BrainBite logo

Security overview.

Short and factual. We share the underlying documentation on request.

Infrastructure and data location

The environment runs single-tenant on Dutch infrastructure. Per institution we record where data sits and which parties have a role in it.

Encryption and access management

Data is encrypted in transit and at rest. Access runs through single sign-on, roles and least privilege.

Compliance and documentation

We provide a data processing agreement, a subprocessor register and a DPIA starter pack, aligned with the GDPR and the EU AI Act.

AI-specific measures

No training on institutional data, measures against prompt injection and a retention policy the institution sets itself.

Incident response

Monitoring, a fixed escalation route and notification within 72 hours of a data breach, with written follow-up.

Continuous improvement

Periodic pentests, a patch policy with fixed deadlines and a responsible disclosure route for researchers.

Security contact

Questions or a report? Email security@brainbite.ai.

Back to PrivateGPT