Keeping your data secure and safe

This page describes the technical and organisational measures we use to protect your data. It is the detail referred to in clause 4.1 of our data processing agreement, and it sits alongside Annex II of that agreement, which states the same measures in contractual form.

Breeze is provided by Template OÜ, a private limited company registered in the Republic of Estonia under registry code 14110689, VAT identification number EE101937247, with its registered office at Tornimäe tn 7-79, 10145 Tallinn, Estonia, trading as Breeze. Security questions, and reports of suspected vulnerabilities, go to security@breeze.pm.

Encryption

All access to the Service is over HTTPS with TLS. Requests made over plain HTTP are redirected to HTTPS, and HTTP Strict Transport Security is enforced, so browsers will not fall back. Connections to the database and to internal services are encrypted.

Database storage, file attachments in object storage and backups are encrypted at rest by our infrastructure providers. Passwords are stored as salted bcrypt hashes and are never stored or transmitted in plain text. Two-factor authentication secrets are stored encrypted.

Access control: your team

  • Individual accounts with their own credentials - logins are not shared.
  • Role-based permissions at workspace and project level, with granular control over which people and guests can see which projects.
  • Optional two-factor authentication.
  • Single sign-on with Google and Apple.
  • Session management and sign-out.

You decide who has access to what, and you remain responsible for configuring roles and permissions appropriately and for promptly removing access for people who no longer need it.

Access control: Breeze personnel

Access to production systems is limited to the small number of people who require it, is protected by multi-factor authentication, and is granted on a least-privilege basis. Access is revoked promptly when it is no longer required, and everyone with it is bound by confidentiality obligations. We do not routinely access, monitor or review the contents of customer accounts; we do so only where it is reasonably necessary, for example to provide support you have asked for, to investigate a security incident, or to comply with a legal obligation.

Tenant separation

Customer accounts are logically separated at the application layer. Every request is scoped to the authenticated user's team, workspace and project permissions, so one customer's data is never reachable from another's session.

Logging and monitoring

We run application error monitoring and performance monitoring, and we keep audit trails of changes made to your data, so a change can be attributed to the person who made it. Authentication events are recorded, including the time of sign-in and the originating IP address.

Secure development

The Service is built on a framework that provides protection against common web vulnerabilities including SQL injection, cross-site scripting, cross-site request forgery and clickjacking. Dependencies are kept current, security updates are applied, and changes are reviewed before release.

Abuse prevention

Public forms are protected by CAPTCHA, and user-supplied content is sanitised before it is stored or displayed.

Your data: export and deletion

You can export your data at any time in HTML and JSON format, delete individual user profiles and projects yourself, and cancel your account, which deletes its content immediately and irrevocably. There is no post-termination retrieval window, so export anything you want to keep before cancelling. Residual copies may persist in encrypted backups for a limited period and are overwritten in the ordinary course of the backup rotation.

Providers we rely on

We enter into written data protection terms with every provider that processes customer data, assess each one before engaging it, and publish the complete list in Annex III of the data processing agreement. We give at least 30 days' notice before adding or replacing one.

If something goes wrong

If we become aware of a personal data breach affecting your data, we will notify you without undue delay and in any event within 72 hours, describing what we know about the nature of the breach, its likely consequences, and the steps taken to address it. The full commitment is in clause 8 of the data processing agreement.

If you believe you have found a security vulnerability in Breeze, please read our vulnerability disclosure policy first - it sets out how to report, what we need from you, what is in scope and what is not - and then report it to security@breeze.pm. We do not operate a bug bounty and do not pay for reports. Our machine-readable contact details are published at /.well-known/security.txt.

AI features and the MCP connector

The AI assistant built into Breeze processes only the content your users submit to it. Separately, our MCP server lets a user connect an outside AI assistant such as ChatGPT or Claude to their own account. That connection is authorised with OAuth and, at the point of connection, the user chooses whether it gets view-only access or view plus the ability to make changes. It then acts with exactly the permissions that user already holds - it cannot reach a project or a person they could not reach themselves.

Creating several records at once, and every deletion, require a preview issued by our server and an explicit confirmation before anything is written. That gate is enforced by Breeze rather than by the assistant, so there is nothing for the assistant to talk its way around. Writes through the connector are rate limited per user. Connector requests are logged for 14 days for security, abuse prevention and troubleshooting. Searching by meaning is done with an embedding service we run on our own servers, so the words your users search for are not sent to any third-party AI provider, and we do not use your data to train machine learning or artificial intelligence models. What each request sends and what comes back is set out in our privacy policy.

Infrastructure

Breeze is hosted by Heroku, one of the leading provider of cloud computing platform-as-a-service, valued by customers for ease of use, automation, and reliability and durability. Heroku is owned by Salesforce.com. The AI assistant and the MCP connector run on separate infrastructure, as described in our GDPR page.

Data Centers

The physical infrastructure is hosted and managed within Amazon’s secure data centers and utilize the Amazon Web Service (AWS) technology. Amazon continually manages risk and undergoes recurring assessments to ensure compliance with industry standards. Amazon’s data center operations have been accredited under:

  • ISO 27001
  • SOC 1 and SOC 2/SSAE 16/ISAE 3402 (Previously SAS 70 Type II)
  • PCI DSS Level 1
  • FISMA Moderate
  • Sarbanes-Oxley (SOX)

Physical Security

Heroku utilizes ISO 27001 and FISMA certified data centers managed by Amazon. Amazon has many years of experience in designing, constructing, and operating large-scale data centers. This experience has been applied to the AWS platform and infrastructure. AWS data centers are housed in nondescript facilities, and critical facilities have extensive setback and military grade perimeter control berms as well as other natural boundary protection. Physical access is strictly controlled both at the perimeter and at building ingress points by professional security staff utilizing video surveillance, state of the art intrusion detection systems, and other electronic means. Authorized staff must pass two-factor authentication no fewer than three times to access data center floors. All visitors and contractors are required to present identification and are signed in and continually escorted by authorized staff. Amazon only provides data center access and information to employees who have a legitimate business need for such privileges. When an employee no longer has a business need for these privileges, his or her access is immediately revoked, even if they continue to be an employee of Amazon or Amazon Web Services. All physical and electronic access to data centers by Amazon employees is logged and audited routinely.

Backups and databases

Our applications are automatically backed up as part of the deployment process on secure, access controlled, and redundant storage. We use these backups to deploy the application across the platform and to automatically bring the application back online in the event of an outage Continuous Protection keeps data safe on our databases. Every change to your data is written to write-ahead logs, which are shipped to multi-datacenter, high-durability storage. In the unlikely event of unrecoverable hardware failure, these logs can be automatically 'replayed' to recover the database to within seconds of its last known state.

The platform

The platform is designed for stability, scaling, and inherently mitigates common issues that lead to outages while maintaining recovery capabilities. Our platform maintains redundancy to prevent single points of failure, is able to replace failed components, and utilizes multiple data centers designed for resiliency. In the case of an outage, the platform is deployed across multiple data centers using current system images and data is restored from backups.

Disaster recovery applications and databases

The platform we use automatically restores applications and databases in the case of an outage. The platform is designed to dynamically deploy applications within the cloud, monitor for failures, and recover failed platform components including customer applications and databases.

For additional information contact us at security@breeze.pm or see: https://www.heroku.com/policy and https://aws.amazon.com/security

See also our privacy policy, data processing agreement, GDPR page and terms of service.

Last revised: August 18, 2026