Trust · Last updated April 2026

Building the security posture enterprises require.

Olbrain is in active build-out of the controls, certifications, and policies our enterprise customers expect. Every item below is currently in build-out across engineering, governance, and compliance — with named owners and target dates. We err toward honest status over polished claims, and update this page as items move forward.

security@olbrain.com Request security questionnaire Request DFD & controls evidence
Status • In Progress All items below are in active build-out. Status will be updated as controls move to attestable in production.
01

Data Residency

All Olbrain customer data is stored, processed, and accessed within India. No egress, no offshore replication.

02

Architecture & Tenant Isolation

Customer data is logically segregated; no cross-tenant exposure in storage, prompt context, or audit surfaces.

03

Access Control

Least-privilege access by default. Privileged operations require strong authentication and are reviewed quarterly.

04

Data Protection

Encryption everywhere. PII detection by default. Customer data is never used to train models.

05

Audit & Logging

Every transaction, every decision, every administrative action is logged. The audit trail is the moat.

06

AI-Specific Controls

The risks unique to AI agents — prompt injection, hallucination, training drift, cross-tenant prompt leakage — treated as first-class engineering concerns.

07

Incident Response

Defined detection, classification, response, and customer-notification process. Reachable 24×7 for critical incidents.

08

Compliance & Certifications

Targets are fixed and engagements are underway. We publish progress, not just intentions.

09

Information Security Governance

Named ownership, defined organizational structure, and a documented policy stack.

10

Customer Commitments in MSA

Standard contracts include the data, AI, third-party, and exit obligations enterprise customers expect.

11

Legal Entity & Data Controller

Indian customer data is held by an Indian operating entity. The US parent does not access, store, or process Indian customer data.