Skip to content

Compliance Ready

Designed to meet major enterprise compliance frameworks. SOC 2 Type II audit on roadmap. No training on your data, ever. Data Processing Agreements available on request.

Compliance Posture

  • SOC 2 Type II (on roadmap)
  • GDPR and PDPA data residency controls
  • ISO 27001 alignment
  • Designed for HIPAA and FedRAMP workloads under air-gapped deployment

No Training on Customer Data

AgentBrain never uses customer data for model training. This is a hard product guarantee:

  • Customer knowledge content is never sent to LLM provider training pipelines
  • Telemetry collected from your tenant is scoped to operational metrics, never content
  • LLM provider opt-outs (OpenAI, Anthropic, Google) are configured at the gateway layer

Data Processing Agreements

DPAs are available on request. Standard DPA covers:

  • Roles (controller vs processor)
  • Sub-processor list and notification obligations
  • Data subject request handling
  • Breach notification SLA
  • International transfer mechanisms (SCCs, UK IDTA)

Framework Mapping

FrameworkStatusDeployment Required
SOC 2 Type IIOn roadmapAny
GDPRSupported via residency controlsCloud, On-prem, Hybrid
PDPA (Vietnam, Singapore)SupportedCloud, On-prem
ISO 27001AlignedOn-prem
HIPAADesign-fitAir-gapped
FedRAMPDesign-fitAir-gapped

Audit Artifacts

For procurement and audit teams, the following artifacts are available:

  • Architecture diagrams and data flow maps
  • Standard DPA template
  • Sub-processor list
  • Security whitepaper
  • Penetration test summary (under NDA, on Enterprise tier)

Contact the security team via the contact form to request artifacts.