Home / Security
Straight answers about your data.
Review the proposed data flow, providers, access, and retention terms before sharing operational documents. Controls depend on the agreed implementation; no system is completely secure.
Security and data-handling principles
What must be written down before anything is shared.
Your documents
Ownership and permitted use
Submitting documents does not itself transfer your ownership. The client agreement must define permitted processing, authorized service providers, model-training restrictions, export formats, retention, and deletion. Do not assume that hosted processing means no third party has access.
Where it runs
Hosted first. On-site if you need it.
The default is Hosted Cloud: we host, your employees sign in, and your documents stay yours. If work must stay on the property, that is a customer-owned path. We do not sell or lease equipment.
Who decides
Define authorization boundaries
BrainBuild is intended for information retrieval and human review. Any action-capable integration requires a separately agreed scope, permissions, and approval workflow. Do not assume a safeguard is present unless it has been configured and verified.
The record
Agree on logging and retention
Available logs, recorded events, access, retention, and export options depend on the system configuration and service agreement. This website does not promise complete records, indefinite retention, or recovery of lost data.
Have a checklist? Send it.
Send proposed requirements by email for review with your operations, IT, and security teams. Discuss controls, authorized providers, incident handling, backups, and known limitations.
No certification or compliance status should be assumed from this website.
BrainBuild
Start with the operation.
Discuss your operational, IT, and security requirements as part of the proposed assessment scope.
Scope agreed in writing · Results vary