Privacy & Your Data

Your data. Isolated. Private. Cited.

Your business knowledge stays yours – never sold, never mixed, never used to train a public model.

  • Per-business isolation
  • Grounded & cited
  • Human approval
  • Sydney region
  • Never trained on
how we protect it

How your data is protected

01/isolation

One business can never reach another's.

The lock is on the vault, not just the door.

Isolation is enforced at the database layer with row-level security – every query is scoped to your business before it runs, in the database, not in application code. The boundary is tested automatically on every change, so it can't quietly regress.

query · acme
Row-level security scopes every query before it runs.
02/grounded & cited

Every answer is grounded in your own brain.

Retrieval over hallucination.

Answers are built from your own content and arrive with the sources attached. If your brain doesn't hold the answer, it says so rather than inventing one – and you can open any citation to read exactly what it drew from.

assistant
Standard refunds are processed within 5 business days of approval.
`policies/refunds.md``handbook/returns.md`
Every claim links to the source it came from.
03/approval before action

Nothing changes without your explicit yes.

Human-in-the-loop on every side-effect.

Anything that sends, writes, or changes data pauses for explicit human approval before it runs. Read and ask freely; acting on the world always waits for a person to say go.

actionpending approval
Nothing is sent or changed until a person approves it.
04/you own your knowledge

Your knowledge stays yours.

Your data, your rules.

Your brain is versioned, editable, and exportable. Edit or roll back any time, export the whole thing whenever you want, and leave with your knowledge intact. There's no lock-in on what you put in.

05/private by default

Private by default – even from owners.

Usage totals, never personal chats.

Admins see usage and cost totals, never individual employees' chats or personal notes. Per-user memory stays private even from owners. The audit log is append-only – entries can be read, never edited or deleted.

06/never sold, trained on, or mixed

Never sold. Never trained on. Never mixed.

Your content isn't the product.

Your content is never sold, never used to train public models, and never blended with another business's brain. It exists to answer for you, and for nothing else.

07/hosted in Australia

Hosted in Australia.

Sydney region.

Your brain runs in the Sydney region, keeping your data on Australian soil. Data residency isn't an add-on – it's where the system lives by default.

08/deployment

Four ways to run it

Where Brain Console runs is itself a privacy choice. Pick how much – if anything – ever leaves your walls.

available

Managed cloud

Run on our infrastructure with your tenant walled off from every other business sharing it.

walled-off tenant
by arrangement

Dedicated instance

Your own single-tenant deployment, ring-fenced from everyone else. Advanced compliance and SSO-style access controls available here.

single-tenant
deployment option

Self-hosted

Runs inside your own environment. Only the model call leaves your walls; your content stays put.

model call only
deployment option

Air-gapped

An open model on your own hardware. Nothing leaves the building.

Honest caveat: a local open model isn't as sharp as the best cloud models yet. This is the “nothing leaves” option.

nothing leaves

Advanced compliance and SSO-style access controls are available as options on dedicated and enterprise deployments. These are configurable controls, not formal certifications.

Have a question about your data?

Talk to us. We’ll walk you through exactly where your data lives, who can reach it, and how the isolation is enforced – no slide-deck hand-waving.