Security

With the Briefly connector, client files stay on the advisor's computer.

Briefly is an AI knowledge base for financial advisors. It runs two ways, a connector inside Claude Desktop and a hosted web app you sign into through your browser. This page lays out where your client files live on each surface, what reaches our servers, and what changes under the new SEC rules for AI vendors.

Briefly's flagship product is a connector you add to Claude Desktop. One download, pick a folder on your computer, sign in, and you're set up. From there, your client files stay in that folder, not on a server somewhere. When you ask Briefly a question, it reads those files on your machine, writes the answer, and saves the draft back to the same folder. The only things that reach our servers are sign-in, a check that your seat is active, a de-identified layer of firm preferences that never carries a client's name, and a short usage record for each tool call, which carries no client file content.

Some firms run Briefly a second way, through the web app you sign into instead of installing the connector. It's priced and sold separately from the connector. For firms on the web app, client files live in Briefly's hosted environment on AWS, protected by per-firm access controls, and sign-in runs through the same account layer either way.

Where your client files live on the connector

For firms running the connector, there's no upload step in Briefly. You point it at a folder once, during setup, and everything after that happens on your own machine.

You choose the folder

During setup, you pick where on your computer Briefly reads and writes. It's a folder your firm already uses, not a location we assign.

Nothing to upload

Briefly runs inside Claude Desktop and works with files already on your machine. There's no button or portal that sends a client file anywhere.

No client-file database for connector firms

We don't operate a database of client files for firms on the connector. If someone got into Briefly's servers, there's no trove of those firms' client documents there for them to find.

What reaches Briefly's server, when you run the connector

Four things reach our servers when you run the connector, and none of them is a client file. The web app works differently, covered below.

Sign-in

Briefly checks who you are through Amazon Cognito, the identity system a large share of the software industry runs on. This confirms it's you, not anything about a client.

Seat and entitlement checks

Briefly checks that your firm's account is active and your seat is licensed before it does any work. It's a subscription check, the kind any paid software runs.

De-identified preference rules

Briefly learns patterns in how your firm likes its work done. Those patterns are tokenized before they leave your computer, so no client name or account number is attached to them.

A usage record for each tool call

Each time you run a Briefly tool, we log a short record of that call, the tool, the outcome, and a timestamp, tied to your seat and firm. It carries no content from your client files.

On the connector, client files never reach Briefly's servers. Only your sign-in, seat check, de-identified preference rules, and a per-call usage record reach Briefly's server, and none of it carries anything about a specific client. Firms on the web app work under a different model, laid out in the section below.

What Claude sees, and what Anthropic does with it

Briefly runs inside Claude, so a careful vendor review should ask about Anthropic too. Here is the full path, with nothing left out.

When an advisor asks a question, Claude reads the parts of the client file it needs to answer, straight from the folder on the advisor's computer. Anthropic processes that content to generate the answer, under your firm's own Claude agreement. Briefly never stores it, and it never touches Briefly's servers.

This is why the Claude plan matters. On Claude for Work, Claude Enterprise, and the API, Anthropic's commercial terms prohibit training models on customer content. That is a contract term, and it comes with a data processing agreement your vendor-oversight file can hold. Deleted conversations purge from Anthropic's systems within 30 days. The exception is content flagged by Anthropic's safety systems, which it can hold for up to two years. We recommend firms run Briefly on a business Claude plan.

Personal Claude plans work differently, and the difference is worth writing down. Conversations on a Free, Pro, or Max account train Anthropic's models unless training is turned off in privacy settings, and content used for training is kept for up to five years. Anthropic's July 2026 policy update also allows conversations flagged by its safety systems to be used for model improvement even after a user opts out, with flagged content held for up to two years. An advisor can run Briefly this way, and a compliance officer will reasonably prefer the business plan's written terms.

One more fact a thorough vendor review will surface. Since June 2026, even Anthropic's zero-retention API arrangements carry a 30-day retention window on its newest models for safety monitoring. No tool built on a frontier model can honestly promise that nothing is ever retained, so the questions worth asking a vendor are where files are stored, whose agreement governs the processing, and what the vendor itself holds.

The short version for your vendor file. Client files are stored only in your folder. Processing happens under your firm's own Claude agreement, and on a business plan Anthropic may not train on your content by contract. Briefly's servers only ever see sign-in, seat checks, de-identified preference rules, and a usage record for each tool call.

Three ways advisor AI tools handle your data

Every AI tool that touches client files falls into one of three custody models, and Briefly's two surfaces land in two different ones.

Cloud AI tools

Files get uploaded to the vendor's servers. From there, the vendor's privacy policy decides what happens next, including how long files sit there and who can review them. You're trusting a policy, not an architecture.

