Last updated: May 1, 2026
BrikMate is a lease-administration product used by commercial real estate teams to extract, abstract, and report on lease portfolios. Customer leases are confidential business documents — protecting them is foundational to our service.
This page describes how we protect customer data: where it's stored, how it's encrypted, who can access it, our sub-processors, our breach-notification SLA, and how to reach our security team. It is intended as an honest, factual summary, not marketing copy.
For the contractual baseline, see our Terms of Service and Privacy Policy. For sub-processor details, see Sub-processors.
BrikMate's production environment runs entirely in U.S. cloud regions:
No customer data is stored or processed outside the United States. All BrikMate engineering staff are U.S.-based.
Every external connection — browser to application, application to database, application to object storage, application to every sub-processor — runs over TLS 1.2 or higher. HTTP requests are rejected at the edge. Modern cipher suites (ECDHE+AES-GCM, ChaCha20-Poly1305) are required; legacy ciphers are disabled.
Every laptop with logical access to BrikMate systems is FileVault-encrypted end-to-end.
BrikMate is multi-tenant by design. Customer data is isolated at three layers:
We follow a least-privilege model for production access:
Before access is granted, every employee and contractor signs:
Pre-employment background checks are performed via Checkr, administered through our PEO Justworks, covering identity verification, criminal history (county / state / federal), employment verification, and reference checks, with a 7-year U.S. lookback window.
A current list of named sub-processors is published at brikmate.com/subprocessors. For each sub-processor, the list shows: country, purpose, the categories of data processed, and DPA-on-file status.
Sub-processors are reviewed at least quarterly. Customers under contracts that require notice receive at least 30 days' notice before a new sub-processor is added.
BrikMate's product uses third-party AI services to process leases:
Inputs and outputs to these vendors run on their commercial / API tiers, where the vendors' terms confirm in writing that BrikMate's inputs and outputs are not used to train their models. Customer documents are sent to these sub-processors only via BrikMate's organizational API keys from backend code, and only to deliver the contracted service.
We do not send customer data to consumer AI tools such as ChatGPT or Claude.ai. Internal use of those tools by BrikMate staff is restricted by our Acceptable Use Policy.
If BrikMate becomes aware of a security breach affecting customer data, we will notify the affected customer within 72 hours of awareness — committed in the BrikMate Master Services Agreement, aligned with GDPR Art. 33 and U.S. state breach-notification laws.
In practice, our internal target is to notify within 24 hours of confirmed awareness, leaving an explicit safety margin against the contractual SLA.
The notice will include: scope of affected data, affected timeframe, what is known about cause and the containment actions taken, and a named BrikMate contact for follow-up. A full post-mortem follows within a reasonable period after containment.
We welcome reports from security researchers, customers, and the public.
Email: security@brikmate.com
We acknowledge receipt within one business day. Please include:
We do not currently run a public bug-bounty program, but we credit responsible disclosures with the reporter's permission.
For details on what personal data BrikMate processes, the legal bases for processing, retention, sub-processors, international transfers, and your rights as a data subject, see our Privacy Policy.
2026-04-30 — Initial public version.
For the contractual baseline, see Terms of Service. Questions not covered here: security@brikmate.com.