Bretton Trust center

Bretton builds AI workers for bank and fintech compliance teams. Innovative teams use our AI workers instead of outsourced teams to onboard customers faster with higher compliance standards.

Powered by Wolfia. Review compliance certifications, security policies, subprocessors, and request access to detailed documentation.

Skip to main content
Bretton Trust center

Bretton Trust center

Bretton builds AI workers for bank and fintech compliance teams. Innovative teams use our AI workers instead of outsourced teams to onboard customers faster with higher compliance standards.

privacy@bretton.com

Access control

Strict identity and permission management ensures users only reach the data and functions required for their roles

Role-based access control

Permissions are granted according to documented job responsibilities so each user receives the minimum privileges needed to perform work, reducing lateral risk.

Multi-factor authentication for privileged access

Administrators must authenticate with an additional factor before reaching production resources, adding a strong barrier against credential compromise.

Quarterly access reviews

System owners review user and admin rights every quarter and revoke any unnecessary privileges to keep entitlements current and least-privileged.

Unique user identities

Every employee and contractor receives an individual account—shared credentials are prohibited—enabling full accountability and auditability of all actions.

Segregation of duties

Conflicting responsibilities are separated so that no single individual can authorize and execute sensitive transactions without oversight, limiting fraud and error.

Data security

Comprehensive safeguards protect customer information throughout its lifecycle

Encryption at rest

All confidential and customer data stored in databases, backups and mobile devices is encrypted to prevent disclosure if media is lost or stolen.

Encryption in transit

TLS is enforced for every connection over public networks, ensuring data remains unreadable to eavesdroppers during transfer.

Data classification program

Information is labelled as confidential, restricted or public with handling rules for each tier so employees know exactly how to protect different data types.

Retention and secure disposal

Data is kept only as long as there is a business or regulatory need, then deleted or destroyed following documented schedules and secure wipe standards.

Encrypted mobile and backup media

Laptop drives and backup files are encrypted, adding defense in depth for data that leaves the primary production environment.

Incident response

A tested program rapidly detects, contains and communicates security events

Documented incident response plan

A company-wide playbook defines roles, severities and workflows so responders act quickly and consistently during security events.

24×7 escalation procedures

Severity-based runbooks and on-call rotations ensure incidents are triaged and routed to engineering leadership any time they occur.

Annual incident response test

Table-top and technical exercises are conducted yearly to validate procedures and identify areas for improvement before real crises strike.

Forensic evidence preservation

Responders collect and protect logs and artifacts in line with NIST guidance, supporting root-cause analysis and potential legal needs.

Regulatory breach notification process

Defined steps guide timely communication to customers and authorities when required, helping meet obligations under laws like GDPR.

Business continuity

Preparedness strategies keep critical services available during disruptive events

Documented BC/DR plan

A formal plan outlines how operations and technology services are restored after natural disasters, outages or office disruptions.

Annual disaster recovery test

Restoration procedures and backups are exercised at least once per year to prove they meet recovery objectives.

Defined RTO and RPO targets

Recovery time and point objectives are set for key systems, providing clear expectations for maximum downtime and data loss.

Remote work capability

Employees can securely operate from alternate locations if the primary office is unavailable, ensuring customer support continues uninterrupted.

Critical service continuity strategies

Playbooks detail how production support, communications and customer notifications proceed even if headquarters or a cloud region is impacted.

Compliance and auditing

Independent reviews and continuous monitoring prove controls operate effectively

SOC 2 Type II certification

A licensed CPA firm audits the security program annually, providing customers with third-party assurance over design and operating effectiveness.

Internal control self-assessments

Teams use automated tooling and manual reviews to validate control performance throughout the year, enabling rapid remediation of gaps.

Annual third-party penetration test

External security experts attempt to exploit the platform each year and findings are remediated under tracked SLAs.

Quarterly vulnerability scanning

Automated scans of external-facing systems identify new weaknesses, with critical and high issues fixed within 30 days.

Board-level cybersecurity oversight

The board receives at least annual briefings on security posture and provides governance direction, aligning efforts with business risk appetite.

Employee security

Human-centric controls foster a trustworthy, security-aware workforce

Pre-employment background checks

Criminal and other screenings are completed for employees and privileged contractors in line with role risk to reduce insider threat.

Annual security awareness training

All personnel complete onboarding and yearly refresher courses covering policies, phishing and data handling, reinforcing secure behaviour.

Code of conduct and confidentiality agreements

Staff formally acknowledge expectations for ethical behaviour and non-disclosure of sensitive information, creating clear accountability.

Role-specific secure development training

Developers receive specialised education on OWASP threats and secure coding practices at least annually, improving product resilience.

Progressive disciplinary process

Policy violations trigger an established escalation path up to termination, demonstrating zero tolerance for negligent or malicious actions.

Application security

Secure development lifecycle embeds protection into every release

Secure development policy

Documented SDLC requirements cover threat modelling, code standards, testing and approvals before any change reaches production.

