Add the archive. Keep every control.
Identity, access, integrations, hosting and security controls. This page lays out how Brolly introduces social media archiving and governance without weakening any of them, and where the documentation for your vendor assessment lives.
30-day free trial · no credit card · unlimited accounts and users
What this team is accountable for.
Another vendor is another identity boundary, another data path and another questionnaire. Here is the assessment Brolly expects to face.
Identity and access
Who can sign in, what each role can reach and proof it stays that way. A new tool has to fit the access model you already enforce, not dilute it.
Vendor assessment and assurance
Questionnaires, certifications, penetration-test evidence and the recurring reviews that follow. Answers should come from controls, not from a sales deck.
Data governance
What data the vendor touches, how it is encrypted in transit and at rest, who processes it and how it leaves in an export. Hosting questions get asked here first.
Integration surface
Every API connection is surface area until it is reviewed. Scopes, authorisations and third-party access need to be explicit, minimal and revocable.
Where evaluations stall.
Most archiving evaluations do not fail on the technology. They fail on how the vendor behaves under assessment.
Opaque vendors
Security pages with badges and nothing behind them. If certification documents and test evidence are not available for review, the assessment cannot finish.
Per-seat pricing pressure
Per-seat licensing quietly pushes teams toward shared logins, which erase individual accountability. Brolly includes unlimited users, so every person has their own account.
Unclear data paths
If a vendor cannot say what it connects to, what scopes it requests and how data is encrypted and exported, you are left to reverse-engineer the answer yourself.
Marketing answers
A security questionnaire answered in marketing language is a red flag on its own. Yours should come back with specifics you can verify.
What review actually finds.
Examples show the product with fictional demonstration data.
Every person gets their own account
Access is protected by multi-factor authentication and role-based access controls: records staff, communications and counsel each see what their role requires. Because users are unlimited, there is no per-seat math pushing anyone toward a shared login.
- Multi-factor authentication on user accounts
- Role-based access scoped to what each role requires
- Unlimited users, so shared credentials never become the workaround
- Sign-ins, searches, exports and role changes are logged
Certified, not self-declared
Brolly is certified against ISO/IEC 27001:2022 and registered with the Cloud Security Alliance STAR program, with controls aligned to NIST SP 800-53. The platform runs on AWS across multiple availability zones. The full picture, including hosting and privacy practices, lives on the security page.
- ISO/IEC 27001:2022 certified information security management system
- CSA STAR registered; controls aligned to NIST SP 800-53
- AES-256 encryption at rest, TLS 1.3+ in transit, checksums on exports
- Independent penetration testing, with summaries available under NDA
A small, explicit integration surface
Capture is supported content from the accounts your organisation connects, through the platforms’ official APIs, read-scoped where the platforms allow. Brolly is not designed to track or profile individuals across unrelated accounts, customers, services or locations.
- Official platform APIs across Facebook, Instagram, Threads, X, YouTube, LinkedIn and TikTok
- Authorisation through the platforms’ own API mechanisms; no passwords are shared with Brolly
- Hootsuite and OpenText (Micro Focus) Content Manager integrations
- Exports in open formats: PDF, CSV, HTML and JSON
Clear lines, no new ambiguity.
Brolly lands cleanly because the responsibilities stay where they already are.
Records owns retention
Retention schedules and disposal decisions belong to your records program. Brolly never disposes of records on its own, and disposal actions are logged.
Comms owns publishing
Publishing and community management stay in the tools your communications team already uses. Brolly preserves supported content alongside them rather than replacing them.
IT owns identity and assessment
Your team decides who gets an account, what each role can reach and whether the vendor clears review. Nothing in the rollout asks you to loosen that.
What IT asks first.
How is access to the archive controlled?
What does Brolly connect to, and with what permissions?
Where do the security documents live?
Does connecting our accounts weaken their security?
Where is our data hosted?
Send the questionnaire first.
A 20-minute walkthrough for IT and security: authentication, scopes, data paths and the documents your assessment needs, with certification documents and pen-test summaries available under NDA.