Metadata-only by design.

Briard-AI stores system descriptions, attestations, evidence references, findings, artifact metadata, and ledger events. It is not a place for CUI, PHI, customer production data, or customer prompt and output content.

Current assurance statusNo SOC 2 or ISO certification held

Implemented controls and internal test evidence are available. No independent certification date is represented as scheduled.

Open trust center Download posture

Tenant isolation

Every tenant data table is designed around org_id, Postgres row-level security, and server-side authorization.

Private evidence storage

Evidence files stay private while the server verifies size and SHA-256, scans for malware and active content, and quarantines anything that does not pass.

Append-only ledger

Material actions write canonical payload hashes into a tamper-evident hash chain with RFC 3161 timestamp anchoring.

Plain language boundaries

Inputs warn on regulated-data-like patterns and ask users to rephrase into metadata before saving.

Current production posture

  • TLS 1.2 or newer on the production domain.
  • TOTP multi-factor authentication is required for owner and administrator workspace access.
  • A daily private-object backup job and a SHA-256-verified object restore drill are evidenced. Database, identity/configuration, and full-boundary recovery exercises remain open operational readiness items.
  • Public security contact at security@briard-ai.app; no contractual breach-notification period is currently published.
  • No legal-advice, assessment, certification, or SPRS scoring posture in the product.

Review subprocessors, data lifecycle, assurance limits, and the vendor questionnaire.