Security Overview

Last updated 3 July 2026

A summary of how BrainVault protects your data. This is an overview, not a certification.

Tenant isolation

Every business table is scoped to a workspace and protected by database Row-Level Security, so one organisation cannot access another's ideas, files, members, evaluations, or reports.

Access control

Role-based permissions gate sensitive actions (moving ideas through governance gates, recording decisions, managing members) — enforced server-side, not just hidden in the UI.

Data protection

Data is encrypted in transit (HTTPS) and at rest by our infrastructure provider. Files are stored in private buckets and served via short-lived signed links, with size and file-type limits enforced on upload.

Auditability

Key actions — stage moves, decisions, membership changes — are written to an activity log for a who-did-what history.

Responsible disclosure

Found a security issue? Please email support@thegrowthsystem.co.za and we'll respond promptly.

This is a starter document provided for transparency and demonstration. It is not legal advice; please review with your own legal counsel before relying on it commercially.