M.L. Sebastian is now br8n.

Trust and Security

Your data boundaries, in writing.

Single-tenant by default. Named access. No training on client data. A direct account of the controls in place and the readiness work still underway.

The posture

Separate the data. Name the access. Record the handling.

Each engagement starts with written boundaries: which sources may enter, which systems may be reached, which vendors process the data, and who on the named team has access.

Data is encrypted in transit and at rest through our infrastructure providers. Their certifications are theirs. br8n owns the configuration, access model, and audit trail on top.

Transparent on governance. Closed on the internal delivery engine.

Before data moves

Boundaries become operating controls.

  1. Scope

    Name the sources

    Agree what enters the corpus, what stays out, and which sub-processors touch the work.

  2. Access

    Grant the minimum

    Use named accounts, multi-factor authentication, and least privilege for the engagement team.

  3. Transfer

    End access cleanly

    Document the installation, transfer ownership, and close br8n access when the engagement ends.

Isolation model

Single-tenant changes the blast radius.

CompareMulti-tenant SaaSSingle-tenant install
Data locationShared application infrastructureYour own installation
Isolation depends onThe vendor’s software controlsSeparate client infrastructure
Defect blast radiusPotentially multiple tenantsOne installation
At exitData export, if offeredThe installation transfers

SOC 2 readiness

The current position, without borrowed badges.

br8n does not hold a SOC 2 attestation today. A readiness program is underway, with controls designed to align with the SOC 2 Trust Services Criteria and the control set mapped and documented.

The path runs Type I first, then Type II after an observation window. Security teams can review the current mapping and sub-processor list under NDA during diligence.

  • DPAs signed on request before client data moves.
  • Client inputs excluded from model training under organizational terms.
  • Security questionnaires handled as normal diligence.

Ask the hard questions

Get the answers in writing.

Bring the questionnaire, the data classes involved, and the controls your team needs to evaluate before work begins.

FAQs

Is br8n SOC 2 certified?

Not yet, and we will not imply otherwise. A SOC 2 readiness program is underway: our controls are designed to align with the SOC 2 Trust Services Criteria, the control set is mapped and documented, and the path runs Type I first, then Type II after an observation window. Buyers who need the current control mapping can review it under NDA before an engagement.

Will br8n sign a DPA?

Yes, on request, before client data moves. The data processing agreement names the sub-processors that will touch your data, the purposes they serve, and the handling obligations we carry. If your legal team prefers your paper, we review it rather than insisting on ours.

Does our data train AI models?

No. Client work runs under organizational accounts with the model vendors, under terms that exclude training on your inputs, with zero-data-retention options selected where the provider offers them. The brains built from your material are owned by you outright.

Is our Install single-tenant?

Yes, by default. Your corpus, memory, and integrations are built as their own installation on infrastructure provisioned for your engagement. No other client’s data shares the store. Single-tenant costs more to stand up than a shared platform, and we consider that the correct trade for client working knowledge.

Where is our data stored and how is it encrypted?

On infrastructure operated by established providers, encrypted in transit with TLS and at rest through those providers’ storage encryption. Their security certifications remain theirs. br8n owns the configuration on top: data boundaries, access control, and the audit trail documented for the engagement.

Who at br8n can access our data?

The named engagement team, under least-privilege access. Access is granted per engagement, runs through accounts with multi-factor authentication, and ends when the engagement does. The access list is part of the governance documents you receive.

Can our security team review your controls before we commit?

Yes. We share the control mapping, sub-processor list, and governance documentation under NDA, and we answer security questionnaires during diligence. You get visibility into how your data is handled while br8n’s internal delivery tooling remains br8n’s.

Can't find what you're looking for? Talk with us