Bretton builds AI workers for bank and fintech compliance teams. Innovative teams use our AI workers instead of outsourced teams to onboard customers faster with higher compliance standards.
Certifications
Trusted by
Does your team answer security questionnaires too? Wolfia answers them for you and runs trust centers
Documentation
Certifications
Policies
Controls
Strict identity and permission management ensures users only reach the data and functions required for their roles
Comprehensive safeguards protect customer information throughout its lifecycle
A tested program rapidly detects, contains and communicates security events
Frequently asked security questions
Is Bretton secure?
Bretton operates this public trust center. It publishes 2 independent compliance certifications and security documentation available on request.
Is Bretton SOC 2 compliant?
Yes. Bretton maintains SOC 2 Type II compliance. You can review this in the compliance section of this trust center.
Is Bretton GDPR compliant?
Yes. Bretton maintains GDPR compliance. See the compliance section of this trust center for details.
How do I request Bretton's security documentation?
You can request access to Bretton's security documentation directly through this trust center. Submit an access request and the Bretton team reviews and grants access.
Does your team answer security questionnaires too? Wolfia answers them for you and runs trust centers
Controls
Access control
Strict identity and permission management ensures users only reach the data and functions required for their roles
Permissions are granted according to documented job responsibilities so each user receives the minimum privileges needed to perform work, reducing lateral risk.
Administrators must authenticate with an additional factor before reaching production resources, adding a strong barrier against credential compromise.
System owners review user and admin rights every quarter and revoke any unnecessary privileges to keep entitlements current and least-privileged.
Every employee and contractor receives an individual account—shared credentials are prohibited—enabling full accountability and auditability of all actions.
Conflicting responsibilities are separated so that no single individual can authorize and execute sensitive transactions without oversight, limiting fraud and error.
Data security
Comprehensive safeguards protect customer information throughout its lifecycle
All confidential and customer data stored in databases, backups and mobile devices is encrypted to prevent disclosure if media is lost or stolen.
TLS is enforced for every connection over public networks, ensuring data remains unreadable to eavesdroppers during transfer.
Information is labelled as confidential, restricted or public with handling rules for each tier so employees know exactly how to protect different data types.
Data is kept only as long as there is a business or regulatory need, then deleted or destroyed following documented schedules and secure wipe standards.
Laptop drives and backup files are encrypted, adding defense in depth for data that leaves the primary production environment.
Incident response
A tested program rapidly detects, contains and communicates security events
A company-wide playbook defines roles, severities and workflows so responders act quickly and consistently during security events.
Severity-based runbooks and on-call rotations ensure incidents are triaged and routed to engineering leadership any time they occur.
Table-top and technical exercises are conducted yearly to validate procedures and identify areas for improvement before real crises strike.
Responders collect and protect logs and artifacts in line with NIST guidance, supporting root-cause analysis and potential legal needs.
Defined steps guide timely communication to customers and authorities when required, helping meet obligations under laws like GDPR.
Business continuity
Preparedness strategies keep critical services available during disruptive events
A formal plan outlines how operations and technology services are restored after natural disasters, outages or office disruptions.
Restoration procedures and backups are exercised at least once per year to prove they meet recovery objectives.
Recovery time and point objectives are set for key systems, providing clear expectations for maximum downtime and data loss.
Employees can securely operate from alternate locations if the primary office is unavailable, ensuring customer support continues uninterrupted.
Playbooks detail how production support, communications and customer notifications proceed even if headquarters or a cloud region is impacted.
Compliance and auditing
Independent reviews and continuous monitoring prove controls operate effectively
A licensed CPA firm audits the security program annually, providing customers with third-party assurance over design and operating effectiveness.
Teams use automated tooling and manual reviews to validate control performance throughout the year, enabling rapid remediation of gaps.
External security experts attempt to exploit the platform each year and findings are remediated under tracked SLAs.
Automated scans of external-facing systems identify new weaknesses, with critical and high issues fixed within 30 days.
The board receives at least annual briefings on security posture and provides governance direction, aligning efforts with business risk appetite.
Employee security
Human-centric controls foster a trustworthy, security-aware workforce
Criminal and other screenings are completed for employees and privileged contractors in line with role risk to reduce insider threat.
All personnel complete onboarding and yearly refresher courses covering policies, phishing and data handling, reinforcing secure behaviour.
Staff formally acknowledge expectations for ethical behaviour and non-disclosure of sensitive information, creating clear accountability.
