# Briard-AI vendor security questionnaire

Version 1.0 — reviewed August 11, 2026

| Question | Current answer | Evidence/status |
| --- | --- | --- |
| What service is provided? | Hosted metadata-only AI governance records, deterministic evidence packages, and tamper-evident activity history | Public platform overview and security page |
| Is CUI or PHI accepted? | No | Product warnings, input validation, Terms, and security posture |
| Is tenant data isolated? | Yes, through organization-scoped authorization and database row-level security | Automated schema/RLS checks and production tenant tests |
| Is MFA available? | TOTP MFA is required for owner and administrator workspace access | Auth implementation and production golden-path test |
| Is data encrypted in transit? | Yes, on production public endpoints | TLS and security-header checks |
| Is customer evidence public? | No; evidence storage is private and access is organization-scoped | Storage and tenant authorization controls |
| Are uploads scanned? | The evidence flow verifies size and SHA-256 and scans for malware and active content before clean status | Backend tests and security posture |
| Is an audit trail provided? | Yes, material activity is linked in a tamper-evident ledger; supported anchors retain RFC 3161 request/receipt evidence | Ledger tests, production verification, public sample verifier |
| Does integrity prove compliance? | No | Public verifier and artifact legal notices |
| Is SOC 2 or ISO certification held? | No | Not available; no completion date represented |
| Is a penetration-test report available? | No | Not currently available |
| Is a DPA available for execution? | No | Counsel-approved terms pending |
| Is a contractual breach-notification period available? | No | Counsel-approved commitment pending |
| Is contractual data residency available? | No | Not currently offered |
| Are subprocessors disclosed? | Yes | Versioned public subprocessor register |
| Is backup/restore independently tested? | Provider-managed durability exists; independent Briard-AI private-object restore evidence is not currently complete | Open operational readiness item |
| How are incidents reported? | security@briard-ai.app | Public security contact |
| How are privacy requests submitted? | Account page or privacy@briard-ai.app | Privacy Notice and data lifecycle sheet |

Answers marked unavailable are intentional disclosures, not implied controls. A buyer should use its own risk process before approval.
