Least privilege by design. Continuity by default.
Households and private offices hold codes, documents, medical context, vendor history, and access details. Britemet treats that as operational risk, not an afterthought: one system of record with provenance you can defend.
Household Product Controls
AES-256 field encryption
Highly sensitive values (such as Wi-Fi passwords, safe and alarm codes, and optional medical notes) are encrypted at rest with AES-256-GCM and envelope keys. They stay hidden by default and decrypt only for authorized roles on explicit reveal.
Role-based by default
Owners, partners, children, sitters, and operators do not share one flat permission model. Visibility is scoped so people see the context they need, and not what they should not.
Audited sensitive actions
Reveals of vault fields and other sensitive actions are logged for accountability. Support workflows keep ticket bodies in-app rather than copying them into email.
Your data is yours
Export household data anytime. Design goals include clear retention and deletion paths, not lock-in through opacity.
Cloud controls on AWS
Production architecture targets private networking, encrypted storage, secrets outside the image, and TLS at the edge.
Specific claims only
Security language on Britemet pages describes mechanisms in the product and platform foundation (encryption, roles, audit, isolation) without overstating external audit status.
Platform foundation controls
Estate builds on the Britemet private-operations platform model: the database and infrastructure enforce non-bypassable rules so sensitive Private Office data stays encrypted, attributed, and governed.
Database as last line of defense
Classification floors, force-audit triggers, no-hard-delete paths, legal-hold blocks, dual-control gates, and tenant-consistency checks run in the data layer. The application connects as a least-privileged role and cannot skip those guards.
Per-client separation
Strong separation options include dedicated data stores and scoped AWS environments so one client’s operating records stay outside another tenant’s boundary.
Envelope encryption + blind indexes
Tier-1 fields use AES-256-GCM envelope encryption with AAD binding to client, model, record, and field. Exact-match search uses blind indexes rather than cleartext columns. Keys are managed via KMS; plaintext key material is minimized in memory.
Completeness and tamper evidence
Hash-chained audit events, append-only mutation logs, and export batches that recompute hashes from source events support verifiable history, including WORM-style export packages for evidence preservation.
Four-eyes and break-glass
Support sessions and admin overrides require dual approval, distinct executor, time limits, and single use. The normal app role cannot insert or rewrite those control-plane artifacts.
Scan, proxy, shred, hold
Malware/DLP scanning with no silent verdict downgrade; authenticated download proxy with attributed access; crypto-shred and derived-copy tracking for erasure; legal hold preservation when required.
Product pages: Estate security posture · Security FAQ · Britemet Home
Questions about security?
For diligence on Estate, or privacy questions on Home, reach out anytime.