Security at Bruno starts with a simple idea: sensitive API data shouldn’t need to pass through our infrastructure.
Bruno is local by default. Your API collections live as files on your machine. They can be version controlled with Git and stored in infrastructure you already control. We don't require you to move your API development workflow into a proprietary cloud just to collaborate with your team.
That architecture is intentional. We believe developer tools should minimize the amount of sensitive customer data they need to collect, store, and process.
As important as we believe that is, architecture alone isn't enough.
Today, we're happy to share that Bruno has successfully completed its SOC 2 Type II examination.
SOC 2 is an independent examination based on criteria established by the American Institute of Certified Public Accountants (AICPA). A Type II examination goes beyond looking at whether controls exist at a point in time. It evaluates whether those controls operated effectively over an extended period.
For us, pursuing SOC 2 was important for two reasons.
First, Bruno is increasingly used by some of the largest organizations in the world. Those customers need more than our word that we take security seriously. They need independent evidence that the company behind the software operates with the same care we put into its architecture.
Second, we wanted the rigor internally. Going through SOC 2 forced us to formalize, document, test, and consistently follow processes across the organization. That's valuable regardless of whether a customer ever asks to see the report.
Local-first reduces what you have to trust us with. SOC 2 helps validate how we operate when you do.
SOC 2 isn't the end of our security work, and it isn't a substitute for building software around privacy and security from the beginning.
It's another layer in the way we're building Bruno: local by default, transparent where possible, and ready for the organizations that depend on it.
Customers who would like access to Bruno's SOC 2 Type II report can request it through our Trust Center.