Security

Least privilege by design. Continuity by default.

Households and private offices hold codes, documents, medical context, vendor history, and access details. Britemet treats that as operational risk, not an afterthought: one system of record with provenance you can defend.

Britemet Home

Household Product Controls

Encryption

AES-256 field encryption

Highly sensitive values (such as Wi-Fi passwords, safe and alarm codes, and optional medical notes) are encrypted at rest with AES-256-GCM and envelope keys. They stay hidden by default and decrypt only for authorized roles on explicit reveal.

Access

Role-based by default

Owners, partners, children, sitters, and operators do not share one flat permission model. Visibility is scoped so people see the context they need, and not what they should not.

Accountability

Audited sensitive actions

Reveals of vault fields and other sensitive actions are logged for accountability. Support workflows keep ticket bodies in-app rather than copying them into email.

Ownership

Your data is yours

Export household data anytime. Design goals include clear retention and deletion paths, not lock-in through opacity.

Platform

Cloud controls on AWS

Production architecture targets private networking, encrypted storage, secrets outside the image, and TLS at the edge.

Clarity

Specific claims only

Security language on Britemet pages describes mechanisms in the product and platform foundation (encryption, roles, audit, isolation) without overstating external audit status.

Britemet Estate

Platform foundation controls

Estate builds on the Britemet private-operations platform model: the database and infrastructure enforce non-bypassable rules so sensitive Private Office data stays encrypted, attributed, and governed.

Substrate

Database as last line of defense

Classification floors, force-audit triggers, no-hard-delete paths, legal-hold blocks, dual-control gates, and tenant-consistency checks run in the data layer. The application connects as a least-privileged role and cannot skip those guards.

Isolation

Per-client separation

Strong separation options include dedicated data stores and scoped AWS environments so one client’s operating records stay outside another tenant’s boundary.

Crypto

Envelope encryption + blind indexes

Tier-1 fields use AES-256-GCM envelope encryption with AAD binding to client, model, record, and field. Exact-match search uses blind indexes rather than cleartext columns. Keys are managed via KMS; plaintext key material is minimized in memory.

Audit

Completeness and tamper evidence

Hash-chained audit events, append-only mutation logs, and export batches that recompute hashes from source events support verifiable history, including WORM-style export packages for evidence preservation.

Privileged access

Four-eyes and break-glass

Support sessions and admin overrides require dual approval, distinct executor, time limits, and single use. The normal app role cannot insert or rewrite those control-plane artifacts.

Files & erasure

Scan, proxy, shred, hold

Malware/DLP scanning with no silent verdict downgrade; authenticated download proxy with attributed access; crypto-shred and derived-copy tracking for erasure; legal hold preservation when required.

Product pages: Estate security posture · Security FAQ · Britemet Home

Questions about security?

For diligence on Estate, or privacy questions on Home, reach out anytime.

Contact us