Security and data handling

Answers your compliance officer can check.

Where client data is stored, how it is encrypted, who can read it and how long it is kept. Short on purpose, and each answer names the mechanism behind it.

Security summaryOctober 2026
Where data is stored
Sydney, AustraliaDatabase, file storage and server functions
Content encryption
AES-256-GCM, one key per workspaceKeys stay on the server, never in a browser
Briefi staff access
Only through a grant you giveUp to seven days, recorded in your audit log
Breach notice to you
Within 48 hoursA commitment in our Data Processing Agreement
AI model training
Briefi does not train on your contentA provider receives content only to do the task you asked for
Where your data lives

Stored in Sydney. Some tasks use providers overseas.

Client records, briefs, transcripts and recordings are kept in Australia. To draft, transcribe and deliver, Briefi sends the content one task needs to a specialist provider. Several of them are outside Australia, including in the United States.

Stored at restSydney
  • DatabaseMeetings, briefs, recaps, client records, email threads and your audit log
  • File storageRecording audio and client documents
  • Server functionsThe code that reads and writes your data runs in Sydney too
Sent for a single task
Drafting

Briefs, recaps, follow-up emails and inbox triage.

Transcription

Recordings, and live captions when you switch them on.

Meeting bot

Joins Zoom, Teams or Google Meet when you send it.

Email and payments

Delivering the email Briefi sends, and billing your subscription.

Transfers outside Australia are covered by APP 8 and, for EU and UK data, the Standard Contractual Clauses.The named list of providers is public, with what each receives and where it is hosted. Read the subprocessors
Encryption

Every workspace has its own key.

Sensitive content is encrypted before it reaches the database, with a key that belongs to your workspace alone. It is decrypted on the server only when a signed-in member with access opens it.

  1. Master keyHeld in the server environment

    A 256-bit key that never reaches a browser and is never stored in the database.

    Wraps every workspace key
  2. Workspace keyOne per workspace

    A random 256-bit key created for your workspace and stored only in wrapped form.

    Unwrapped in server memory, briefly
  3. Your contentAES-256-GCM, field by field

    One workspace's key cannot open another workspace's records.

    Stored as ciphertext in Sydney

Encrypted with your workspace key

  • Meeting briefs
  • Recaps
  • Follow-up drafts
  • Notetaker transcripts
  • Client notes
  • Check-in answers
  • Email and calendar tokens
  • Mailbox passwords
  • CRM keys

What is not field-encrypted

Values the database must search or sort on, such as names, email addresses, dates and statuses. The access rules below protect them. Every connection is HTTPS only, and the browser is told to insist on it (HSTS).

Who can see what

Three boundaries, each enforced separately.

Between practices, between colleagues, and between your practice and us.

1Between workspaces

Another practice cannot reach your records.

  • Row-level security is on for every table, and a build check fails if a new table ships without it.
  • Stored credentials cannot be read from a browser at all, even inside their own workspace.
  • Our server checks membership before it acts, and a record in another workspace answers as if it does not exist.
2Inside your workspace

Colleagues see what their role allows.

  • Meetings can be visible to the workspace, one team, or the owner alone. Personal mailboxes stay private unless shared.
  • Four roles, from owner and admin to member and read-only viewer. Privileged actions go to an audit log.
3Briefi staff

We do not look inside your workspace.

  • Unless an owner or admin grants access, for up to seven days, at a level they choose. They can revoke it at any time.
  • Read-only by default. Hands-on access never covers sending, spending, billing, members or deletion. Each visit is recorded in your audit log.
Two-step sign-in

Codes from an authenticator app, available to every user.

Connected accounts

Google, Microsoft and CRMs connect by OAuth, asking only for the access the features you turn on need. Their tokens are encrypted, and you can revoke them from the provider.

Retention

How long each thing is kept.

Your records stay while your workspace is active, with these exceptions.

RecordHow long
Recording audioDeleted after 7 days by default. Set anywhere from 1 to 90 days in workspace settings.
Meetings and transcriptsKept, encrypted, until you delete them or the workspace.
A deleted accountRecoverable for 90 days, then permanently removed.
A paused workspaceKept for 90 days, then deleted. If you had a trial or a plan, we email the workspace owner first.
Questions

What compliance officers ask first.

Can I get a Data Processing Agreement (DPA)?

Yes. Our DPA is published and covers the Privacy Act, GDPR and the UK Addendum. If your practice needs a signed copy, email us and we will prepare one for you.

Email privacy@briefi.shRead the DPA
Who are your subprocessors?

The current list, with what each receives and where it is hosted, is public. Workspace owners get at least 30 days of notice before a new subprocessor handles customer data.

Open the subprocessor list
Does client data leave Australia?

It is stored in Sydney. To draft, transcribe and send, Briefi passes the content one task needs to a specialist provider, and several are outside Australia. Those transfers are covered by APP 8 and, for EU and UK data, the Standard Contractual Clauses.

Is our clients’ information used to train AI models?

Briefi does not train AI models on your content, and we do not sell it or share it with advertising networks. Content goes to a provider only to complete the task you asked for. The providers and what each receives are on the subprocessor list.

Can Briefi staff read our client files?

Only if an owner or admin grants support access, for up to seven days. It is read-only unless you allow more, every visit is recorded in your audit log, and you can end it at any time.

What happens if there is a breach?

We notify the workspace owner within 48 hours of becoming aware of it, with what is known about its scope and what we are doing. That leaves you time for your own assessment under the Notifiable Data Breaches scheme.

Can we take our data with us?

An owner or admin can download any client’s full record as one file from their contact page, which is also how you answer an access request. Plans with API access can pull meetings, contacts, deals and threads through the API. For the whole workspace, email us and we will export it for you.

Email support@briefi.sh
Contact

Security reports and data requests.

We do not run a bug bounty, but every security report is read personally and we reply as soon as we can. Please give us a fair chance to fix an issue before you disclose it.

Security reports
security@briefi.sh
DPA, subprocessor questions and privacy requests
privacy@briefi.sh

Privacy requests are answered within 5 business days.

Bring your compliance questions to the demo.

A 30-minute walkthrough, with time to go through your own checklist.

Last reviewed October 2026