Procurement · Legal · Security
Trust Center
One page for procurement, legal and security: what is in force, where the documents are, how to request the ones that need an agreement, and what we do not have yet.
Three desks, one page
Grinding throughput on a gold mill
Industrial engagement · published in a trade magazine
Problem
Grinding is the largest energy consumer on a mill. Setpoint drift and harder, lower-grade ore make it difficult to hold throughput and particle size at the same time.
Method
Two-year collaboration with the plant process-engineering team. Controlled 25-day trial from 10 January 2024 to 5 February 2024. Modes alternated every 48 hours. Only periods with at least 85% active hours were compared — 265 hours in each mode.
Measured result
+6% throughput (435 t/h vs 412 t/h). 115,347 tonnes processed vs 109,079 tonnes. Particle size (p80) held. Energy intensity (kWh/t) stayed essentially unchanged. Extrapolated full-year effect at this plant: about 2,694 additional ounces of gold, about US$781,000 incremental annual profit net of all-in sustaining cost.
Source
Brasil Mineral magazine, issue 441, July 2024.
Fabio Suizu, Founder — Identified practitioner. The mill is a Canadian mid-tier gold producer. The operator is not named here because we do not have authorization to publish the company name or logo.
This is a published industrial engagement. It is not an API-platform customer logo.
Procurement
Start with the register and the document table. Public pages open here. Gated artifacts (full questionnaire, associate agreement, security policy) go out after we have an agreement on file.
Compliance register
Every row has a state and a date. In-progress items keep their target date until they close. Nothing here is a badge we do not hold.
| Framework | State | Date | Evidence |
|---|---|---|---|
| GDPR (EU/UK) | In force | As of 2026-04-28 | Contractual processing addendum in force, including standard contractual clauses for international transfers and 72-hour breach notice. |
| LGPD (Brazil) | In force | As of 2026-04-28 | Same processing addendum. Data can be resident in Brazil when requested. |
| Cloud control questionnaire (self-attestation) | In force | As of 2026-05-06 | Public answers for key controls. The full questionnaire is sent under agreement. |
| SOC 2 Type II | In progress | As of 2026-08-23 · target 2026-09-30 | Controls are implemented. The independent audit is in progress — not complete. The report will be shared under agreement when issued. |
| HIPAA associate agreement | On request | As of 2026-08-23 | Available on request for healthcare workloads on annual contracts. Not a certification. |
| ISO/IEC 27001 | In progress | As of 2026-08-23 · target 2027-12-31 | Control mapping in progress. Certification is not complete. |
| CSA STAR Level 1 listing | In progress | As of 2026-08-23 · target 2026-09-30 | Self-attestation deposit is in progress. Not listed yet. |
| CSA STAR Level 2 | Not started | As of 2026-08-23 | Not started. Planned after the independent audit path in 2027. |
| Independent penetration test | In progress | As of 2026-08-23 · target 2026-09-30 | Internal testing runs today. An independent report is in progress and is not complete. |
| Presentation-attack detection, Level 2 | In progress | As of 2026-08-23 · target 2027-03-31 | On the public identity roadmap. Not certified. |
| Formal bug bounty | Not started | As of 2026-08-23 | Not started. Coordinated disclosure is open via security.txt. Recognition is offered; there is no paid bounty yet. |
Legal
The processing addendum, privacy policy and terms are public. The master agreement page states which clauses we negotiate. We do not publish a customer logo or a quote without a named person and role.
Documents
Every public link below is a page or file that exists. Gated items use a mail path that names the document — we send them after an agreement.
Public
| Document | What it is | Access |
|---|---|---|
| Privacy policy | Legal · how we handle personal data | Open |
| Terms of service | Legal · default contract | Open |
| Data processing addendum | Legal · GDPR / LGPD processing terms | Open |
| Control questionnaire (key controls) | Security · public self-attestation | Open |
| Enterprise master agreement | Procurement · negotiable clauses on annual contracts | Open |
| Published grinding case study | Procurement · measured industrial result | Open |
| Identity verification roadmap | Security · public RFC, including what is not built | Open |
| Content moderation model card | Security / legal · intended use and known limits | Open |
| Live status page | Security · current health, not a claimed uptime percentage | Open |
| security.txt | Security · coordinated disclosure | Open |
| Contact | All desks · named mailboxes | Open |
| Pilot services addendum | Legal · paid evaluation pilots | Open |
| Pilot processing annex template | Legal · production data in a pilot | Open |
Under agreement
These are not hosted on this site. The link opens a message to legal or security with the document name in the subject.
| Document | What it is | Access |
|---|---|---|
| Full control questionnaire | Security · complete questionnaire under agreement | Request |
| SOC 2 Type II report | Security · shared when the audit completes, under agreement | Request |
| Business associate agreement | Legal · healthcare workloads on request | Request |
| Information security policy | Security · under agreement | Request |
| Software bill of materials | Security · under agreement | Request |
| Independent pen-test report | Security · when issued, under agreement | Request |
Security
API payloads are processed in memory and discarded when the response is sent. We do not store payloads to train models. Keys are stored as hashes. Traffic is encrypted in transit. Workloads run on dedicated machines we operate — not on a third-party public cloud. Residency options are in the processing addendum.
Sub-processors
The named list lives in the processing addendum. We give 30 days' notice before adding a sub-processor. Open the addendum.
Breach and disclosure
- Contain and assess scope within 1 hour of discovery.
- Notify affected controllers within 72 hours using the email on file.
- Provide nature, categories, approximate counts, likely consequences, and mitigation.
- Post a public incident note on the status page.
Coordinated vulnerability reports go to security@brainiall.com. Policy: security.txt.
What we do not have yet
Stated as in progress or not started — never as done.
- SOC 2 Type II audit report — in progress, target 2026-09-30.
- ISO/IEC 27001 certification — in progress, target 2027-12-31.
- Independent penetration-test report — in progress, target 2026-09-30.
- CSA STAR Level 1 listing — in progress, target 2026-09-30.
- CSA STAR Level 2 — not started, target 2027-12-31.
- Presentation-attack detection Level 2 — in progress, target 2027-03-31.
- Formal paid bug bounty — not started.
- API-platform customer logos — not started. We do not publish a logo without authorization.
Ask for a document
If a questionnaire is not answered by the pages above, write to legal@brainiall.com · contact page.