password-handling practices designed to make stored credentials significantly more resistant to offline attack if credential storage were ever exposed.

Argon2id

Passwords can be protected using Argon2id, a memory-hard password hashing algorithm designed specifically for credential storage.

Unique Salt

Password hashing incorporates unique salt values so identical passwords do not produce identical stored representations.

Additional Secret Protection

Additional server-side secret protection can provide another layer beyond the individual password hash where configured.

Customer Data Isolation

Separate customers. Separate data boundaries.

Brilliance One can provision dedicated customer databases rather than requiring every customer to share the same primary application database.

  • Dedicated customer databases
  • Clearer logical isolation
  • Customer-specific backup boundaries
  • Customer-specific restoration
  • Controlled database access
  • Customer-specific retention options
  • Cleaner migration boundaries
  • Independent maintenance opportunities
  • Operational separation
  • Reduced cross-customer data exposure paths

Isolation by Architecture

Data separation should not rely only on a tenant identifier.

Dedicated database architecture provides another structural boundary between customer environments and can simplify backup, restoration, retention, migration, and customer-specific operational management.

No architecture eliminates every security risk, but additional isolation can reduce the consequences of entire classes of cross-tenant application mistakes.

Encryption & Transport

Protect information in transit and where required at rest.

Encryption is one part of a broader security model. Brilliance One uses secure transport and encryption-oriented controls to help protect sensitive information as it moves through supported platform workflows.

Secure Transport HTTPS and modern TLS protections help secure supported communication between browsers, APIs, and platform services.
Encrypted Secrets Sensitive application secrets can be encrypted and protected rather than stored as directly readable configuration values.
Password Hashing User passwords are protected through password hashing rather than reversible password storage.
Key Separation Security-sensitive key and secret handling can be separated from ordinary application data where appropriate.
Protected Workflows Encryption controls can support sensitive modules and workflows according to their data requirements.
Controlled Access Encryption is complemented by permissions and operational controls that govern who can reach protected information.

Authorization

Give users only the access they need.

A connected platform contains information used by many roles. Sales, HR, accounting, administrators, customer service, technicians, managers, and external users should not automatically receive identical access.

Users

Access can be associated with individual authenticated user accounts.

Roles

Role-based permissions can help standardize access around common responsibilities.

Security Groups

Security groups can provide another way to organize permission and access requirements.

Modules

Access can be separated across different operational areas of the platform.

Sensitive Information

Financial, employee, compliance-related, administrative, and other sensitive information can require more restrictive access.

Administrative Access

Higher-risk administrative capabilities can be restricted to authorized users with appropriate responsibilities.

Auditability & Visibility

Security needs an operational record.

Preventive controls matter, but organizations also need enough visibility to investigate activity, understand changes, review important events, and improve operational accountability.

  • Authentication activity
  • User activity
  • Security-sensitive changes
  • Administrative actions
  • Workflow events
  • Record history
  • Security alerts
  • Operational logs
  • Access review support
  • Audit-oriented reporting

Accountability

Prevention is stronger when it is paired with visibility.

Audit-oriented records and operational logging can help answer important questions about what happened, when it happened, which account was involved, and what action followed.

Monitoring & Operations

Security continues after deployment.

Secure architecture still requires operational awareness. Monitoring, alerts, logging, maintenance, dependency review, deployment controls, backups, and incident processes are all part of operating a secure platform.

Application Monitoring

Monitor supported application and service behavior for conditions requiring operational attention.

Logging

Maintain operational and security-related logs appropriate to supported platform functions.

Alerts

Use alerting workflows to surface selected operational or security conditions.

Backups

Maintain backup processes appropriate to the underlying customer data architecture and deployment model.

Updates

Review application, framework, dependency, and infrastructure updates through controlled maintenance processes.

Incident Awareness

Operational visibility helps teams identify, investigate, respond to, and learn from security-relevant conditions.

Privacy & Data Governance

Security protects data. Privacy governs how it is used.

Brilliance One can support operational privacy workflows related to consent, communication preferences, suppression, access, retention, and data-management requests where those capabilities are configured.

  • Consent-related records
  • Communication preferences
  • Opt-out handling
  • Suppression workflows
  • Access controls
  • Retention-related settings
  • Data request workflows
  • Privacy-oriented audit history
  • Customer data separation
  • Organization-defined governance

Privacy by Process

Privacy is more than a checkbox.

Effective privacy programs depend on technology, policies, contracts, data classification, employee training, documented procedures, retention decisions, and ongoing governance working together.

Compliance-Aware Controls

Built to support regulated environments.

Brilliance One includes security, privacy, auditability, access, configuration, and documentation capabilities that can support organizations working toward regulatory or contractual requirements.

Healthcare

HIPAA-Ready Workflows

Security controls and configuration capabilities can support organizations implementing HIPAA-oriented safeguards and workflows where applicable.

