07SOC 2 Type II

Audited controls,
annually attested.

Effective 2026-05-07

Brain by AIStack maintains a SOC 2 Type II report covering the Security, Availability, and Confidentiality trust service criteria. The report is renewed every 12 months and is available to customers and prospective customers under NDA.

Scope

The report covers the Brain hosted service — including the API, dashboard, document indexing pipeline, and supporting infrastructure. It does not cover self-hosted deployments operated by customers.

Controls

  • Access — SSO + MFA, role-based least privilege, quarterly access reviews.
  • Change management — peer-reviewed pull requests, automated CI gates, signed deploys.
  • Vulnerability management — automated dependency scanning, internal bug bounty, quarterly third-party penetration tests.
  • Logging & monitoring — centralized logs, anomaly detection, on-call rotation with documented runbooks.
  • Incident response — tabletop exercises twice a year; postmortems published for all sev-2+ incidents.

Subprocessors

Our SOC 2 program covers oversight of subprocessors handling production data. Subprocessor list and their attestations are available on request.

Requesting the report

Customers and prospective customers can request the most recent SOC 2 Type II report by emailing trust@aistack.dev. Reports are shared under NDA via a secure data room.

Questions? Email legal@aistack.dev.