Briefs are meant to be shared, but sharing should always be your decision. Access control, authentication, and encryption are built in so you can open a Brief to the world or lock it to your team with equal confidence.
Each Brief is public, private, or internal to your organization. Private Briefs are gated so only authorized users and agents can read them, and permissions are enforced on every fetch, whether through the web, the MCP server, or the REST API.
Programmatic access is authenticated with OAuth or personal access tokens scoped to the access you intend to grant. Tokens can be revoked at any time, so automation and agents never carry more permission than they need.
Organizations get a shared namespace with member and admin roles and per-Brief collaborators. Ownership and edit rights are explicit, so you always know who can change a Brief and who can read it.
Enterprise plans support domain-verified SSO for centralized, company-wide access. Provision and de-provision access through your identity provider so joiners and leavers are handled in one place.
Briefs runs on Google Cloud. All traffic is served over HTTPS with TLS, and data is encrypted at rest by the underlying managed infrastructure.
Enterprise customers can request a security review, complete vendor questionnaires, and put service-level agreements in place. Reach out and we’ll work through your requirements.
We take security reports seriously and appreciate the researchers who help keep Briefs safe. If you believe you’ve found a vulnerability, email us with the details and steps to reproduce. Please give us a reasonable window to investigate and remediate before any public disclosure.
We’re happy to walk your security team through our controls, complete a questionnaire, or scope SSO and SLAs for your organization.