trust
last updated 2026-07-28 · production · operated by flndrn Limited (Cyprus)
enterprise auth
Briven Auth is built for multi-app products that need day-to-day login and company IT controls. Enterprise surfaces include:
- SAML 2.0 + OIDC SSO — employees sign in with the company identity provider (Okta, Entra, Google Workspace, custom OIDC).
- SCIM 2.0 — HR/IT systems can auto-add and remove users (and map groups into Briven orgs).
- Compliance pack — DPA / BAA templates and retention notes available to project owners via the dashboard API (sales kit). Final contracts are signed with flndrn Limited; flags are recorded per project after signature.
- Audit + retention — auth audit and app logs with configurable retention windows.
Subprocessors list: /subprocessors. Status: /status.
where data lives
Production API runs in the EU (France host for api.briven.tech). Customer project data is isolated per project in the data plane. Team and enterprise needs (dedicated capacity, residency questions) are handled case-by-case — contact sales / legal.
encryption
- TLS on every public endpoint.
- Per-project env vars: AES-256-GCM at rest with a platform-held KEK.
- Session cookies: HTTP-only, Secure in production.
- API / SCIM / SDK keys: SHA-256 hashed; only short suffixes displayed.
access & audit
Platform mutations (deploy, member change, env edit, key revoke) are written to an append-only audit log. Auth-tenant events live in the project's auth audit stream. IPs are hashed before storage where privacy policy requires it.
incident disclosure
We aim to disclose incidents that affect customer data within 72 hours of detection to affected accounts and publish a post-mortem here within 30 days when material. Report security issues to security@flndrn.com.
legal contacts
Privacy & DPA: legal@flndrn.com · Operator: flndrn Limited, Limassol, Cyprus. Terms and privacy live under this site's legal section.