Who we help · IT & security teams

Add the archive. Keep every control.

Identity, access, integrations, hosting and security controls. This page lays out how Brolly introduces social media archiving and governance without weakening any of them, and where the documentation for your vendor assessment lives.

30-day free trial · no credit card · unlimited accounts and users

Your remit

What this team is accountable for.

Another vendor is another identity boundary, another data path and another questionnaire. Here is the assessment Brolly expects to face.

Identity

Identity and access

Who can sign in, what each role can reach and proof it stays that way. A new tool has to fit the access model you already enforce, not dilute it.

Assessment

Vendor assessment and assurance

Questionnaires, certifications, penetration-test evidence and the recurring reviews that follow. Answers should come from controls, not from a sales deck.

Data

Data governance

What data the vendor touches, how it is encrypted in transit and at rest, who processes it and how it leaves in an export. Hosting questions get asked here first.

Surface

Integration surface

Every API connection is surface area until it is reviewed. Scopes, authorisations and third-party access need to be explicit, minimal and revocable.

The friction

Where evaluations stall.

Most archiving evaluations do not fail on the technology. They fail on how the vendor behaves under assessment.

Opacity

Opaque vendors

Security pages with badges and nothing behind them. If certification documents and test evidence are not available for review, the assessment cannot finish.

Shared logins

Per-seat pricing pressure

Per-seat licensing quietly pushes teams toward shared logins, which erase individual accountability. Brolly includes unlimited users, so every person has their own account.

Data paths

Unclear data paths

If a vendor cannot say what it connects to, what scopes it requests and how data is encrypted and exported, you are left to reverse-engineer the answer yourself.

Questionnaires

Marketing answers

A security questionnaire answered in marketing language is a red flag on its own. Yours should come back with specifics you can verify.

A better operating position

What review actually finds.

Examples show the product with fictional demonstration data.

Access control

Every person gets their own account

Access is protected by multi-factor authentication and role-based access controls: records staff, communications and counsel each see what their role requires. Because users are unlimited, there is no per-seat math pushing anyone toward a shared login.

  • Multi-factor authentication on user accounts
  • Role-based access scoped to what each role requires
  • Unlimited users, so shared credentials never become the workaround
  • Sign-ins, searches, exports and role changes are logged
Platform security

Certified, not self-declared

Brolly is certified against ISO/IEC 27001:2022 and registered with the Cloud Security Alliance STAR program, with controls aligned to NIST SP 800-53. The platform runs on AWS across multiple availability zones. The full picture, including hosting and privacy practices, lives on the security page.

  • ISO/IEC 27001:2022 certified information security management system
  • CSA STAR registered; controls aligned to NIST SP 800-53
  • AES-256 encryption at rest, TLS 1.3+ in transit, checksums on exports
  • Independent penetration testing, with summaries available under NDA
Integration surface

A small, explicit integration surface

Capture is supported content from the accounts your organisation connects, through the platforms’ official APIs, read-scoped where the platforms allow. Brolly is not designed to track or profile individuals across unrelated accounts, customers, services or locations.

  • Official platform APIs across Facebook, Instagram, Threads, X, YouTube, LinkedIn and TikTok
  • Authorisation through the platforms’ own API mechanisms; no passwords are shared with Brolly
  • Hootsuite and OpenText (Micro Focus) Content Manager integrations
  • Exports in open formats: PDF, CSV, HTML and JSON
Working with other teams

Clear lines, no new ambiguity.

Brolly lands cleanly because the responsibilities stay where they already are.

Records

Records owns retention

Retention schedules and disposal decisions belong to your records program. Brolly never disposes of records on its own, and disposal actions are logged.

Communications

Comms owns publishing

Publishing and community management stay in the tools your communications team already uses. Brolly preserves supported content alongside them rather than replacing them.

IT & security

IT owns identity and assessment

Your team decides who gets an account, what each role can reach and whether the vendor clears review. Nothing in the rollout asks you to loosen that.

Security review

What IT asks first.

How is access to the archive controlled?
Through multi-factor authentication and role-based access: records staff, communications and counsel each see what their role requires. Brolly includes unlimited users, so every person signs in with their own account and shared logins never become the workaround. Sign-ins, searches, exports and role changes are logged.
What does Brolly connect to, and with what permissions?
Brolly captures supported content from the accounts your organisation connects, through the platforms’ official APIs, read-scoped where the platforms allow. Supported platforms are Facebook, Instagram, Threads, X, YouTube, LinkedIn and TikTok. Brolly is not designed to track or profile individuals across unrelated accounts, customers, services or locations.
Where do the security documents live?
Start at the security and trust centre, which covers certifications, encryption, access controls and privacy in one place. Certification documents, penetration-test summaries and completed security questionnaires are available under NDA on request.
Does connecting our accounts weaken their security?
No credentials are shared with Brolly or between staff. Capture runs on authorisation granted through the platforms’ own API mechanisms, read-scoped where the platforms allow, and your administrators can review or revoke that access from the platform side at any time.
Where is our data hosted?
The platform runs on AWS across multiple availability zones, with AES-256 encryption at rest and TLS 1.3+ in transit. For hosting and residency specifics relevant to your assessment, start at the security page; detailed documentation is available under NDA.

Send the questionnaire first.

A 20-minute walkthrough for IT and security: authentication, scopes, data paths and the documents your assessment needs, with certification documents and pen-test summaries available under NDA.