We launched on Product Hunt!We launched on Product Hunt! If you like Brain, please support us by following the launch.See the launch on Product Hunt (opens in a new tab)

Brain · The Brain Platform

Secure AI for Business Starts with Controlled Access

Give people and agents access to approved company knowledge, keep restricted sources out of their answers, and review the evidence behind the workflow.

Fictional example · evidence you can inspect

What are the expense deadline and compensation-review notes?

The fictional handbook gives the expense deadline: the fifth working day of the next month. The compensation-review note is a separate restricted source. This first card shows only the permitted handbook reference; inspect the separate compensation card under each example identity to see the compensation portion withheld.

Operations expense handbook
Source excerpt · Operations expense handbook

Submit ordinary expense reports by the fifth working day of the next month.

Secure AI for business requires more than a private chat window

A security review often begins with a simple question: which company information will this assistant receive? An enterprise account can improve contractual protections, but the account label alone does not tell you which handbook, finance folder or client document enters a particular answer. The useful boundary is the one between the person or agent asking and the sources that identity is allowed to consult.

Brain provides a knowledge layer that compatible AI clients can query. Its published access model ties retrieval to people and agents rather than treating an entire connected collection as public to everyone. Start with a small approved source set, identify the owner of each collection and give a test agent only the scope it needs. A familiar answer should still point to evidence you can inspect.

Separate the access decision from the record of the decision. An access-record review can examine actor, action, object and outcome fields. Those fields do not describe everything that may be stored: query records may include query text, and activity metadata may contain content. Review the actual record for a known test request and check coverage and retention before using it as audit evidence.

The rest of the data path matters too. Review processing, storage, source connections and model-provider terms for the account you will use. Bringing your own model key changes who controls the provider credential; it does not make every request free or erase the provider from the workflow. Combine a practical access test with the current privacy terms and available assurance documents when deciding whether the rollout fits your requirements.

Connect. Ask. Govern.

From scattered documents to a shared answer

  1. 01

    Connect approved review material

    Choose the handbook and operating notes the pilot needs. Name the source owners, confirm who may read the collection and exclude private payroll or deal material from the initial security test.

  2. 02

    Ask as the intended identity

    Use an approved compatible client to ask the expense question as a support teammate and a scoped agent. Inspect the handbook excerpt and compare the separate restricted-source example.

  3. 03

    Review access and records

    Test a fresh request after changing scope or retiring a credential. Inspect the actual recorded activity and provider configuration, then retain the evidence needed for the security decision.

See the idea in action

secure ai for business: questions with evidence

Fictional examples. These interactions do not query your Brain or test real permissions.

Try the example as

Open a question, then inspect its source excerpts.

Try a fictional model and agent setup

Choose a model-key arrangement, then retire the example onboarding agent. These controls change only this illustration; no API key is requested and no credential is created or revoked.

Example arrangement: model setup still to be reviewed. Confirm supported providers and account configuration before connecting sources.

Fictional agent scope: staff guide and onboarding checklist.

Next reference request in this illustration: Allowed within the assigned scope

Compensation appendix: outside this agent’s assigned collection.

Retirement here demonstrates a state change. It does not erase previously received text, establish revocation timing or prove live authorization. Verify a fresh request and downstream copies in the actual approved deployment.

Keep working in the AI tools you use

Brain is a knowledge layer reached through MCP, the Model Context Protocol. Claude, Cursor and Codex are examples of compatible clients in the existing product. Client support and setup differ, so check the current connection instructions rather than assuming every assistant has the same capabilities.

Connect a useful set of sources first

The current public setup describes Google Drive and Notion as connected sources, alongside documents you choose to add. Start with a focused collection and inspect the actual connection screen for availability. A tool appearing in a roadmap or illustration does not mean its connector is ready for your account.

Google Drive

Connect the documents your workspace needs.

Notion

Bring approved pages into a shared knowledge layer.

Your documents

Add a focused set of knowledge you own.

