Breva's security controls have been independently examined under SOC 2 Type II. The platform runs on Google Cloud Platform, and bank connections are tokenized through Stripe Financial Connections — your banking credentials never touch Breva's systems.
SOC 2 Type II audit performed annually by a third-party firm. Controls are tested over time, not just at a point in time.
TLS 1.3 protects data in transit. AES-256 encryption protects data at rest in Google Cloud Platform.
Bank and partner credentials are tokenized whenever possible and never stored on Breva servers.
Multi-factor authentication, role-based permissions, and SOC 2-aligned audit logging on every sensitive action.
Export your data, delete your account, and revoke partner access at any time. You own your books.