Security
For the data you cannot afford to leak.
Company Brain reads your most sensitive systems. That only works if the controls around it are boring, provable, and open to your inspection.
Permissions are inherited, not applied
Access rights are captured at ingestion and travel with the content. If a user cannot open a file in the source system, Company Brain will not surface it to them.
Your data does not train models
Inputs, outputs and uploaded documents are never used for training. We require zero-retention terms from every model provider we route to.
Every action is recorded
Each agent run is logged end to end — sources read, decisions taken, systems written to, approvals given. Exportable, and reversible where it matters.
You choose where it runs
Our environment or yours. Regional processing for residency requirements, and full deployment into your own cloud where that is the only acceptable answer.
Standards
Where we actually stand
We publish status plainly rather than implying certifications we do not hold. Each entry says exactly where it is, and this page is updated as audits complete.
SOC 2 Type II
In progress
Controls built against the Trust Services Criteria. Audit underway; documentation and questionnaire responses available under NDA.
GDPR
Compliant
Data processing agreements, disclosed sub-processors, full data subject rights, and EU-region processing where required. A regulation, not a certification.
EU AI Act
Readiness
A regulation rather than a certification. We build for its obligations: documentation, traceability, human oversight and disclosure.
ISO/IEC 27001
Aligned
Security management practices mapped to Annex A controls. Certification is on the roadmap and will be published here when issued.
ISO/IEC 42001
Aligned
AI management system practices covering impact assessment, model lifecycle governance and monitoring of deployed systems.
Data residency
Available
Regional processing, configurable retention and deletion, and deployment into infrastructure you own and operate.
Bring your security team to the first call.
We would rather answer the hard questions up front than find a blocker three months into a deployment. Send your questionnaire to hello@notrix.ai and we will work through it with you under NDA.
