Brightest
  • πŸ‘‹Welcome to Brightest
  • Overview
    • πŸ’‘Brightest 101
    • πŸ”…New Client Onboarding Sequence
    • ✨Key Brightest Capabilities
  • Fundamentals
    • πŸ› οΈGetting set up
      • πŸ‘©β€πŸ’ΌGetting Started for Brightest Admins
      • πŸ“User Permissions
      • πŸ“¨Inviting Team Members
        • πŸ”‘Two-Factor Authentication
      • πŸ–ΌοΈOrganization Settings
        • πŸ“ΆESG and Sustainability Settings
      • πŸ”“Single Sign-on (SSO)
        • πŸ‡«πŸ‡²Microsoft SSO
        • πŸ‡«πŸ‡²Okta SSO
    • πŸ“‹Navigating Brightest
  • Product Guides
    • πŸ“ŠKPIs and Custom Metrics
      • ℹ️Creating a KPI
      • ℹ️Linking KPIs to Global licenses
      • πŸ—‚οΈOrganizing your KPIs
        • KPIs & Global licenses
      • πŸ’»Entering KPI data
    • 🎯Goals and Targets
      • β›³Setting Goals
      • Uploading Data to Goals
      • πŸ“‰Setting Environmental or Climate Related Targets
      • πŸ“ŠMateriality (single)
    • βš–οΈDouble Materiality
      • 🌐Double Materiality in Brightest
    • 🌎CSR & Impact
    • ⚑Actions
    • πŸ“₯Surveys
      • πŸ“‘How to make a survey
        • Survey form features
    • πŸ‘₯Partners
    • 🏒Assets
      • πŸ—οΈBulk Asset Creation
    • ☁️Carbon Accounting
      • πŸŒ₯️How Carbon Accounting Works in Brightest
      • βž—Emissions Factors
      • πŸ‘©β€πŸ”¬Configuring and Customizing Emissions Factors
      • 1️⃣Scope 1 GHG
      • 2️⃣Scope 2 GHG
      • 3️⃣Scope 3 GHG
    • 🌿Collecting and Importing Sustainability Data
      • πŸ‘£Uploading Asset Footprint Data
        • Using the Add Tool
          • Adding Water Data
          • Adding Fuel Data
          • Adding Waste Data
        • Uploading CSV Files
        • Uploading Utility Invoices
      • πŸš›Uploading Transit Data
      • πŸ’±Financial Transaction (Spend) Data
        • πŸ’ΈSpend Capabilities
      • πŸ›οΈProduct and Materials Data
    • 🚩Tags
    • πŸ“ESG & Sustainability Reporting
      • ESG Reporting Standards & Frameworks in Brightest
  • Use Cases
    • 🏭GHG Emissions Measurement
    • πŸ–₯️Brightest for IT Teams
  • Roadmap
    • πŸ”†Our Product Roadmap
  • FAQs and Support
    • ❓FAQs
    • πŸ“§Contact Us
Powered by GitBook
On this page
  1. Use Cases

Brightest for IT Teams

PreviousGHG Emissions MeasurementNextOur Product Roadmap

Last updated 29 days ago

Documentation coming soon: this page is still under construction, please check back soon.

Brightest Offers Enterprise Grade Security to Protect Your Data and Reduce Your Risk.

At Brightest, we closely integrate web application security and privacy best practices throughout our development, web architecture, and DevOps processes, allowing us to provide enterprise-ready social impact, sustainability, corporate social responsibility (CSR), and environmental social governance (ESG) software that meets your security controls and requirements, earns your trust, and complies with international data privacy laws.

Today, our clients include governments, publicly-traded companies, and organizations operating in highly-regulated industries, thanks to the strength and consistency of our security controls and risk management practices.

