As of: 5 October 2026
This page explains how we protect the data you put in BrickFlow. It is written for the IT and procurement teams of our customers. It is also our posted cyber-security policy for energy data we receive through Ontario’s Green Button Connect My Data program, and it should be read with the Privacy Rules for Energy Data in our Privacy Policy.
BrickFlow is a trade name of GreenKey Information Management Corporation, London, Ontario. Security questions: [email protected].
Where your data lives
| Data | Where | Provider |
|---|---|---|
| App, database and uploaded bills | Toronto, Canada | Google Cloud (Compute Engine, Cloud Storage) |
| Backups | Montreal, Canada | Google Cloud Storage |
| Website | Global edge network | Cloudflare (Pages, content delivery, bot protection) |
| AI bill reading | United States | Anthropic API, only for bill images and PDFs you upload |
Green Button energy data stays in Canada (Toronto and Montreal) and is never sent to the AI provider. Bills sent to Anthropic are not used to train its models and are deleted by Anthropic within 30 days. The full list of service providers, with what each one does, is in section 6 of our Privacy Policy.
Encryption
- In transit: every connection uses TLS, and the website and app enforce HTTPS. Connections to utility Green Button endpoints use TLS 1.2 or higher, and TLS 1.3 where the utility supports it.
- At rest: data on our servers’ disks and in our backups is encrypted at rest by Google Cloud.
- Sign-in: you sign in with your Google account. We do not use passwords, so we never receive or store one.
- Secrets: utility access tokens are stored encrypted in our database. API keys are kept in server configuration outside our source code, and every change to our code is scanned for secrets.
Utility connections (Green Button)
- We connect to utilities with OAuth 2.0. Access and refresh tokens are stored encrypted. If you disconnect a utility in BrickFlow, we delete its token at once. If you revoke at your utility, the token stops working at once and is deleted with your data.
- We request only the access needed for the purpose you authorized: the data categories, accounts and period you choose at your utility.
- Where a utility requires a client certificate, we use one from a public certificate authority with an RSA key of at least 2048 bits.
- If we find that a utility has sent us data you did not authorize, we delete it and tell the utility.
Access control
- Access to production systems and customer data is limited to named staff, currently the founder, who are bound by confidentiality. There are no shared accounts. Access is removed the day a person’s role changes.
- Inside BrickFlow, your workspace administrator decides who in your organization can see what.
Availability and abuse controls
- The website sits behind Cloudflare’s denial-of-service protection and bot filtering.
- The app limits sign-in attempts from each network address, and limits uploads, AI bill reading and other costly operations per user and organization.
- Backups run nightly to a separate region (Montreal), are encrypted at rest, and database backups expire after 30 days. We test a full restore every month.
Logging and monitoring
- We keep web access logs, application logs and a record of every sign-in.
- Logs are kept on our servers in Canada. Web and application logs rotate out automatically as they reach a fixed size, usually within weeks. Sign-in records are kept with your account.
- We are alerted when a nightly backup fails, and we review logs when investigating any incident.
Vulnerability management
- Software dependencies are monitored with GitHub Dependabot and updated monthly, and sooner for serious vulnerabilities.
- We apply operating-system security updates to our servers regularly.
- Every change goes through automated checks before it is deployed, including secret scanning and static code analysis.
Incident response
We have a written breach-response procedure. In an incident we:
- Contain it: revoke sessions, rotate credentials, isolate the affected system, and preserve logs.
- Notify affected utilities immediately on discovery if Green Button energy data is or may be involved, with a summary of the incident, the facts known, the status of our investigation and the customers affected, and update them as we learn more.
- Tell affected customers immediately, before our analysis is complete.
- Notify under privacy law: the Office of the Privacy Commissioner of Canada and affected individuals where there is a real risk of significant harm (PIPEDA), and Quebec’s Commission d’accès à l’information where there is a risk of serious injury.
- Record every breach, fix the root cause, and review within 30 days.
Service providers
Every service provider that handles your data is bound by contract to protect it, to use it only to provide its service to us, and to tell us about incidents. We list them in our Privacy Policy and update that list when a provider is added or changed. We do not add a provider for Green Button energy data without updating the Privacy Rules, which requires your prior consent.
Reporting a vulnerability
If you find a security problem, email [email protected]. Our contact details are also published at brickflow.ca/.well-known/security.txt. We acknowledge reports within two business days and keep you informed until the issue is fixed. Please do not access other people’s data or disrupt the service while testing; we will not take legal action against good-faith research that follows these rules.
Certifications and reviews
We do not currently hold SOC 2 or ISO 27001 certification, and we do not claim any certification. We are a small company; we review our controls regularly against industry practice (including OWASP and Google Cloud security guidance), at least once a year and after any incident, and we are happy to complete your security questionnaire.
Energy data: no changes without your consent
We will not amend this cyber-security policy, or our Privacy Rules for Energy Data, as they apply to your Green Button energy data, without your prior consent. If we propose a change, we will send it to you and ask you to agree before it applies to your data.
Changes
We update this page when our controls change. Each version carries an “as of” date. Changes that affect Green Button energy data follow the consent rule above.
Contact: [email protected] | [email protected] | GreenKey Information Management Corporation, 64 Elmwood Place, London, ON N6J 1J2, Canada