Security

Security-minded, without fake badges.

Brixor uses practical safeguards for account access, documents, payments, and customer data — and describes those practices honestly.

TLSStripe-handled cardsAccess controlsResponsible disclosureNo fake compliance claims

Practices

Clear protections contractors can understand.

01

Encryption in transit

Traffic is served over HTTPS/TLS so data is protected between the browser and Brixor.

02

Payment handling

Card details are handled by Stripe-hosted payment flows rather than stored directly in Brixor.

03

Access controls

Account access, dashboard sessions, and API keys are designed around authenticated workflows.

04

Data respect

We do not sell customer data, and privacy/security requests have dedicated contact paths.

Disclosure

Report security issues with enough detail to reproduce.

Please include the affected URL, steps, expected behavior, actual behavior, and any relevant request IDs or screenshots. Do not access customer data or disrupt the service while testing.

Responsible disclosure

If you discover a vulnerability, email security@brixor.ai with reproduction steps and impact.

Operational backups

Database backups and recovery capabilities depend on the configured production infrastructure.

Incident handling

Security issues are triaged by severity and communicated to affected users when required.

Security questions should not get buried.

Use the dedicated security inbox for vulnerabilities and the contact page for account or privacy requests.