Olbrain is in active build-out of the controls, certifications, and policies our enterprise customers expect. Every item below is currently in build-out across engineering, governance, and compliance — with named owners and target dates. We err toward honest status over polished claims, and update this page as items move forward.
All Olbrain customer data is stored, processed, and accessed within India. No egress, no offshore replication.
Customer data is logically segregated; no cross-tenant exposure in storage, prompt context, or audit surfaces.
Least-privilege access by default. Privileged operations require strong authentication and are reviewed quarterly.
Encryption everywhere. PII detection by default. Customer data is never used to train models.
Every transaction, every decision, every administrative action is logged. The audit trail is the moat.
The risks unique to AI agents — prompt injection, hallucination, training drift, cross-tenant prompt leakage — treated as first-class engineering concerns.
Defined detection, classification, response, and customer-notification process. Reachable 24×7 for critical incidents.
Targets are fixed and engagements are underway. We publish progress, not just intentions.
Named ownership, defined organizational structure, and a documented policy stack.
Standard contracts include the data, AI, third-party, and exit obligations enterprise customers expect.
Indian customer data is held by an Indian operating entity. The US parent does not access, store, or process Indian customer data.