SOC 2 Type II
Security · Availability · ConfidentialityIndependent attestation of controls operating effectively over time, with continuous evidence collection.
The systems we build run in regulated, high-stakes environments — so security, privacy and compliance aren't a checklist at the end. They're designed into the architecture, enforced in code, and evidenced by default.
We align engagements to the frameworks our clients are held to — with the controls, evidence and audit trails to back them up.
Independent attestation of controls operating effectively over time, with continuous evidence collection.
A documented ISMS with risk treatment, policy and continual improvement mapped to ISO 27001 controls.
Data residency, lawful basis, consent and right-to-erasure designed into how we handle personal data.
PHI handling, de-identification and access audit for healthcare workloads, with BAAs available on request.
Tokenization and segmented architectures for payment workloads — scope and attestation engagement-dependent.
Consumer rights, opt-out and disclosure handling for California residents built into our data processes.
The same engineering discipline we apply to building platforms governs how we secure and operate them.
Data encrypted in transit with TLS 1.2+ and at rest with AES-256. Keys managed in a dedicated KMS with rotation and strict access policies.
Single sign-on via SAML/OIDC, enforced MFA and role-based, least-privilege access. Every grant is reviewed and time-bound.
Security woven into delivery: code review, SAST/DAST, dependency scanning and signed builds gate every release.
Continuous scanning, prioritized remediation SLAs and routine third-party penetration tests with tracked findings.
Centralized logging, anomaly detection and a documented incident response plan with defined severities and on-call rotations.
Automated backups, tested restore procedures and multi-region resilience targets so critical systems recover fast.
How we process, store and protect data is documented in plain language. The full terms live in our policies.
What personal data we collect, the lawful basis for processing it, how long we keep it, and the rights you can exercise over it.
Read the Privacy PolicyThe cookies and similar technologies we use, what each category does, and how to manage your consent at any time.
Read the Cookie PolicyWe keep a current list of the subprocessors we rely on and the regions data is processed in. Hosting region can be scoped per engagement.
| Subprocessor | Purpose | Data region | Type |
|---|---|---|---|
| Cloud Platform APrimary infrastructure & compute | Application hosting, storage and managed databases | US · UK | Infrastructure |
| Cloud Platform BSecondary / DR region | Disaster recovery and regional failover | UAE · India | Infrastructure |
| Observability VendorLogging & monitoring | Application metrics, logs and alerting | US | Monitoring |
| Email & Comms ProviderTransactional messaging | System notifications and account email | UK | Communications |
| Support PlatformCustomer support | Ticketing and support correspondence | US · India | Operations |
We welcome reports from security researchers and treat them seriously. Report a suspected vulnerability in good faith and we'll work with you to verify and resolve it — and we won't pursue action against researchers who follow this policy.
Email security@braindoos.com with steps to reproduce, impact and any proof-of-concept. Please don't disclose publicly before we've responded.
We aim to acknowledge within two business days, validate the report and assign a severity and owner.
We remediate, keep you updated on progress, and coordinate timing on any public acknowledgement of your finding.
Request our security overview, latest reports, a completed questionnaire, or a mutual NDA. Our team will route you to the right materials for your review.