Certifications and Compliance
- SOC 2 Type I and Type II:Β Bronto has completed both its SOC 2 Type I and SOC 2 Type II audits, and maintains SOC 2 Type II compliance through recurring audits. Current SOC 2 reports and bridge letters are available on request from the Bronto Trust Center.
- GDPR Compliance:Β Ensures the privacy and protection of personal data for customers in the EU, adhering to the General Data Protection Regulation.
- CCPA Compliance:Β Guarantees the privacy and protection of personal data for customers in California, in accordance with the California Consumer Privacy Act (CCPA). Requests related to CCPA can be addressed by contactingΒ support@bronto.io.
- Continuous Compliance Monitoring:Β Utilizes advanced tools and systems to continuously monitor compliance with security standards and regulations, promptly addressing any gaps.
Comprehensive Security Measures
Bronto employs a comprehensive approach to data security, encompassing encryption, penetration testing, system protection, and robust organizational measures.Data Encryption
At Bronto, data is encrypted both at rest and in transit, adhering to industry standards and undergoing regular audits to ensure maximum security.- Data at restΒ is stored within Amazon Web Services (AWS) infrastructure and secured with AES-256 bit encryption provided by AWS technologies.
- Data in transitΒ is protected using AES-256 bit encryption and TLS to secure network traffic.
Data Residency
Bronto currently offers two regional environments: one where data is ingested and stored in the EU, and one where data is ingested and stored in the US. You select your region when creating your Bronto account. The EU and US environments are isolated from each other. Data sent to the EU environment remains in EU data centres, and data sent to the US environment remains in US data centres. After selecting a region, configure your agents, collectors, and integrations to send data to the matching Bronto ingestion endpoint. See Ingestion Endpoints and Connect OpenTelemetry Collector to Bronto for regional endpoint details.Penetration Testing
Bronto conducts regular vulnerability scans and annual third-party penetration tests to proactively identify and mitigate potential security threats. The latest penetration test reports are available on request from the Bronto Trust Center.System Protection and Resilience Against Failure
Bronto systems are segmented into separate networks and protected by restrictive firewalls and Virtual Private Networks (VPNs) to secure network traffic and prevent unauthorized access. Network segmentation isolates sensitive data and systems. Regular backups and tested data recovery procedures ensure business continuity. Additionally, vulnerability assessments and patch management processes are in place to guard against known vulnerabilities.Organisational Security Practices
Brontoβs commitment to security extends beyond technological measures to include comprehensive organizational practices:- Employee Training:Β All employees receive regular training on security best practices, including phishing awareness, data handling procedures, and incident response protocols.
- Stringent Security Requirements:Β We enforce stringent security measures such as encrypted storage and two-factor authentication.
- Security Policies:Β Our comprehensive and regularly updated policies cover all aspects of data protection and compliance, ensuring robust governance.
- Incident Response:Β A thorough response plan is in place for the prompt identification, assessment, mitigation, and remediation of security incidents, with predefined procedures for effective handling.
- Continuous Monitoring:Β We utilize Intrusion Detection Systems (IDS) for real-time threat detection and analysis.

