Trust · Last updated June 2026

InfoSec-first by construction, not bolted on later.

Olbrain Studio is built for enterprises that operate under regulatory scrutiny — RBI, DPDP, sectoral regulators, and your own InfoSec team. The architecture below describes what runs in production today, and the certifications still moving toward attestation. We err toward honest status over polished claims.

security@olbrain.com Request security questionnaire Request DFD & controls evidence
Status ✓ Live Running in production today. • In Progress Under active build-out / certification.
01

Data Residency

Olbrain customer data is stored, processed, and accessed within India — primary region Google Cloud Mumbai. Payloads are PII-tokenized before reaching third-party language models (see 11); a sub-processor inventory documenting these flows is being formalized below.

02

Architecture & Tenant Isolation

Customer data is logically segregated; no cross-tenant exposure in storage, prompt context, or audit surfaces.

03

Access Control

Least-privilege access by default. Privileged operations require strong authentication and are reviewed quarterly.

04

Data Protection

Encryption everywhere. PII detection by default. Customer data is never used to train models.

05

Audit & Logging

Every transaction, every decision, every administrative action is logged. The audit trail is the backbone of the product.

06

AI-Specific Controls

The risks unique to AI agents — prompt injection, hallucination, training drift, cross-tenant prompt leakage — treated as first-class engineering concerns.

07

Incident Response

Defined detection, classification, response, and customer-notification process. Reachable 24×7 for critical incidents.

08

Compliance & Certifications

Targets are fixed and engagements are underway. We publish progress, not just intentions.

09

Information Security Governance

Named ownership, defined organizational structure, and a documented policy stack.

10

Customer Commitments in MSA

Standard contracts include the data, AI, third-party, and exit obligations enterprise customers expect.

11

PII Architecture — in detail

The most important part of our InfoSec story is what happens to your customers' PII. The short version: it is designed so the LLM does not see it.

12

Cognitive Substrate (CS-packet)

Olbrain’s proprietary state-carrier primitive: context, memory, and identity unified into one LLM-window-fit packet.

13

Witness Network

Tamper-evident, replayable verification over CS-packet streams. Witnesses are Olbrain-operated today; a federated, independent witness network is on the roadmap.

14

Legal Entity & Data Controller

One legal entity, incorporated in India. Indian customer data is held, processed, and contracted by it — there is no foreign parent or affiliate in the data path.