Briefly web app

Your firm signs in through a browser, and files live in Briefly's hosted environment on AWS, with access controls scoped to your firm. It's server-side custody, the same category as a hosted private AI tool, except we're the ones running it.

Briefly connector

Client files stay in a folder on the advisor's own computer. There's no upload and no server-side client-file store, so there's nothing of yours on our servers for a breach to reach.

What this means under Reg S-P

SEC privacy and safeguards rules, Reg S-P among them, put the duty on advisory firms to know how their vendors handle customer information, and firms are treating AI tools as part of that vendor review. That oversight duty sits with your firm, not just with us.

Both the SEC and FINRA have said publicly that they are watching how firms use and supervise AI. The practical effect is that the vendor relationship gets reviewed, not only the advisor's own desk.

No agency certifies an AI tool as SEC-approved. That label doesn't exist. What a firm can document is how a specific tool actually handles client data, which is what the rest of this page lays out.

How we secure the account layer

For connector firms, client files aren't on our servers, so what we secure there is narrower, the sign-in and entitlement system that confirms who you are and what your firm has access to. Web-app firms have files in our hosted environment too, secured the way the custody section above describes.

Sign-in

Access runs through Amazon Cognito, the identity system described above, on both surfaces. Every session ties back to your individual login and your firm's account, not a shared password.

No client-file database to isolate on the connector

For connector firms, there's no per-firm client-file database on our servers to isolate, because those files never reach our servers in the first place. For web-app firms, per-firm access controls scope each firm to its own data. Sign-in and preference records are isolated at the application level for every firm.

Encrypted transport and vendor review

Sign-in and entitlement traffic between your computer and our servers runs over encrypted connections. We review the vendors behind that layer, including AWS and Cognito, the way we'd want a vendor we depend on reviewed.

SOC 2 aligned controls

Our security program is built around the SOC 2 Trust Services Criteria, applied to the systems we actually run, sign-in and entitlement. Formal certification is on our roadmap, not yet in audit.

Compliance officer FAQ

The questions we hear most from the people responsible for signing off on a vendor like Briefly.

Where exactly do client files live?

It depends on which surface your firm runs. On the connector, files stay in a folder on the advisor's own computer that Briefly reads from and writes back to. On the web app, files live in Briefly's hosted environment on AWS, with access scoped to your firm's account.

Does Anthropic see client files when Briefly runs inside Claude?

When an advisor asks a question, Claude reads what it needs from the client file, and Anthropic processes that content under your firm's own Claude plan. On business plans, Anthropic's commercial terms prohibit training on customer content, and deleted conversations purge within 30 days, except content flagged by Anthropic's safety systems. Briefly never stores what Claude reads.

What does Briefly's server actually receive?

It depends on the surface. From the connector, Briefly's server receives sign-in through Amazon Cognito, a seat-active check, de-identified preference rules, and a short usage record for each tool call, which carries no client file content. From the web app, your firm's files also reach our hosted environment, because that's how the product runs on that surface.

Does Briefly train AI models on client data?

No, on either surface. Client data is used to run the product for your firm, not to train general-purpose AI models, and any pattern-level learning we do runs through a de-identified, tokenized layer with no client name or account number attached.

Is Briefly a web app my staff logs into?

Both exist. The connector runs inside Claude Desktop and works with files already on the advisor's computer, without an upload step, just a one-time sign-in. The web app is a separate, browser-based product your staff can sign into instead, priced separately, with files hosted in Briefly's own environment rather than on your machine.

What happens if Briefly's servers are breached?

For connector firms, a breach exposes sign-in records, seat-check records, de-identified preference rules, and usage records, not client files, since those never reach our servers. For web-app firms, Briefly's hosted environment does hold firm data, protected by encryption and per-firm access controls, so the exposure model is different for that surface.

How does this change our Reg S-P vendor due diligence?

Firms generally review Briefly as a service provider under Reg S-P, the same as any vendor. For connector firms, client files never reach our servers, so what our side holds for that review is sign-in, seat entitlement, the preference layer, and usage records, with no client-data store. The model call runs under your firm's own Claude plan, laid out earlier on this page. For web-app firms, the review also takes in Briefly's AWS hosting and per-firm access controls, the way any hosted vendor gets reviewed.

Is Briefly SEC-approved or certified compliant?

No certification like that exists, and no agency approves an AI tool as compliant. What we can show you is exactly how Briefly's architecture, on either the connector or the web app, handles client data, which is the purpose of this page.

This page describes Briefly's architecture and general regulatory background for information only. It is not legal or compliance advice. Review any AI tool with your own counsel or compliance officer.
Need a security review? Contact contact@brieflywealth.com for architecture, vendor, and data-processing questions, including security and vulnerability reports.