Security statement
Brilliant Assessments | Updated March 2026
Brilliant Assessments has taken appropriate technical and organizational measures to protect the personal data of its Users.
Brilliant Assessments has been independently audited and has obtained Service Organization Control (SOC 2) Type II certification. Type II is the highest level of certification specified by that standard.
As part of that certification, we have regular third-party technical security reviews of the system and significant issues are addressed promptly.
All data is held in Amazon Web Services’ data center in Central Canada. Canada was chosen to leverage that country's Privacy Laws and to be compliant with EU and UK GDPR requirements. Further details are available here https://aws.amazon.com/security/. We perform additional data backups daily which are transferred to another AWS site in Ireland, fully encrypted.
Our software is developed using Microsoft software and standards. We use the latest versions and rapidly install new versions of all system software, particularly if there is a security implication.
We use Transport Layer Security (TLS) 1.2 and 1.3 encryption, HTTPS (RSA 2048 bit) for all transmitted data, and all data is held Encrypted at Rest, using Microsoft’s Transparent Data Encryption (TDE) on SQL Server Enterprise Edition. All backups are held encrypted.
You control who has access to your system and data. It is important for your users to practice sound security practices by using strong account passwords and restricting access to their accounts to authorized persons. Two Factor Authentication (2FA) is enforced on your site for all administrators and is available for Assessment Manager and Respondent roles if you choose to enforce it.
Support Personnel can only access your system if you allow it, using the Support Access Checkbox on the Settings Screen.
Access to database servers is restricted to a small number of specific individuals and specified IP Addresses.
Artificial Intelligence Services
Brilliant Assessments supports multiple AI providers, allowing customers to choose the service that best meets their business and compliance requirements.
Microsoft Azure OpenAI
When using AI Build, AI Interpret or AI Discuss with Microsoft Azure OpenAI, data is transmitted securely using TLS and HTTPS. We use Microsoft Semantic Kernel to orchestrate AI interactions. Any context we provide to the AI service—such as user-specific information or assessment data—is generated only for the current request and is not retained by Azure OpenAI after processing. Conversation history is securely stored within Brilliant Assessments' AWS-hosted environment and is only retransmitted when required to fulfil subsequent requests. Microsoft states that prompts, completions, and customer data processed through Azure OpenAI are not used to train OpenAI or Microsoft foundation models.
Anthropic Claude via Amazon Bedrock
When using Anthropic Claude through Amazon Bedrock, data is transmitted securely using TLS and HTTPS. We use Microsoft Semantic Kernel to orchestrate AI interactions and may use Retrieval-Augmented Generation (RAG) to retrieve relevant information from your assessment data in order to improve the quality and accuracy of AI responses.
Any information retrieved through RAG is used only for the duration of the current request and is not retained by the AI model. Conversation history and any retrieved knowledge remain securely stored within Brilliant Assessments' AWS environment and are only retransmitted when required for subsequent requests.
Amazon Bedrock and Anthropic do not use your prompts, retrieved context, or model responses to train Anthropic foundation models.
Questions regarding this statement should be sent to support@brilliantassessments.com.