Security Overview

Version: 6.0  ·  Effective Date: June 15, 2026  ·  Last Updated: June 15, 2026

EXECUTIVE SUMMARY

brainCloud is a cloud-based Backend-as-a-Service (“BaaS”) platform supporting game developers, studios, publishers, and enterprise customers operating mobile, console, PC, web, and cross-platform applications.

brainCloud provides backend services including authentication, player management, cloud code, analytics, matchmaking, multiplayer services, commerce, live operations, messaging, AI integrations, and platform integrations.

Security, privacy, reliability, and operational transparency are fundamental principles of the brainCloud platform.

This Security Overview provides a high-level description of brainCloud’s security governance, operational safeguards, privacy practices, infrastructure protections, and security controls.

This document should be read together with the:

Additional security, privacy, operational, and compliance information is available through the brainCloud Trust Center at https://getbraincloud.com/trust/.

SECURITY PRINCIPLES

brainCloud’s security program is guided by:

  • Secure by Design
  • Least Privilege
  • Defense in Depth
  • Continuous Improvement

Security Governance

Security Program

brainCloud maintains an information security program designed to support the confidentiality, integrity, and availability of systems, services, and information.

The program is supported through documented policies, operational procedures, technical controls, risk management processes, and ongoing review activities.

Security considerations are incorporated throughout product development, infrastructure operations, customer support, supplier management, and business operations.

Governance Framework

brainCloud maintains documented policies addressing areas including:

  • Information Security
  • Access Control
  • Risk Management
  • Secure Development
  • Change Management
  • Vulnerability Management
  • Logging & Monitoring
  • Business Continuity
  • Backup & Recovery
  • Supplier Security
  • Data Protection
  • Privacy Management
  • Incident Response

Policies are periodically reviewed and updated to reflect evolving technologies, threats, legal requirements, and operational practices.

Continuous Improvement

Security controls, operational procedures, and governance practices are reviewed and improved on an ongoing basis.

Lessons learned from operational activities, incidents, customer feedback, and risk assessments may be incorporated into future improvements.

Risk Management

brainCloud utilizes a risk-based approach to security and operational management.

Risk Identification

Security risks may be identified through:

  • Security Reviews
  • Vulnerability Assessments
  • Monitoring Activities
  • Incident Investigations
  • Change Management Reviews
  • Supplier Assessments
  • Customer Reports

Risk Assessment

Identified risks are evaluated based on:

  • Potential Impact
  • Likelihood
  • Operational Exposure
  • Business Consequences

Risk Treatment

  • Risks may be mitigated through:
  • Technical Controls
  • Administrative Controls
  • Operational Controls
  • Monitoring Activities
  • Process Improvements

Shared Responsibility Model

Security is a shared responsibility between brainCloud and its customers.

Public BaaS

Responsibility AreabrainCloudCustomer
Platform Infrastructure
Platform Availability
Platform Security Controls
Customer Applications
End User Management
Customer Content
Data Classification
Integrations

Customers remain responsible for the security of their applications, business processes, end users, integrations, credentials, and data processing activities.

BYOC and Private Deployments

Certain customers may operate brainCloud using private deployment or Bring Your Own Cloud (“BYOC”) models.

In such arrangements, responsibility for infrastructure security, operating systems, networking, cloud services, and related controls may reside with the customer.

Applicable responsibilities are governed by separate commercial agreements.

Identity & Access Management

brainCloud maintains access control measures designed to limit access to authorized personnel.

Least Privilege

Access is granted according to business requirements and operational responsibilities.

Role-Based Access

Access permissions may be assigned according to job responsibilities and operational needs.

Administrative Access

Administrative access is restricted to authorized personnel with legitimate operational requirements.

Access Reviews

Access rights may be periodically reviewed and adjusted as responsibilities change.

Account Lifecycle Management

Processes exist to support account provisioning, modification, suspension, and removal.

Secure Development Lifecycle

Security considerations are incorporated throughout the software development lifecycle.

Design

Security requirements may be considered during architecture and design activities.

Development

Development practices may include:

  • Peer Review
  • Code Review
  • Defect Tracking
  • Secure Coding Practices
  • Release Validation
  • Defect Management
  • Security Issue Tracking

Testing

Software may undergo testing and validation activities before deployment.

Change Management

Changes to production systems are governed by change management procedures intended to reduce operational risk.

Release Management

Production deployments are managed through established operational processes.

Infrastructure Security

brainCloud services are hosted using cloud infrastructure providers and supporting operational services.

