Trust

Trust Center

Everything below is a real property of how Braize is built, with an honest status. Where we are not yet certified, we say so — we would rather earn your trust than borrow a badge.

Posture

What we enforce, and where we stand

Enforced and structural items are how the system behaves today. 'Available on request' means we will send it; 'Not yet certified' means exactly that.

ACL pre-filter inside the query

Enforced

Access control is a pre-filter inside every retrieval SQL leg — dense, lexical, and fallback — never a post-filter. A dedicated leak suite gates CI.

One Postgres per workspace

Structural

Each workspace is its own Postgres database with its own login role and REVOKE CONNECT FROM PUBLIC. Cross-workspace access is structurally impossible.

Region pinning

Structural

A workspace is pinned to one region at creation. No service can construct a cross-region connection; inference is routed in-region.

Embeddings are personal data

Enforced

Vectors can encode the underlying text, so they never leave the workspace database — not in logs, analytics, or backups — and are nulled on purge.

SSRF egress guard

Enforced

Every outbound fetch passes an egress guard that blocks loopback, private ranges, and cloud-metadata, and re-validates each redirect hop.

Prompt-injection quarantine

Enforced

Ingested content is normalized and scanned for hidden instructions; any match quarantines the whole document — it is never indexed.

Purge within 24 hours

Enforced

Deleting a document removes it from retrieval immediately and enqueues a purge of content, vectors, blobs, and cached answers, targeted within 24 hours.

ZDR-aware inference routing

Enforced

A per-workspace processing_policy can require zero-data-retention endpoints or lock inference in-region, enforced in the gateway with no silent fallback.

EU AI Act Article 50 disclosure

Enforced

Every end-user channel always discloses AI-generated responses at the channel boundary — it is not themeable away.

GDPR & UAE PDPL alignment

Available on request

Region residency, purge, and embeddings-as-personal-data are built to align with EU GDPR and UAE PDPL. A DPA and subprocessor list are available on request.

SOC 2

Not yet certified

No SOC 2 audit has been completed yet. We are happy to walk through our controls and architecture in the meantime.

Built for sovereign teams

UAE PDPLEU GDPREU AI Act Art 50ZDR-aware routingRegion-pinned data

Hosted in Europe. Each workspace is pinned to one region; embeddings never leave it.

Request our DPA or subprocessor list

Email sales and we will send the Data Processing Agreement, our current subprocessor list, and walk your security team through the architecture. Ask us anything we have not certified yet — we will tell you the truth.