Trust

Compliance

Our position, stated plainly. BrainPower AI is an early stage platform. We are building toward formal certification and we are not going to claim certifications we do not hold.

Note: Verify every claim on this page against the live system. Remove anything you cannot evidence. The honest framing here is deliberate: an early stage company that states its gaps clearly is more credible to an enterprise buyer than one that implies a posture it does not have, and enterprise diligence will find the difference.

What we do today

  • Data protection controls aligned with the principles of Oman's Personal Data Protection Law and the GDPR: data minimisation, explicit consent, right of access, right of export, and right of erasure.
  • Encryption in transit and at rest.
  • Two factor authentication and role based access control.
  • Audit logging of administrative and security relevant actions.
  • Data export and deletion available to every user on request.
  • Contractual review of subprocessors, and a maintained list available on request.

What we do not yet have

We are not currently SOC 2 certified, ISO 27001 certified, or HIPAA covered. We will say so plainly rather than imply otherwise. Formal certification is on the roadmap and will be announced when it is achieved, not before.

Regional posture

  • GCC: aligned with Oman's Personal Data Protection Law. Data residency options are available for enterprise customers on request.
  • Europe: GDPR aligned. A data processing agreement is available for enterprise customers.
  • Japan: working toward alignment with the Act on the Protection of Personal Information.

Enterprise requirements

If your procurement process requires specific controls, certifications, or a data processing agreement, contact reply@smarthinkerz.com. We would rather have that conversation directly than have you discover a gap after signing.

© 2026 BrainPower AI. All rights reserved.
OverviewPrivacyTermsSecurityCompliance