Skip to main content
Brainiall

Procurement · Legal · Security

Trust Center

One page for procurement, legal and security: what is in force, where the documents are, how to request the ones that need an agreement, and what we do not have yet.

Last reviewed 2026-08-23

Three desks, one page

Published case studyBrasil Mineral · #441 · Jul 2024

Grinding throughput on a gold mill

Industrial engagement · published in a trade magazine

+6%throughput vs manual
US$781Kannual margin, extrapolated
25controlled pilot (days)

Problem

Grinding is the largest energy consumer on a mill. Setpoint drift and harder, lower-grade ore make it difficult to hold throughput and particle size at the same time.

Method

Two-year collaboration with the plant process-engineering team. Controlled 25-day trial from 10 January 2024 to 5 February 2024. Modes alternated every 48 hours. Only periods with at least 85% active hours were compared — 265 hours in each mode.

Measured result

+6% throughput (435 t/h vs 412 t/h). 115,347 tonnes processed vs 109,079 tonnes. Particle size (p80) held. Energy intensity (kWh/t) stayed essentially unchanged. Extrapolated full-year effect at this plant: about 2,694 additional ounces of gold, about US$781,000 incremental annual profit net of all-in sustaining cost.

Source

Brasil Mineral magazine, issue 441, July 2024.

Fabio Suizu, FounderIdentified practitioner. The mill is a Canadian mid-tier gold producer. The operator is not named here because we do not have authorization to publish the company name or logo.

This is a published industrial engagement. It is not an API-platform customer logo.

Procurement

Start with the register and the document table. Public pages open here. Gated artifacts (full questionnaire, associate agreement, security policy) go out after we have an agreement on file.

Compliance register

Every row has a state and a date. In-progress items keep their target date until they close. Nothing here is a badge we do not hold.

Frameworks, current state, dates, and where to read or request evidence.
FrameworkStateDateEvidence
GDPR (EU/UK)In forceAs of 2026-04-28

Contractual processing addendum in force, including standard contractual clauses for international transfers and 72-hour breach notice.

Open the public document

LGPD (Brazil)In forceAs of 2026-04-28

Same processing addendum. Data can be resident in Brazil when requested.

Open the public document

Cloud control questionnaire (self-attestation)In forceAs of 2026-05-06

Public answers for key controls. The full questionnaire is sent under agreement.

Open the public document

SOC 2 Type IIIn progressAs of 2026-08-23 · target 2026-09-30

Controls are implemented. The independent audit is in progress — not complete. The report will be shared under agreement when issued.

Request under agreement

HIPAA associate agreementOn requestAs of 2026-08-23

Available on request for healthcare workloads on annual contracts. Not a certification.

Request under agreement

ISO/IEC 27001In progressAs of 2026-08-23 · target 2027-12-31

Control mapping in progress. Certification is not complete.

CSA STAR Level 1 listingIn progressAs of 2026-08-23 · target 2026-09-30

Self-attestation deposit is in progress. Not listed yet.

CSA STAR Level 2Not startedAs of 2026-08-23

Not started. Planned after the independent audit path in 2027.

Independent penetration testIn progressAs of 2026-08-23 · target 2026-09-30

Internal testing runs today. An independent report is in progress and is not complete.

Request under agreement

Presentation-attack detection, Level 2In progressAs of 2026-08-23 · target 2027-03-31

On the public identity roadmap. Not certified.

Open the public document

Formal bug bountyNot startedAs of 2026-08-23

Not started. Coordinated disclosure is open via security.txt. Recognition is offered; there is no paid bounty yet.

Open the public document

Documents

Every public link below is a page or file that exists. Gated items use a mail path that names the document — we send them after an agreement.

Public

Documents you can open without an agreement.
DocumentWhat it isAccess
Privacy policyLegal · how we handle personal dataOpen
Terms of serviceLegal · default contractOpen
Data processing addendumLegal · GDPR / LGPD processing termsOpen
Control questionnaire (key controls)Security · public self-attestationOpen
Enterprise master agreementProcurement · negotiable clauses on annual contractsOpen
Published grinding case studyProcurement · measured industrial resultOpen
Identity verification roadmapSecurity · public RFC, including what is not builtOpen
Content moderation model cardSecurity / legal · intended use and known limitsOpen
Live status pageSecurity · current health, not a claimed uptime percentageOpen
security.txtSecurity · coordinated disclosureOpen
ContactAll desks · named mailboxesOpen
Pilot services addendumLegal · paid evaluation pilotsOpen
Pilot processing annex templateLegal · production data in a pilotOpen

Under agreement

These are not hosted on this site. The link opens a message to legal or security with the document name in the subject.

Documents sent after an agreement.
DocumentWhat it isAccess
Full control questionnaireSecurity · complete questionnaire under agreementRequest
SOC 2 Type II reportSecurity · shared when the audit completes, under agreementRequest
Business associate agreementLegal · healthcare workloads on requestRequest
Information security policySecurity · under agreementRequest
Software bill of materialsSecurity · under agreementRequest
Independent pen-test reportSecurity · when issued, under agreementRequest

Security

API payloads are processed in memory and discarded when the response is sent. We do not store payloads to train models. Keys are stored as hashes. Traffic is encrypted in transit. Workloads run on dedicated machines we operate — not on a third-party public cloud. Residency options are in the processing addendum.

Sub-processors

The named list lives in the processing addendum. We give 30 days' notice before adding a sub-processor. Open the addendum.

Breach and disclosure

  1. Contain and assess scope within 1 hour of discovery.
  2. Notify affected controllers within 72 hours using the email on file.
  3. Provide nature, categories, approximate counts, likely consequences, and mitigation.
  4. Post a public incident note on the status page.

Coordinated vulnerability reports go to security@brainiall.com. Policy: security.txt.

What we do not have yet

Stated as in progress or not started — never as done.

  • SOC 2 Type II audit report — in progress, target 2026-09-30.
  • ISO/IEC 27001 certification — in progress, target 2027-12-31.
  • Independent penetration-test report — in progress, target 2026-09-30.
  • CSA STAR Level 1 listing — in progress, target 2026-09-30.
  • CSA STAR Level 2 — not started, target 2027-12-31.
  • Presentation-attack detection Level 2 — in progress, target 2027-03-31.
  • Formal paid bug bounty — not started.
  • API-platform customer logos — not started. We do not publish a logo without authorization.

Ask for a document

If a questionnaire is not answered by the pages above, write to legal@brainiall.com · contact page.

Trust Center | Brainiall