Security
This Security Statement summarizes the administrative, technical, and organizational safeguards maintained by bry3d llc for the BRY3D Services. It does not constitute a warranty, service-level commitment, or exhaustive description of controls. Security inquiries must be directed to admin@bry3d.com.
Encryption
- All traffic between your browser and BRY3D is encrypted with TLS (HTTPS), including embedded 3D viewers and the customer portal.
- Data is encrypted at rest by our infrastructure providers.
- Authentication credentials are protected through cryptographic controls maintained by BRY3D's authentication provider; plaintext passwords are not stored by BRY3D.
Access control and tenant isolation
- Customer records are logically associated with a designated workspace, and database-level access policies are used to enforce tenant separation.
- Role-based authorization controls restrict permitted actions within a workspace.
- Administrative access to production systems is restricted according to business need and least-privilege principles.
Infrastructure
- The Services use third-party cloud infrastructure, including Supabase and Vercel.
- Payment-card processing is provided by Stripe. BRY3D does not store complete payment-card numbers in its application databases.
- Operational monitoring and diagnostic controls are used to identify errors, service degradation, and anomalous events.
Backups and continuity
- Database backups are created on a defined schedule to support recovery objectives.
- Backups are subject to encryption and retention controls maintained by BRY3D and its infrastructure providers.
Customer-facing surfaces
- Embedded viewers, enquiry forms, and the chat assistant run in isolated contexts on your website and send data only to BRY3D endpoints.
- Customer portal access uses one-time codes sent by email — no passwords for your customers to lose.
- Quote e-signatures are recorded with a timestamped audit trail.
Data protection
Processing of personal data, including the use of sub-processors and cross-border transfer mechanisms, is governed by the Privacy Policy and the Data Processing Agreement.
Responsible disclosure
Suspected vulnerabilities must be reported to admin@bry3d.com with sufficient technical information to permit validation and reproduction. Researchers must not access, alter, retain, or disclose data belonging to another person; degrade or disrupt the Services; use social engineering; or publicly disclose a vulnerability before BRY3D has had a reasonable opportunity to investigate and remediate it. BRY3D will not initiate legal action solely for good-faith security research conducted in compliance with these requirements, subject to applicable law.