BriefTether guide

Security and service limits

Practical protections, clear storage limits, and explicit control over AI requests.

Updated 9 October 2026 · Free early access

Account and workspace controls

Passwords are stored as hashes. Recovery codes support password recovery without an email provider. Recovery and account deletion invalidate old sessions. Authenticated access checks restrict projects to their owning account, and request protection guards state-changing actions. Keep passwords and recovery codes private.

Cloud storage and application keys

The live website and API run on Cloudflare Workers, with persistent project data in D1. Cloudflare manages storage encryption and protected transport. Authorized application and platform access can read the data; this is not end-to-end encryption. See D1's security controls.

Gemini and Claude credentials are separately encrypted with AES-GCM for each account and provider, with encryption material supplied through Worker secrets. Keys are never returned after saving. A prepared connection is transferred only to the invited first operator; this does not grant other users access to it. Local development files do not serve the live website.

Document and quotation handling

Document processing applies file and content bounds. The service extracts text from supported files rather than treating them as executable content. Exact source and evidence excerpts are checked against the selected project document. This verifies a text match, not the truth of an agency's capability statement.

Baselines store an immutable snapshot of requirement rows and source text so later edits do not rewrite the earlier reference. Remove unnecessary personal or confidential content before upload and review exports before sharing them.

Explicit AI requests

Only an extraction request with selected documents and explicit consent sends text to the selected provider: Google's official Gemini API or Anthropic's official Claude API. The screen identifies the actual destination. Draft candidates are not automatically saved as commitments, and invalid responses produce visible errors.

Google unpaid-service use requires an additional non-sensitive-content confirmation and must satisfy the provider's regional terms. See the privacy notice. Quota errors do not automatically retry, switch provider, or start a paid fallback.

Request budgets rely on configured prices and estimated usage, not a guarantee of the final charge. A single local Gemini test used a public fictional brief. It is not a general quality or cloud-inference result. Live Claude extraction remains untested.

No external tracking assets

The interface loads local assets and self-hosted or system fonts. It includes no external font CDN, advertising script, or third-party analytics tracker. Optional AI requests and external links are separate user actions.

Backups and deletion

Account deletion removes active workspace records and encrypted API credentials. Cloudflare D1 automatically provides point-in-time recovery; the Free plan has a seven-day recovery window. Historical copies may contain data predating deletion. The operator must protect any separate exported backups and apply deletion requests when restoring data. See Time Travel documentation. No disaster-recovery service guarantee is offered.

Assurance and reporting

BriefTether does not claim SOC 2, ISO 27001, penetration-test certification, or regulatory certification. Report issues to jaypark@brieftether.com. This address has incoming domain forwarding configured; no response-time promise or outgoing-mail service is claimed. The invited operator supplies the real legal identity during setup.