Peer code reviews and version control

All significant changes are reviewed by qualified engineers and tracked in version control, catching defects early and maintaining traceability.

Automated dependency and code scanning

Continuous tools analyse source and open-source libraries for vulnerabilities, with issues remediated under defined SLAs.

Annual application penetration test

Third-party testers simulate real-world attacks against the platform, and remediation plans address any findings.

Environment segregation

Development and staging are logically isolated from production, preventing test activities from affecting live customer data.

Infrastructure security

Hardened cloud environments and monitoring protect the production platform

Network segmentation and firewalls

Security groups and access control lists restrict traffic between tiers, limiting the blast radius of a compromise.

Configuration management and hardening standards

Servers and services follow documented baselines that disable defaults, enforce updates and remove unnecessary components.

Intrusion detection and monitoring

Automated systems watch networks and hosts for malicious activity and alert the security team for rapid response.

Anti-malware on endpoints

Company devices run managed anti-malware that updates automatically and blocks known threats.

Cloud provider attestation review

AWS datacenter controls are reviewed through SOC reports to verify complementary safeguards for physical and environmental security.

Third-party management

Rigorous oversight governs vendors that handle or influence customer data

Vendor risk assessments

Security questionnaires and evidence are reviewed before granting vendors access to confidential data or systems.

Critical vendor inventory

An up-to-date register tracks all suppliers, their services and relevant compliance obligations to maintain visibility and accountability.

Security clauses in contracts

Agreements require vendors to meet confidentiality, integrity and availability commitments aligned with Greenlite policies.

Annual vendor performance review

Key suppliers are reassessed at least yearly to confirm they still satisfy security and service expectations.

Subservice monitoring via attestations

SOC reports and other audit documents are requested and evaluated to ensure subservice organizations operate effective controls.

Physical security

Controlled facilities and safeguards protect equipment and paper records

Secured office perimeters

Buildings meet local code and use electronic access controls that log entry events for review when needed.

Visitor management procedures

Guests sign in, wear badges and are escorted in secure areas, preventing unauthorized physical access to sensitive zones.

CCTV and intrusion detection in secure areas

Video surveillance and alarms monitor server rooms and wiring closets, deterring and detecting physical tampering.

Environmental and power controls

Critical processing areas include fire suppression, climate monitoring and backup power to maintain availability and safety.

Certified device destruction

When hardware cannot be wiped, an e-waste provider destroys it and issues certificates kept on record for at least one year.

Cryptography

Strong encryption and key management protect confidentiality and integrity

NIST-aligned cryptography policy

Encryption algorithms, key lengths and lifecycles follow SP 800-57 guidance to align with industry best practice.

TLS for all external communications

Only strong cipher suites are permitted for data in transit, preventing interception or tampering.

AES-256 encryption for confidential data at rest

Sensitive information stored in databases, backups and devices uses robust symmetric encryption to mitigate data-at-rest exposure.

Restricted key access

Encryption keys are accessible only to authorised personnel with a business need, reducing insider and external threat vectors.

One-way password hashing with salt and pepper

User passwords are stored using bcrypt/scrypt or Argon2, protecting credentials even if a database were compromised.

Logging and monitoring

Continuous visibility supports rapid detection and investigation of anomalies

Centralised log management

System and application logs are aggregated and retained for at least 30 days, enabling comprehensive incident reconstruction.

Infrastructure performance monitoring

Automated tools watch uptime and thresholds, issuing alerts when predefined conditions are met.

Administrator activity logging

Privileged actions are captured and periodically reviewed to detect unauthorised changes.

Security event correlation

Logs feed into analytics that highlight suspicious patterns requiring investigation.

Protection of log integrity

Access to logging systems is restricted and tamper-evident controls prevent alteration of records.

Risk management

Structured processes identify, evaluate and treat security and privacy risks

Annual enterprise risk assessment

Management ranks threats by likelihood and impact, updating the risk register and remediation tasks accordingly.

Documented risk register and treatment plans

Risks are tracked with owners, mitigation steps and timelines, ensuring accountability until closure.

Board review of cyber risk

Executive summaries keep directors informed of top risks and planned treatments, aligning strategic decisions with security posture.

Vulnerability remediation SLAs

Critical and high findings are fixed within 30 days, medium within 60 and low within 90, limiting exposure windows.

Supply chain risk consideration

Vendor and technology dependencies are analysed during assessments to address potential downstream threats.

Data privacy

Policies and controls uphold legal and contractual privacy commitments

PII deletion on request or end-of-purpose

Personally identifiable information is erased or de-identified once business need ends or a verified subject request is received.

Contractual confidentiality obligations

Employees and vendors sign NDAs and confidentiality clauses, reinforcing the duty to protect customer data.

Restricted use of production data in testing

Customer data may not be loaded into development or test environments without explicit owner approval, preventing accidental exposure.

Public privacy policy disclosures

Service commitments and data handling practices are transparently communicated to users and prospects.

Privacy breach response procedures

Dedicated workflows ensure prompt assessment and notification in line with regulations when personal data may be compromised.