Join us at the Go Beyond Summit 2026, June 16-18 | Chicago, IL USA Register Now!

Core Commitments & Trust Vision

At Braincube, we empower world-leading manufacturers in their digital transformation journey through Real Time Process Optimization. Trust, data security, and operational reliability are the foundations of our solutions.

We are committed to delivering rigorous data protection standards at every stage of industrial data processing, while providing the agility required by modern manufacturing environments. Our security strategy is built on data sovereignty, complete operational transparency, and compliance with the most demanding global standards.

Certifications & Regulatory Compliance

Braincube maintains a proactive compliance posture designed to meet the stringent requirements of critical industrial sectors (automotive & tyres, aerospace, chemicals, food & beverage, energy, pulp & paper, building materials, pharma…). Our compliance framework aligns with, but is not limited to, the following certifications, standards, and regulatory requirements:

Certifications & StandardsScope & DescriptionCompliance Status
ISO/IEC 27001Information Security Management System (ISMS) covering all software development, hosting, and SaaS support operations.Certified
ISO 9001Quality Management System ensuring customer satisfaction and continuous process optimization.Certified
SOC 2 Type IIIndependent audit evaluating Security, Availability, and Confidentiality trust service criteria.Annual Report available under NDA
Data Privacy Standards (GDPR, LGPD, CCPA/CPRA, DPDP Act…)Compliance with major global data protection frameworks including EU GDPR, Brazilian LGPD, US CCPA/CPRA, and India DPDP Act across all processed personal data.Fully Compliant
EU AI ActClassification of Braincube industrial AI features as minimal/low risk (industrial optimization tools without direct personal impact).Compliant / Aligned

Data Protection & Security Architecture

Braincube’s Global Security Policy (GSP) enforces strict standards regarding data isolation, transmission, and storage.

  • Isolated Multi-Tenant Architecture: Strict logical segregation of tenant data at application level, preventing unauthorized cross-tenant data access.
  • Data Encryption at Rest: Object storage and backups are encrypted using standard AES-256.
  • Data Encryption in Transit: Data flows are secured using robust encryption protocols, including TLS 1.3 / HTTPS for public interfaces and SSH RSA 2048 for secure data integration pipelines.
  • Credential Hashing: Robust password hashing implemented via SHA512 with unique per-user salting.
  • Data Sovereignty & Location: We use multiple cloud providers across multiple regions to guarantee geolocation of customer data.
  • Certificate of Data Destruction: Upon contract termination, a certified secure erasure protocol is executed, accompanied by a formal Certificate of Destruction issued to the customer on request.

Responsible AI & Braincube Companion

The integration of Generative AI within the platform via Braincube Companion adheres to strict enterprise governance and data privacy rules.

  • BYOK (Bring Your Own Key) Support: Native integration with OpenAI, Anthropic and Google allowing customers to use their own API keys and subscriptions for full cost and data boundary governance. Alternative LLM upon request.
  • Strict Prohibition of Model Training on Customer Data: No customer production data, telemetry, or user prompts submitted to Braincube Companion are ever used to train or fine-tune public or third-party AI models.
  • Access Control Propagation: AI interfaces strictly inherit access control boundaries configured within the platform. Users can only query data and analytics they are explicitly authorized to view.

Delegated & Proactive Security Controls

Platform security relies on a shared responsibility framework where Braincube provides advanced management features alongside proactive infrastructure controls.

Complementary User Entity Controls (CUECs)

  • Single Sign-On (SSO): Native support for SAML 2.0 and OpenID Connect protocols to integrate with enterprise Identity Providers (Azure AD, Okta, Ping Identity).
  • Two-Factor Authentication (2FA/MFA): Configurable multi-factor authentication policies enforceable across all user accounts.
  • Advanced: Air-gapped setups are available to allow advanced complementary controls for users and entities.

 

Resilience & Independent Audits

  • Disaster Recovery Plan (DRP / PRA): Automated replication and backup procedures ensuring low RPO and RTO metrics for high business continuity.
  • Third-Party Security Audits: Annual penetration tests conducted by accredited independent cybersecurity firms.
  • High-Availability Cloud Infrastructure: Leading multi-cloud infrastructure providers including Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP).

Resource Center & Downloads

Our security documentation and corporate governance policies are organized by access level: public availability versus NDA-gated documents.

Public Access Documents

  • BOSS Manual (Braincube Operating Smart System Overview): Comprehensive overview of Braincube’s operational and functional architecture.
  • QIS Policy (012 MQS PY WW – Quality & Information Security Policy): Executive commitments to quality management and information security.
  • ESG & HSE Policy (011 MQS PY WW – ESG & HSE Policy): Strategic framework for Environmental, Social, Health, and Safety management.
  • HR, Ethics & Human Rights Policies (00B HRM PY WW): Governance rules covering ethics, DEI, whistleblower protection, and human rights.
  • GSP Executive Summary: Overview of core technical security measures and architecture.

Restricted Documents (NDA Required)

  • Full Global Security Policy (GSP): Deep-dive documentation of technical controls and security engineering.
  • SOC 2 Type II Audit Report: Full third-party auditor report.
  • Penetration Testing Reports: Executive summaries of third-party security audits.
Document TitleReferenceAccess LevelDownload Link
BOSS Operating Manual OverviewBOSS ManualPublicDownload PDF
GSP Executive SummaryGSP-EXEC-SUMMARYPublicDownload PDF
Quality & Information Security Policy012 MQS PY WWPublicDownload PDF
ESG & HSE Policy011 MQS PY WWPublicDownload PDF
HR, Ethics, DEI & Human Rights Policy00B HRM PY WWPublicDownload PDF
Full Global Security Policy (GSP)GSP - Global Security PolicyNDA RequiredUpon request
SOC 2 Type II ReportSOC2-REPORT-2025NDA RequiredUpon request
Penetration Testing ReportsPENTEST-REPORT-2026NDA RequiredUpon request

Contact & Access Request

For any questions regarding data security, to report an incident, or to request access to confidential documents (SOC 2 Reports, Pentests, Full GSP), you can reach out directly to the following contacts:

  • Security Team Email : security@braincube.com
  • CISO Contact (Chief Information Security Officer) : ciso@braincube.com
  • DPO Contact (Data Protection Officer) : dpo@braincube.com

NDA Document Request Form