Security is not a feature of BrainPower. It is a precondition. The platform exists to hold the decisions an organisation least wants exposed.
Note: Every claim on this page must be verified against the live system before publication. Do not publish a security claim you cannot demonstrate. Nothing damages enterprise trust faster than a security page that overstates the posture, and enterprise buyers will test it.
Email and password authentication with verification, OAuth support, and two factor authentication using time based one time passwords with recovery codes.
Data is encrypted in transit using TLS and encrypted at rest.
Role based access with least privilege by default. Users see only what they are entitled to see. Team and organisation permissions are explicit.
Administrative and security relevant actions are logged with actor, action, and timestamp. The log is queryable and exportable.
Request rate limiting is enforced at the API and AI layers to protect availability and prevent abuse.
Customer data is logically isolated. Your decisions are visible to you and to those you explicitly grant access.
Content sent to third party model providers for the language layer is limited to what is required. Quantitative computation is performed inside BrainPower and is never sent to a third party. We select providers that do not train on submitted content.
If you believe you have found a vulnerability, contact reply@smarthinkerz.com. We will acknowledge within two business days. Please do not disclose publicly until we have had a reasonable opportunity to remediate.