Security overview.
Short and factual. We share the underlying documentation on request.
Infrastructure and data location
The environment runs single-tenant on Dutch infrastructure. Per institution we record where data sits and which parties have a role in it.
Encryption and access management
Data is encrypted in transit and at rest. Access runs through single sign-on, roles and least privilege.
Compliance and documentation
We provide a data processing agreement, a subprocessor register and a DPIA starter pack, aligned with the GDPR and the EU AI Act.
AI-specific measures
No training on institutional data, measures against prompt injection and a retention policy the institution sets itself.
Incident response
Monitoring, a fixed escalation route and notification within 72 hours of a data breach, with written follow-up.
Continuous improvement
Periodic pentests, a patch policy with fixed deadlines and a responsible disclosure route for researchers.
Security contact
Questions or a report? Email security@brainbite.ai.
Back to PrivateGPT