Policy centre
Security and trust
Last updated: 29 August 2026
A plain-language overview of how Brakan protects accounts, documents and operational evidence.
Controls in place
- Organisation-level data separation and role-based access.
- Hosted authentication, protected sessions and bot resistance on public account forms.
- TLS in transit and separately protected secrets for sensitive tax data.
- Private file storage, signed short-lived downloads and quarantine before use.
- File-signature validation, malware scanning and restricted upload formats and sizes.
- Immutable or append-only evidence for sensitive tax and administrative actions.
- Encrypted backups, restore drills, retention controls and independent infrastructure alarms.
- No administrator impersonation and no routine browsing of customer documents or bank details.
Your responsibilities
- Use a unique password and protect the email account used for recovery.
- Do not share credentials; invite team members using their own account.
- Assign the least-privileged suitable role and remove access promptly.
- Keep independent copies of legally critical records.
- Report suspected compromise immediately.
Reporting a vulnerability
Send a concise report to support@mail.brakan.co.uk with the subject “Security report”. Do not access customer data, disrupt the service, use destructive testing, publish an unremediated vulnerability or demand payment as a condition of disclosure. Brakan will acknowledge and triage good-faith reports.
Limits
No online service can promise absolute security. This page describes current controls without creating a warranty or disclosing operational secrets that would weaken them.