COMPANY BRAIN
SECURITY & DEPLOYMENT / FACTS, NOT BADGES

Keep the control
close to the source.

Company Brain is designed for a customer-controlled production environment, with a bounded deployment scope and explicit responsibility lines. Security and procurement requirements are assessed before production go-live.

01

Customer-controlled environment

One isolated production environment is deployed into infrastructure you provide and control. In the standard configuration, document content and inference stay inside that environment; a premium hosted model is optional and off unless you enable it.

02

Credentials encrypted, keys durable

Source credentials are encrypted before they reach the database, with cryptographic separation per source. Production start fails closed rather than use a key ring that could leave credentials unrecoverable.

03

Tamper-evident operating record

Governance-critical changes are written to an append-only, hash-chained record. The chain can be verified on demand and reports the sequence where a break is detected.

04

Human release decision, enforced in code

No knowledge reaches a published state without cited, hash-verified evidence and a named reviewer’s decision. The deterministic grounding checks sit on one release path.

RESPONSIBILITY BOUNDARY

What Company Brain manages—and what the customer still controls.

Company Brain

Software deployment and configuration, governed knowledge workflow, product updates, standard support and the evidence/usage record described in the signed scope.

Customer

Cloud or host infrastructure, source-data access, network and security approvals, source-data quality, named reviewers and consequential business decisions.

INTERNAL ENGINEERING EVIDENCE / 2 AUG 2026

Show the work.
Name the limits.

These are self-run engineering checks, not independent certification or assurance.

AUTOMATED TEST SUITE1,965 passed

In a 1,973-test run. Five Docker-dependent fixture tests failed because the container runtime was unhealthy; three were skipped. No non-Docker test failed.

INTERNAL ADVERSARIAL AUDIT78 findings

Across grounding, access control, tenancy, approvals, connectors and the API surface. All 23 remediation tasks were merged to main.

ENGINE STRESS PASS / 18 JUL 20265 scenarios passed

Including concurrent drift alerts, a governed proposal lifecycle and an adversarial prompt-injection round. This is functional evidence, not a customer-scale load benchmark.

WHAT IS NOT CLAIMEDNo certifications. No independent penetration test.

No external security audit, customer-scale load test or disaster-recovery restore test has been completed. Those requirements are scoped transparently with each customer.

PROCUREMENT NOTE

Do not infer certifications or guarantees that are not listed in a signed agreement.

Company Brain can provide deployment scope, data-flow discussion, support targets and implementation boundaries for your assessment. Audit records are tamper-evident rather than immutable; prompt-injection screening is defence in depth rather than a complete trust boundary; and premium hosted-model use sends prompts to that provider. Contracted service levels, premium support, additional regions and bespoke security commitments are separately scoped.

Review the pilot evidence plan
RESPONSIBLE DISCLOSURE

Found a security issue?
Tell us directly.

Email security@companybrain.work with enough detail to reproduce the issue. We will acknowledge the report, work the issue and let you know when it is resolved.

Please give us a reasonable opportunity to fix an issue before public disclosure. Do not access, modify or delete data that is not yours; do not degrade service for others; and do not run automated scans against a customer environment.

Company Brain does not currently run a paid bug-bounty programme. Reporters who ask to be credited will be credited.