Security & privacy at Brandex
This page is maintained by the Brandex team to answer the questions buyers, security reviewers, and your own legal team will ask before signing off. It describes the controls that are live today — not aspirational ones.
Certifications. Brandex is pre-certification. We build on infrastructure that holds SOC 2, ISO 27001, and GDPR attestations, and we'll pursue our own audits once enterprise demand justifies the cost. Contact us if your procurement process requires a current attested report.
Last 30 days · 1000 runs observed · last heartbeat 8/7/2026, 1:24:00 PM
View live status →
Covers RLS policies, function search paths, secret rotation, and exposed endpoints. Triaged via automated linter + manual review.
Listed in full below. Updated whenever we add or remove a vendor.
Authentication & access
Sign-in is handled by a managed identity provider with email/password and Google OAuth. Workspaces are multi-tenant with role-based access (owner, admin, editor, viewer). Privileged actions (role changes, secret access, API key rotation) are audit-logged. Sessions are bearer tokens stored in browser storage and validated server-side on every privileged call.
Hosting & data location
Brandex runs on Cloudflare's global edge network for the application layer. Tenant data (Postgres + object storage) is hosted in our managed backend's EU-Central region (Frankfurt, Germany); read replicas may briefly cache data at the edge during a request for latency. Backups are stored in the same region. We do not currently offer customer-selectable data residency or US-only hosting; enterprise buyers with residency requirements should contact us before signing so we can confirm the current setup matches their policy.
Row-level isolation
Tenant data is isolated at the database layer via Postgres row-level security. Every table that holds tenant content carries a policy that scopes reads and writes to members of the owning workspace. The application code cannot bypass these policies; only verified backend webhooks use the service role, and they are signature-checked before any privileged write.
Encryption
All traffic between you, Brandex, and our infrastructure is encrypted in transit over TLS 1.2+. Data at rest in the database, object storage, and backups is encrypted by the underlying platform. Webhook secrets and API keys are stored in a managed secret store and are masked in the UI — only the last four characters are visible after creation.
Data we collect & why
We collect the content you create (brand dossiers, assets, prompts), the integrations you connect (CRM, Search Console, social), and operational telemetry (errors, usage counts) needed to run the product. We do not sell personal data and we do not train shared models on your private brand content.
Retention & deletion
Generated assets and brand memory are kept for the life of the workspace and 30 days after deletion to allow recovery. Audit logs are kept for 12 months. Signed-in users can download a JSON archive of their data or schedule account deletion from Preferences → Your account; deletion runs after a 14-day grace window and can be cancelled at any time before then. Workspace-owner requests for bulk export can also be sent to request@brandex.app.
Billing & tax (Merchant of Record)
All paid plans and top-ups are sold through Polar, our Merchant of Record. That means Polar — not Brandex — is the contracting seller on the invoice, and Polar is responsible for collecting and remitting VAT, GST and US sales tax in jurisdictions where it applies. We never see or store full card numbers; Polar handles PCI-scoped data. Refund and tax-invoice questions can be sent to request@brandex.app and we route them to Polar where needed.
Cookies & analytics
We use first-party cookies and local storage strictly to keep you signed in, remember workspace preferences, and run the product. We do not run third-party advertising trackers. Product analytics is limited to aggregated usage counts and error telemetry needed to operate the service, and is not sold or shared with marketing networks.
Subprocessors
We rely on: Lovable (hosting + managed Postgres + AI gateway), Resend (transactional email from brandex.app and notify.brandex.app), and — only when you explicitly connect them — HubSpot, TikTok, Google Search Console, Slack, and Meta. Connecting an integration shares only the scopes you grant in that provider's consent screen.
Email integrity
Outbound email is sent from verified domains (brandex.app for transactional, notify.brandex.app for marketing) with SPF, DKIM, and DMARC aligned. Every marketing email includes a one-click unsubscribe; suppressed addresses are honored across the workspace.
Incident notification
If we confirm an incident that materially affects your workspace data, we notify the workspace owner by email without undue delay — and within 72 hours where required by law. Notifications describe what we know, what's affected, and the steps we're taking. Subscribe to status.brandex.app for live operational updates.
Reporting a security issue
If you believe you've found a vulnerability, please email security@brandex.app with steps to reproduce. We acknowledge within 48 hours and aim to patch high-severity issues within 7 days. We do not currently run a paid bounty, but we credit responsible disclosures on this page on request.
Vendors that may process tenant data on our behalf. Integrations marked "opt-in" only receive data after a workspace owner connects them and grants the listed scopes.
| Vendor | Purpose | Region |
|---|---|---|
| Lovable Cloud | Application hosting, managed Postgres, object storage, AI gateway | Global edge |
| Resend | Transactional & notification email delivery (brandex.app, notify.brandex.app) | US / EU |
| Polar | Subscription billing & payment processing (merchant of record, global) | EU / US |
| Replicate | Hosted inference for select image & video models (only when used) | US |
| Semrush | SEO benchmark data (only on tenants that connect SEO) | US |
| Firecrawl | Public-web research crawling for brand intelligence (opt-in) | US |
| Google / Meta / TikTok / LinkedIn / HubSpot / Slack | Connected only when a workspace owner authorises the integration; scopes shown at consent | Per provider |
Brandex is operated by Aitwauthentica, registered in Ghana. Aitwauthentica is the data controller for personal data processed through Brandex and the counterparty named in any commercial or data-processing agreement.
- Security disclosures: security@brandex.app
- Privacy / data subject requests: request@brandex.app
- General: hello@brandex.app
Last updated: June 23, 2026.
