Brainam customers trust us with their prompts, knowledge files, conversations, and agent configurations — the same things they would protect inside their own walls. We take that seriously.
This page is a transparent summary of the technical, organisational and operational controls used by Taku Ventures Private Limited (CIN: U79110DL2024PTC431506, GSTIN: 07AALCT0078R1ZL) — the company that operates Brainam — to protect your data. It is updated as our infrastructure and practices evolve. For deeper detail, enterprise buyers can request our security questionnaire response (SIG Lite / CAIQ) by writing to security@brainam.ai.
TLS 1.2+ in transit and AES-256 at rest. OAuth tokens are stored in an encrypted secrets vault.
Customer data is logically isolated. Your training content never powers another customer’s agents.
We never use your prompts, files, or conversations to train foundation models — ours or any third party’s.
Production access is restricted, MFA-enforced, and logged. Routine work uses scoped, time-limited credentials.
Brainam aligns its security programme to the standards expected of modern SaaS infrastructure, including the Digital Personal Data Protection Act, 2023 (DPDP), the EU/UK GDPR, and the CCPA/CPRA. We design and operate Brainam to be auditable to SOC 2 Trust Services Criteria from day one, even while we work towards formal certification.
Honest roadmap: Brainam does not currently hold a SOC 2, ISO 27001 or HIPAA certification. We are at the early-stage discipline phase — designing controls now so that audit readiness is straightforward when we pursue Type I and Type II reports. Enterprise customers can request our current security questionnaire (SIG Lite / CAIQ format) at security@brainam.ai.
Where our sub-processors hold certifications (such as MongoDB Atlas, Render and Cloudflare), we rely on their audited controls and review their compliance reports annually.
All traffic to Brainam — including the web application, API endpoints, webhook callbacks, and OAuth flows — is encrypted using TLS 1.2 or higher. We use Cloudflare to manage certificate issuance, renewal, and modern cipher suite enforcement. HTTP requests are automatically redirected to HTTPS, and HSTS is enabled.
Customer data stored in MongoDB Atlas is encrypted at rest using AES-256. Encryption keys are managed by the cloud provider and rotated according to provider policy. Database backups are encrypted using the same standard.
OAuth tokens, third-party API keys, BYOK provider keys, and integration credentials are stored in an encrypted secrets vault separate from the primary database. Plain-text secrets are never written to logs, error reports, or analytics events.
Brainam is hosted on enterprise-grade cloud infrastructure with established compliance pedigrees:
| Layer | Provider | Region | Compliance |
|---|---|---|---|
| Application hosting | Render | Singapore | SOC 2 Type II |
| Primary database | MongoDB Atlas | Singapore / India | SOC 2 Type II, ISO 27001, HIPAA-ready |
| Edge, CDN & DDoS | Cloudflare | Global edge | SOC 2 Type II, ISO 27001, PCI DSS |
| Transactional email | Resend / SES | USA | SOC 2 Type II |
| Payments | Razorpay | India | PCI DSS Level 1, RBI-licensed |
Inside a Brainam workspace, administrators can assign granular roles to team members. Sensitive operations (billing, BYOK key management, account deletion) require admin-level permissions and are logged separately.
We perform internal security review on every significant feature. Independent third-party penetration tests are part of our SOC 2 roadmap and will be conducted at least annually once initiated.
Application and infrastructure logs are centralised and retained for at least 12 months. Anomalies (failed login attempts, unusual API usage, suspicious admin actions) trigger alerts to the on-call engineer.
Each Brainam Customer’s data is logically isolated. Queries, agents, training content, and conversations are scoped to a workspace identifier and cannot be read across workspaces.
Brainam does not use your prompts, training files, conversations, or Outputs to train, fine-tune, or improve any general-purpose foundation model — whether our own or any third party’s (Anthropic, OpenAI, Google or others).
When your agent runs, prompts and necessary context are sent to one or more AI providers (Anthropic, OpenAI, Google) for inference. We rely on those providers’ API terms, which state that data sent via the API is not used to train their models. Specifically:
Primary Customer Data is stored in MongoDB Atlas clusters located in Singapore or India. AI inference may be processed in the United States or European Union depending on the provider routing. International transfers are governed by Standard Contractual Clauses and the EU–US Data Privacy Framework where applicable.
You can delete training content, conversations, agents, or your entire Account at any time from the product. Deleted data is removed from active databases immediately and from backups within 90 days. See our Privacy Policy for the full retention schedule.
The full list of sub-processors we engage to deliver the Services — including their purpose, the categories of data they receive, and their location — is published and maintained on our Privacy Policy under Section 11. Enterprise customers can subscribe to advance notification of sub-processor changes by writing to security@brainam.ai.
Our internal targets, which we tighten as we grow:
These are operational targets, not contractual SLAs. Bespoke SLAs are available for enterprise plans on request.
We maintain a documented business continuity and disaster-recovery plan covering provider outages, key personnel unavailability, and catastrophic data-centre events. The plan is reviewed at least annually.
Brainam maintains a written incident-response plan that defines roles, severity classifications, communication channels, and post-incident review.
If we become aware of a personal-data breach that is likely to affect you, we will notify you and the relevant supervisory authority within the timelines required by law — within 72 hours under the DPDP Act and the GDPR. Notification will include the nature of the breach, the categories of data affected, the likely consequences, and the steps we are taking in response.
For service-impacting incidents, we communicate via in-product banner, email to administrators, and (where applicable) our status page. Post-incident reports are shared with affected customers on request.
We welcome reports from security researchers. If you believe you have found a vulnerability in Brainam, please email security@brainam.ai with:
Good-faith security research conducted under the following guidelines will not result in legal action from Brainam:
We will acknowledge valid reports within 5 business days and keep you informed of remediation progress.
When a team member leaves Brainam, all system access — including source code, cloud consoles, the secrets vault, and SaaS tools — is revoked within one business day. Company-issued devices are reclaimed and wiped.