Trust

Security

Security is not a feature of BrainPower. It is a precondition. The platform exists to hold the decisions an organisation least wants exposed.

Note: Every claim on this page must be verified against the live system before publication. Do not publish a security claim you cannot demonstrate. Nothing damages enterprise trust faster than a security page that overstates the posture, and enterprise buyers will test it.

Authentication

Email and password authentication with verification, OAuth support, and two factor authentication using time based one time passwords with recovery codes.

Encryption

Data is encrypted in transit using TLS and encrypted at rest.

Access control

Role based access with least privilege by default. Users see only what they are entitled to see. Team and organisation permissions are explicit.

Audit logging

Administrative and security relevant actions are logged with actor, action, and timestamp. The log is queryable and exportable.

Rate limiting and abuse protection

Request rate limiting is enforced at the API and AI layers to protect availability and prevent abuse.

Data isolation

Customer data is logically isolated. Your decisions are visible to you and to those you explicitly grant access.

AI provider handling

Content sent to third party model providers for the language layer is limited to what is required. Quantitative computation is performed inside BrainPower and is never sent to a third party. We select providers that do not train on submitted content.

Responsible disclosure

If you believe you have found a vulnerability, contact reply@smarthinkerz.com. We will acknowledge within two business days. Please do not disclose publicly until we have had a reasonable opportunity to remediate.

© 2026 BrainPower AI. All rights reserved.
OverviewPrivacyTermsSecurityCompliance