Trust and Security
Your data boundaries, in writing.
Single-tenant by default. Named access. No training on client data. A direct account of the controls in place and the readiness work still underway.

The posture
Separate the data. Name the access. Record the handling.
Each engagement starts with written boundaries: which sources may enter, which systems may be reached, which vendors process the data, and who on the named team has access.
Data is encrypted in transit and at rest through our infrastructure providers. Their certifications are theirs. br8n owns the configuration, access model, and audit trail on top.
Transparent on governance. Closed on the internal delivery engine.
Before data moves
Boundaries become operating controls.
Scope
Name the sources
Agree what enters the corpus, what stays out, and which sub-processors touch the work.
Access
Grant the minimum
Use named accounts, multi-factor authentication, and least privilege for the engagement team.
Transfer
End access cleanly
Document the installation, transfer ownership, and close br8n access when the engagement ends.
Isolation model
Single-tenant changes the blast radius.
| Compare | Multi-tenant SaaS | Single-tenant install |
|---|---|---|
| Data location | Shared application infrastructure | Your own installation |
| Isolation depends on | The vendor’s software controls | Separate client infrastructure |
| Defect blast radius | Potentially multiple tenants | One installation |
| At exit | Data export, if offered | The installation transfers |
SOC 2 readiness
The current position, without borrowed badges.
br8n does not hold a SOC 2 attestation today. A readiness program is underway, with controls designed to align with the SOC 2 Trust Services Criteria and the control set mapped and documented.
The path runs Type I first, then Type II after an observation window. Security teams can review the current mapping and sub-processor list under NDA during diligence.
- DPAs signed on request before client data moves.
- Client inputs excluded from model training under organizational terms.
- Security questionnaires handled as normal diligence.
Ask the hard questions
Get the answers in writing.
Bring the questionnaire, the data classes involved, and the controls your team needs to evaluate before work begins.
FAQs
Is br8n SOC 2 certified?
Not yet, and we will not imply otherwise. A SOC 2 readiness program is underway: our controls are designed to align with the SOC 2 Trust Services Criteria, the control set is mapped and documented, and the path runs Type I first, then Type II after an observation window. Buyers who need the current control mapping can review it under NDA before an engagement.
Will br8n sign a DPA?
Yes, on request, before client data moves. The data processing agreement names the sub-processors that will touch your data, the purposes they serve, and the handling obligations we carry. If your legal team prefers your paper, we review it rather than insisting on ours.
Does our data train AI models?
No. Client work runs under organizational accounts with the model vendors, under terms that exclude training on your inputs, with zero-data-retention options selected where the provider offers them. The brains built from your material are owned by you outright.
Is our Install single-tenant?
Yes, by default. Your corpus, memory, and integrations are built as their own installation on infrastructure provisioned for your engagement. No other client’s data shares the store. Single-tenant costs more to stand up than a shared platform, and we consider that the correct trade for client working knowledge.
Where is our data stored and how is it encrypted?
On infrastructure operated by established providers, encrypted in transit with TLS and at rest through those providers’ storage encryption. Their security certifications remain theirs. br8n owns the configuration on top: data boundaries, access control, and the audit trail documented for the engagement.
Who at br8n can access our data?
The named engagement team, under least-privilege access. Access is granted per engagement, runs through accounts with multi-factor authentication, and ends when the engagement does. The access list is part of the governance documents you receive.
Can our security team review your controls before we commit?
Yes. We share the control mapping, sub-processor list, and governance documentation under NDA, and we answer security questionnaires during diligence. You get visibility into how your data is handled while br8n’s internal delivery tooling remains br8n’s.
Can't find what you're looking for? Talk with us