Security Controls

SOC 2 Readiness

Security, availability, confidentiality, privacy, logging, documentation, and operational controls can support broader SOC 2 readiness efforts.

Privacy

GDPR & U.S. Privacy Workflows

Consent, access, opt-out, suppression, retention, and privacy-related operational controls can support GDPR, CCPA, CPRA, and related requirements where appropriate.

Payments

PCI-Aware Integration

Payment workflows can be structured to minimize unnecessary exposure to payment-card information and rely on appropriate payment providers where configured.

Defense

CMMC-Oriented Controls

Access, logging, documentation, security controls, and operational configuration can support future defense-adjacent and CMMC-oriented requirements where appropriate.

Documentation

Control Mapping & Review

Internal assessments, security summaries, and control information can support customer security reviews under appropriate confidentiality arrangements.

Deployment Strategy

Security requirements vary by organization.

Brilliance can support deployment discussions around shared cloud infrastructure, dedicated environments, private cloud approaches, and other implementation requirements depending on the customer’s security, compliance, scale, and operational needs.

Standard Cloud Managed platform infrastructure for organizations with standard operational requirements.
Dedicated Data Dedicated customer database architecture can provide stronger customer-specific data boundaries.
Dedicated Environment Dedicated infrastructure discussions can be evaluated for customers with additional operational requirements.
Private Cloud Private-cloud requirements can be reviewed according to implementation complexity and customer needs.
Integration Security External integrations can be evaluated according to authentication, authorization, data scope, and operational risk.
Customer Requirements Security architecture can be discussed during implementation when contractual or regulatory requirements demand additional consideration.

Software Supply Chain

Security includes the software we depend on.

Application security extends beyond internally written code. Frameworks, libraries, packages, professional components, build systems, external APIs, and deployment dependencies all become part of the security boundary.

  • Dependency review
  • Known-vulnerability awareness
  • Controlled versions
  • License awareness
  • Maintenance review
  • Package integrity
  • Controlled deployment
  • Update testing
  • Dependency replacement
  • Reduced unnecessary dependencies

Verified Stack

Every dependency becomes part of the security story.

Brilliance One evaluates technology choices not only for functionality, but also for security, licensing, maintenance, operational risk, and long-term platform fit.

Explore the Verified Stack

Shared Responsibility

Security is a partnership.

Brilliance One can provide security-focused infrastructure, application controls, account protection, monitoring capabilities, and configuration options. Customers remain responsible for how their users, policies, processes, devices, integrations, and data are managed.

Brilliance Responsibilities

Protect the platform.

  • Platform architecture
  • Application security controls
  • Customer data isolation architecture
  • Authentication capabilities
  • Security-focused development
  • Infrastructure safeguards
  • Platform monitoring
  • Dependency management
  • Platform maintenance
  • Security-related configuration capabilities

Customer Responsibilities

Operate securely.

  • Assign appropriate user access
  • Require MFA where appropriate
  • Protect employee credentials
  • Remove access when users leave
  • Maintain secure endpoint devices
  • Train employees
  • Review permissions
  • Maintain organizational policies
  • Configure integrations responsibly
  • Maintain legal and regulatory compliance programs

Brilliance Health Check

Better configuration. Stronger operational posture.

The Brilliance Health Check can evaluate selected configuration patterns and help identify settings, access decisions, and operational practices that may deserve additional review.

  • User access review
  • Role review
  • Permission review
  • MFA posture
  • Security configuration
  • Privacy-related settings
  • Compliance-oriented configuration
  • Administrative controls
  • Operational recommendations
  • Security awareness opportunities

Security Brief

Need more detail for your security review?

Organizations evaluating Brilliance One can contact our team to discuss security architecture, deployment requirements, customer isolation, access controls, privacy capabilities, compliance readiness, and available security documentation.

Security Principles

Protect. Limit. Observe. Improve.

1

Reduce Exposure

Limit unnecessary access, dependencies, data exposure, privileges, and cross-customer interaction paths.

2

Protect & Observe

Combine authentication, permissions, encryption, logging, isolation, monitoring, and operational safeguards.

3

Continuously Improve

Review architecture, configuration, dependencies, monitoring, customer requirements, security guidance, and emerging risks as the platform evolves.

Security & Compliance Responsibility

Technology supports compliance. It does not create compliance by itself.

Security and compliance requirements vary according to organization, industry, jurisdiction, contract, deployment model, configuration, data, users, and applicable law.

Brilliance One provides security-focused technology and compliance-aware capabilities, while each organization remains responsible for determining its requirements and maintaining appropriate policies, procedures, configurations, training, contracts, legal review, and compliance programs.

Brilliance One Security

Security by architecture. Trust through discipline.

Brilliance One combines identity protection, dedicated customer databases, access governance, encryption, auditability, monitoring, privacy-aware workflows, controlled dependencies, and compliance-oriented configuration into one security-focused platform foundation.

Brilliance One • Security First • Dedicated Data • Controlled Access