# Briard-AI security posture

Version 1.0 — reviewed August 11, 2026

## Scope and assurance status

Briard-AI is a hosted, metadata-only AI-governance evidence service. It is not designed to receive CUI, PHI, payment-card data, credentials, customer production records, or raw prompt/output content.

Briard-AI does not currently hold a SOC 2 report or ISO certification, and no audit completion date is represented as scheduled. Available assurance consists of implemented product controls, automated tests, production health checks, and internal operating evidence. That is not the same as independent certification or a penetration-test opinion.

## Implemented product controls

- Organization-scoped authorization and PostgreSQL row-level security for tenant tables.
- TOTP multi-factor authentication required for owner and administrator access.
- Private evidence-object storage with file-size, SHA-256, malware, and active-content checks before an object can be treated as clean.
- Tamper-evident event chains and retained RFC 3161 timestamp request/receipt material for supported production ledger anchors.
- TLS on public production endpoints, security headers, rate limits, and secrets kept outside client bundles and source control.
- Deterministic evidence-package manifests that distinguish attested, evidenced, and missing items.
- Metadata-only warnings and validation that block regulated-data-like content in governed entry points.

## Current limitations

- No SOC 2 Type I/II, ISO 27001, ISO 42001, FedRAMP, StateRAMP, or CMMC certification is held.
- No independently validated penetration-test report is currently offered.
- Independent private-object backup and restore evidence remains an operational readiness item; provider-managed durability is not represented as an independently tested Briard-AI recovery control.
- A contractual DPA, breach-notification period, recovery-time commitment, and data-residency commitment require approved contract terms and are not currently offered as public commitments.

## Contacts

- Security reports: security@briard-ai.app
- Procurement and legal questions: legal@briard-ai.app
- Service support: support@briard-ai.app

This document describes current product posture; it is not a certification, warranty, or contract amendment.