Developers receive specialised education on OWASP threats and secure coding practices at least annually, improving product resilience.
Policy violations trigger an established escalation path up to termination, demonstrating zero tolerance for negligent or malicious actions.
Application security
Secure development lifecycle embeds protection into every release
Documented SDLC requirements cover threat modelling, code standards, testing and approvals before any change reaches production.
All significant changes are reviewed by qualified engineers and tracked in version control, catching defects early and maintaining traceability.
Continuous tools analyse source and open-source libraries for vulnerabilities, with issues remediated under defined SLAs.
Third-party testers simulate real-world attacks against the platform, and remediation plans address any findings.
Development and staging are logically isolated from production, preventing test activities from affecting live customer data.
Infrastructure security
Hardened cloud environments and monitoring protect the production platform
Security groups and access control lists restrict traffic between tiers, limiting the blast radius of a compromise.
Servers and services follow documented baselines that disable defaults, enforce updates and remove unnecessary components.
Automated systems watch networks and hosts for malicious activity and alert the security team for rapid response.
Company devices run managed anti-malware that updates automatically and blocks known threats.
AWS datacenter controls are reviewed through SOC reports to verify complementary safeguards for physical and environmental security.
Third-party management
Rigorous oversight governs vendors that handle or influence customer data
Security questionnaires and evidence are reviewed before granting vendors access to confidential data or systems.
An up-to-date register tracks all suppliers, their services and relevant compliance obligations to maintain visibility and accountability.
Agreements require vendors to meet confidentiality, integrity and availability commitments aligned with Greenlite policies.
Key suppliers are reassessed at least yearly to confirm they still satisfy security and service expectations.
SOC reports and other audit documents are requested and evaluated to ensure subservice organizations operate effective controls.
Physical security
Controlled facilities and safeguards protect equipment and paper records
Buildings meet local code and use electronic access controls that log entry events for review when needed.
Guests sign in, wear badges and are escorted in secure areas, preventing unauthorized physical access to sensitive zones.
Video surveillance and alarms monitor server rooms and wiring closets, deterring and detecting physical tampering.
Critical processing areas include fire suppression, climate monitoring and backup power to maintain availability and safety.
When hardware cannot be wiped, an e-waste provider destroys it and issues certificates kept on record for at least one year.
Cryptography
Strong encryption and key management protect confidentiality and integrity
Encryption algorithms, key lengths and lifecycles follow SP 800-57 guidance to align with industry best practice.
Only strong cipher suites are permitted for data in transit, preventing interception or tampering.
Sensitive information stored in databases, backups and devices uses robust symmetric encryption to mitigate data-at-rest exposure.
Encryption keys are accessible only to authorised personnel with a business need, reducing insider and external threat vectors.
User passwords are stored using bcrypt/scrypt or Argon2, protecting credentials even if a database were compromised.
Logging and monitoring
Continuous visibility supports rapid detection and investigation of anomalies
System and application logs are aggregated and retained for at least 30 days, enabling comprehensive incident reconstruction.
Automated tools watch uptime and thresholds, issuing alerts when predefined conditions are met.
Privileged actions are captured and periodically reviewed to detect unauthorised changes.
Logs feed into analytics that highlight suspicious patterns requiring investigation.
Access to logging systems is restricted and tamper-evident controls prevent alteration of records.
Risk management
Structured processes identify, evaluate and treat security and privacy risks
Management ranks threats by likelihood and impact, updating the risk register and remediation tasks accordingly.
Risks are tracked with owners, mitigation steps and timelines, ensuring accountability until closure.
Executive summaries keep directors informed of top risks and planned treatments, aligning strategic decisions with security posture.
Critical and high findings are fixed within 30 days, medium within 60 and low within 90, limiting exposure windows.
Vendor and technology dependencies are analysed during assessments to address potential downstream threats.
Data privacy
Policies and controls uphold legal and contractual privacy commitments
Personally identifiable information is erased or de-identified once business need ends or a verified subject request is received.
Employees and vendors sign NDAs and confidentiality clauses, reinforcing the duty to protect customer data.
Customer data may not be loaded into development or test environments without explicit owner approval, preventing accidental exposure.
Service commitments and data handling practices are transparently communicated to users and prospects.
Dedicated workflows ensure prompt assessment and notification in line with regulations when personal data may be compromised.
Documentation
Certifications
Policies
Privacy & Legal
No subprocessors available
No updates available







