Security

Authority enforced at six gates.

AI that acts needs more than encryption talk. Here is where power is checked in Brainis — mechanically, at every layer, with an audit trail that can’t be quietly edited.

Six gates, every time.

One enforcement path, six checks — power is re-checked at every layer it passes through.

  1. Gate 1 · Compile

    Out-of-authority steps can't even enter a mission plan; they compile into decision gates instead.

  2. Gate 2 · Dispatch

    Work is assigned only to actors holding an eligible authority contract; no contract, no claim.

  3. Gate 3 · MCP token

    Each run's token binds org, actor, mission, scopes, and expiry; agents receive context packets, never database access.

  4. Gate 4 · Tool call

    Every call re-checks current policy and authority server-side; the token is a hint, the server is the law.

  5. Gate 5 · Verification

    Required checks cannot be skipped by any actor, including humans; overrides are recorded decisions.

  6. Gate 6 · Release

    Verified work still waits for release authority; Verify gates, contracts and humans release.

Everything else, evidence-backed

Tenant isolation

Org-scoped everything, enforced at the database. Attacked by our own probes before releases — a practice statement, no certification implied.

Identity & roles

Google/Microsoft OAuth sign-in on every tier; enterprise SAML/SCIM (post-launch). Role-based access, sensitivity levels on state.

Execution isolation

Per task class: data (scoped tokens), code (isolated worktrees), browser (domain allowlists), communication (draft-first), finance (deterministic limits + human gates).

Providers

Scoped context, no durable credentials, no training on your data without explicit consent.

Audit

Hash-chained action log; every consequential object answers the Trust Inspector's questions.

Data lifecycle

Export anytime; deletion on schedule; the DPA governs the specifics.

Uptime

Uptime is published on status.brainis.ai. It appears here once the status feed is wired — we would rather show nothing than a number we did not measure.

Security contact: support@brainis.ai · advisory archive on /trust.