Security
This page is the technical detail behind the security claims on our marketing pages — for security reviewers, IT teams, and anyone who wants the specifics before signing off. For the legal terms, see our DPA, Privacy Policy, and Subprocessors list.
Data isolation
Every organisation gets its own dedicated set of AI agents. There is no shared execution context and no shared model layer between organisations — cross-organisation requests are rejected at the infrastructure layer, not just in application code. Within your organisation, row-level security is enforced at the database layer, so access is controlled by the database itself rather than by application logic that could be misconfigured or bypassed.
How AI agents handle your data
Our agents are rule-based: they apply configured logic to map fields, flag quality issues, and generate transformations. They don’t review your records the way a person would, and each agent only receives the specific fields it needs to complete its task — not your full dataset.
Where a step calls for a third-party model provider (currently Anthropic, and AWS Bedrock for private/enterprise deployments), that data is handled under the provider’s standard commercial terms: it is not used to train their models, and it is retained only as long as the provider’s standard terms allow for abuse and safety monitoring before deletion. We do not have a zero-data-retention agreement with our model providers today — if your organisation requires one, or requires routing through private infrastructure, contact us at admin@brocktransform.com to discuss Enterprise options.
Encryption and access control
Connection credentials are encrypted at rest. Customer data is encrypted in transit and at rest. Access to production systems is limited by role, and every action in Brock — who did it, what they did, and when — is captured in an audit log.
Questions we haven’t answered here? Email admin@brocktransform.com.