Tenant isolation
Every tenant data table is designed around org_id, Postgres row-level security, and server-side authorization.

Briard-AI stores system descriptions, attestations, evidence references, findings, artifact metadata, and ledger events. It is not a place for CUI, PHI, customer production data, or customer prompt and output content.
Implemented controls and internal test evidence are available. No independent certification date is represented as scheduled.
Open trust center Download postureEvery tenant data table is designed around org_id, Postgres row-level security, and server-side authorization.
Evidence files stay private while the server verifies size and SHA-256, scans for malware and active content, and quarantines anything that does not pass.
Material actions write canonical payload hashes into a tamper-evident hash chain with RFC 3161 timestamp anchoring.
Inputs warn on regulated-data-like patterns and ask users to rephrase into metadata before saving.
Review subprocessors, data lifecycle, assurance limits, and the vendor questionnaire.