Hosting Providers

Public BaaS services currently support deployment on:

  • Amazon Web Services (AWS)
  • Google Cloud Platform (GCP)
  • Microsoft Azure

Infrastructure Controls

Infrastructure protections may include:

  • Network Controls
  • Segmentation
  • Monitoring
  • Availability Controls
  • Access Restrictions
  • Configuration Management

Redundancy

Operational architectures may incorporate redundancy and resilience measures designed to support service availability.

Cryptography & Data Protection

brainCloud utilizes cryptographic technologies intended to protect information during storage and transmission.

Encryption in Transit

Information transmitted across networks may be protected using secure communication protocols.

Encryption at Rest

Stored information may be protected using encryption technologies where appropriate.

Key Management

brainCloud maintains key management practices intended to support secure use of cryptographic controls.

Data Classification

Information may be classified and handled according to sensitivity and operational requirements.

Data Retention

Retention and deletion practices are governed by documented policies and applicable legal requirements.

Monitoring & Logging

brainCloud maintains monitoring and logging capabilities designed to support operational awareness and security activities.

Monitoring

Monitoring activities may include:

  • Infrastructure Monitoring
  • Service Monitoring
  • Performance Monitoring
  • Operational Alerting

Logging

Operational and security events may be logged to support:

  • Troubleshooting
  • Investigations
  • Incident Response
  • Operational Analysis

Alerting

Monitoring systems may generate alerts when operational or security thresholds are exceeded.

Vulnerability Management

brainCloud maintains processes intended to identify, evaluate, prioritize, and remediate vulnerabilities.

Identification

Vulnerabilities may be identified through:

  • Internal Reviews
  • Monitoring
  • Customer Reports
  • Security Researcher Reports

Evaluation

Potential vulnerabilities are reviewed and assessed according to risk and operational impact.

Remediation

Remediation efforts may include:

  • Patching
  • Configuration Changes
  • Infrastructure Updates
  • Software Updates

Responsible Disclosure

Security vulnerabilities reported through approved channels are reviewed and investigated.

Backup, Recovery & Resilience

brainCloud maintains operational practices designed to support resilience and recovery.

Backup Practices

Operational backups may be utilized to support restoration activities.

Recovery Planning

Recovery procedures are maintained to support restoration of affected systems and services.

Business Continuity

Business continuity planning activities are intended to support continued operation during disruptive events.

Third-Party Providers & Subprocessors

brainCloud utilizes third-party providers to support:

  • Hosting
  • Communications
  • Customer Support
  • Analytics
  • Payment Processing
  • AI Services
  • Infrastructure Operations

brainCloud maintains supplier management processes intended to evaluate and manage supporting providers.

AI providers are subject to the same general supplier management and subprocessor review processes applied to other third-party providers.

Current subprocessors are identified in the brainCloud Subprocessor List.

Privacy, Data Protection & Compliance

brainCloud supports customer privacy obligations through technical, operational, and administrative safeguards.

Governing Documents

Privacy-related activities are governed by:

Customer Responsibilities

Customers remain responsible for determining the legality of their collection, use, disclosure, and processing of personal information.

International Transfers

Cross-border data processing activities are governed by applicable agreements and legal requirements.

Incident Response

brainCloud maintains incident response procedures intended to support:

  • Detection
  • Investigation
  • Escalation
  • Containment
  • Remediation
  • Recovery
  • Communication

Incident Handling

Security incidents are evaluated according to their nature, severity, and potential impact.

Customer Communication

Where required by law, contractual obligations, or operational necessity, notifications may be provided to affected customers.

Post-Incident Review

Operational reviews may be conducted following significant incidents to identify improvements and corrective actions.

Security Awareness & Training

brainCloud personnel may receive security awareness and operational training designed to support responsible handling of systems, information, and customer data.

Training activities may include:

  • Security Awareness
  • Acceptable Use Requirements
  • Incident Reporting Procedures
  • Privacy Awareness
  • Operational Security Practices

Security Contact Information

Security inquiries, vulnerability reports, and security-related questions may be directed to:

Security Contact: <se******@***********ud.com>

Additional information is available through:

Related Documents

Customers may refer to the following documents for additional information:

DISCLAIMER

This Security Overview is provided solely for informational purposes.

Nothing contained in this document creates contractual commitments, warranties, certifications, service level guarantees, or representations beyond those expressly set forth in applicable agreements.

brainCloud may update this document from time to time as technologies, operational practices, legal requirements, and security programs evolve.

Thanks for Connecting!

We’ll get back to you as soon as we can.