Olbrain Studio is built for enterprises that operate under regulatory scrutiny — RBI, DPDP, sectoral regulators, and your own InfoSec team. The architecture below describes what runs in production today, and the certifications still moving toward attestation. We err toward honest status over polished claims.
Olbrain customer data is stored, processed, and accessed within India — primary region Google Cloud Mumbai. Payloads are PII-tokenized before reaching third-party language models (see 11); a sub-processor inventory documenting these flows is being formalized below.
Customer data is logically segregated; no cross-tenant exposure in storage, prompt context, or audit surfaces.
Least-privilege access by default. Privileged operations require strong authentication and are reviewed quarterly.
Encryption everywhere. PII detection by default. Customer data is never used to train models.
Every transaction, every decision, every administrative action is logged. The audit trail is the backbone of the product.
The risks unique to AI agents — prompt injection, hallucination, training drift, cross-tenant prompt leakage — treated as first-class engineering concerns.
Defined detection, classification, response, and customer-notification process. Reachable 24×7 for critical incidents.
Targets are fixed and engagements are underway. We publish progress, not just intentions.
Named ownership, defined organizational structure, and a documented policy stack.
Standard contracts include the data, AI, third-party, and exit obligations enterprise customers expect.
The most important part of our InfoSec story is what happens to your customers' PII. The short version: it is designed so the LLM does not see it.
Olbrain’s proprietary state-carrier primitive: context, memory, and identity unified into one LLM-window-fit packet.
Tamper-evident, replayable verification over CS-packet streams. Witnesses are Olbrain-operated today; a federated, independent witness network is on the roadmap.
One legal entity, incorporated in India. Indian customer data is held, processed, and contracted by it — there is no foreign parent or affiliate in the data path.