The AWS data center infrastructure used to provide all Brightest services by default is located in the United States, however AWS also offers us the flexibility to relocate your data storage and application servers to a European Union (EU) data center in either Germany or Ireland if and where your organization needs to comply with GDPR and EU data compliance laws. The cloud IT infrastructure AWS provides Brightest is designed and managed to meet security best practices and a variety of IT security standards, including:

β€’ SOC 1/SSAE 16/ISAE 3402 (formerly SAS 70)

β€’ SOC 2

β€’ SOC 3

β€’ FISMA, DIACAP, and FedRAMP

β€’ DOD CSM Levels 1-5

β€’ PCI DSS Level 1

β€’ ISO 9001 / ISO 27001 / ISO 27017 / ISO 27018

β€’ NIS 2 Directive (Directive (EU) 2022/2555)

The AWS infrastructure platform provides gives Brightest web, file, and database hosting infrastructure that meets the following standards:

β€’ Criminal Justice Information Services (CJIS)

β€’ Cloud Security Alliance (CSA)

β€’ Family Educational Rights and Privacy Act (FERPA)

β€’ Health Insurance Portability and Accountability Act (HIPAA)

β€’ Motion Picture Association of America (MPAA)

International Data Compliance

In addition to ensuring strong controls within our application technology, architecture, and hosting provider ecosystem, we also take dedicated, diligent internal steps at Brightest to monitor and assess our security programs and effectiveness to mitigate any vulnerabilities or issues. That includes:

β€’ Third party security assessments and penetration tests

β€’ 24/7 application security and performance monitoring and log analysis using systems like Sentry, NewRelic, Papertrail, CloudWatch, and other systems

β€’ Routine vulnerability scanning

β€’ Strict access controls (requiring 2FA) and employee security training

β€’ Routine, internal testing and business continuity planning

β€’ Ongoing maintenance of our Information Security Management System (ISMS) policies and procedures. Our corporate ISMS policy applies to all Brightest management, staff, contractors, and third-party service providers under contract, who have any access to, or involvement with, the business processes, information assets, and supporting IT assets and processes covered under the scope of our ISMS.

Enterprise and Employee (Individual) Data Privacy

Whatever your company’s data privacy and IT security needs are, Brightest can be configured to meet them.

For more information on our cloud hosting and database security levels, please see AWS's security resources and policies at and

To read more about AWS GDPR compliance, please see and AWS'

We work closely with third party privacy and security firms and vendors to ensure our platform meets international data protection, privacy, and processing standards. Brightest's Data Processing Agreements comply with all applicable GDPR requirements, and we completed a GDPR assessment verified by in February, 2021. Brightest is also compliant with US state and federal data security laws, including the California Consumer Privacy Act (CCPA).

For more information on our privacy and data processing policies, please see our .

If you have any questions or comments about our security policies, approach, work, or information, or would like to report a security concern please .

Our technology, with built-in roles, permissions, access levels, and data environments, is designed and implemented to ensure your company’s information is only accessible by authorized individuals. Where needed, Brightest can support corporate directory single-sign on (SSO), Security Assertion Markup Language (SAML), Multi-Factor Authentication (MFA), and identity provider (IDP)or HR information system (HRIS) integrations to provide secure directory sync and access privileges between your company's Brightest use and employee access, roles, permissions, and user authentication. Brightest can work with IDPs like Microsoft Active Directory, Okta, Auth0, Shibboleth, and others, and we're an .

We take additional steps to verify that any 3rd party service provider integrated into Brightest: (1) conducts background checks on all new employees, (2) enforces info security training for all employees, (3) offers secure, stable, modern web application infrastructure and technologies that are widely used in the industry by best-in-class companines, (4) is regularly audited by 3rd party monitoring organizations, and (5) is PCI-compliant and complies with other modern information security and IMS standards like ISO/IEC 27001 and SOC 2. Our only third-party service providers integrated into our application that can receive personal information (PIIA) beyond AWS are and for transactional user email notifications and donation reciept emails, both of whom meet these strict requirements.

πŸ–₯️
https://aws.amazon.com/security/
https://docs.aws.amazon.com/whitepapers/latest/introduction-aws-security/introduction-aws-security.pdf
https://aws.amazon.com/blogs/security/all-aws-services-gdpr-ready/
GDPR data processing addendum
Osano
privacy policy
contact us here
ADP developer marketplace partner
Stripe
Twilio Sendgrid