BBrakan

Policy centre

Data processing security schedule

Last updated: 29 August 2026

Technical and organisational measures supporting the draft Data Processing Terms and Article 32 UK GDPR.

Launch draft — controls must be verified against production and reviewed before incorporation into a commercial agreement

Governance and access

  • Named responsibility for security, privacy, incident response and recovery.
  • Role-based, least-privilege access with separate customer organisations and no routine administrator impersonation.
  • Individual accounts for authorised personnel, protected authentication and prompt access removal.
  • Confidentiality obligations and proportionate security training for authorised personnel.
  • Administrative actions and sensitive events recorded in append-only or immutable evidence where implemented.

Data and cryptography

  • TLS protects data in transit between supported clients and the service.
  • Production secrets and sensitive integration credentials are kept outside source code and access is restricted.
  • Customer uploads use private object storage, short-lived signed access, format and signature validation, quarantine and malware scanning.
  • Encrypted backups are separated from ordinary application access and retained under the published recovery schedule.
  • Data minimisation and metadata-only operational monitoring limit unnecessary administrator exposure.

Availability and separation

  • Organisation-scoped database controls and application authorisation restrict cross-customer access.
  • Backups, documented restoration procedures and periodic restore testing support recovery.
  • Retention workers remove expired temporary and deleted material, subject to legal holds and backup expiry.
  • Capacity, database and storage growth, failed jobs, email failures and public-service health are monitored independently.

Secure operation

  • Supported file types and sizes, request validation, rate controls and bot resistance reduce abuse.
  • Dependency, vulnerability and security-update processes are maintained and proportionate independent testing is required before public launch.
  • Security incidents are contained, investigated, evidenced and handled under the breach procedure.
  • Subprocessors receive only the access and data needed for their documented purpose and are subject to due diligence and contracts.

Testing and review

Brakan reviews the effectiveness of these measures through automated tests, access-control tests, backup and restore exercises, monitoring, incident learning and periodic risk review. Material weaknesses are prioritised according to risk. The final schedule must record control owners, review frequency and any independent assurance available at launch.

BrakanPrivate UK pilot · not yet a public paid service
PricingTermsPrivacyFair usageAcceptable useCookiesSecuritySubprocessorsRetentionComplaintsAccessibilityData processingSecurity scheduleTransfersOpen BankingAI & automationSubscriptions
support@mail.brakan.co.uk