Keep access intentional

AI data security includes access, processing and evidence

Enterprise AI security begins with an identified asker and a useful, limited collection. AI data privacy also depends on the services processing that collection and the terms covering their work. A private AI for business proposal should explain both paths. Brain provides source-aware access and activity records; assess their actual coverage alongside source ownership, storage, provider terms and the current assurance documentation. Query records may store query text, and activity metadata may contain content. Review these storage categories separately from actor, object, action and outcome fields. The content-free examples on this page do not establish that all stored records are content-free.

Fictional content-blind access record
Choose an illustrative access decision
Actor
Example policy reviewer
Object
demo-object-01
Action
Read
Scope rule
Included in the example collection
Outcome
Allowed

No document content appears in this illustration. It is not a record from your account or proof of live enforcement.

Read the privacy policy

Keep a security pilot focused enough to measure

Use the same approved test questions when comparing a full document bundle with relevant source context. Record input usage and answer quality, then include retrieval, outputs and Brain charges in the budget. Bring your own key, often called BYOK, can put the model credential under your control; it does not establish free usage or a fixed percentage saving.

Compare current plans and limits

Match the security approach to the data path

Choosing an approach for this workflow
ApproachWhat to consider
Personal AI accountsConvenient for personal work, but company approval, product terms and connected material still need review. Do not assume a personal subscription supplies the identity, source scope or records your organization requires.
Enterprise assistant plansCan provide business terms and administrative features. Evaluate the plan’s actual source-access behavior and logs; modern enterprise products vary, and an enterprise label alone neither proves nor disproves permission-aware retrieval.
Build an internal retrieval systemOffers control over architecture and hosting choices. Your team owns connector permissions, tenant boundaries, agent identities, logging and ongoing changes. Include those maintenance responsibilities in the decision alongside the search and model components.
Brain with a compatible clientAdds a shared, governed knowledge layer to a client workflow. Test source scope, a restricted user, an agent credential and the resulting records in your own environment. Review provider processing and available assurance documentation as separate parts of the rollout.

secure ai for business: frequently asked questions

Is it safe to use AI with company data?

It depends on the data, approved purpose, product configuration and provider terms. Establish who can access each source and which services process it. Then test permitted and restricted identities using non-sensitive material. Brain supports a governed knowledge workflow, but a marketing page cannot establish that every company dataset or use case is appropriate.

Does Brain train on our data?

Brain’s published product information says connected knowledge is not used to train a model. Review the current privacy policy and the terms covering your selected model provider and account. A no-training commitment addresses training; it does not imply zero processing, zero storage, no subprocessors or unlimited retention exemptions across the complete workflow.

How does Brain enforce permissions?

Brain’s published model uses source-aware access and identities for people and agents so retrieval can respect the asker’s permitted scope. Validate the particular connector and workspace in a pilot: ask the same question as an approved and restricted identity, then change access and test again. The interactive examples here use fictional data.

What does the audit record contain?

Review activity records by field and storage category. Query records may include query text, and activity metadata may contain content. Review the actual fields available for your workflow, including actor, object, action, outcome and timing where recorded. Coverage, retention and verification matter as much as the format. The illustration is not evidence from your account.

Can we use our own model API key?

Brain’s published product information describes bringing your own model key. Confirm the provider and configuration available in your account before planning a rollout. The provider’s API charges and terms can differ from a chat subscription. Keep credentials in the approved configuration flow, and never include them in a demo request or knowledge document.

Is Brain GDPR compliant?

Brain’s privacy policy describes personal-data processing and service providers. Review it with your organization’s purpose, data categories, contracts and transfer requirements. Access controls and records can support a privacy program, but they do not make every connected dataset or deployment compliant automatically. Obtain the applicable contractual and operational evidence for your particular use.

What is Brain's SOC 2 status?

Request current assurance documentation before relying on a SOC 2 or ISO 42001 claim. Check the reporting entity, covered service, scope and dates with the responsible reviewer. This page does not establish a completed report, certification or current programme status. Source-access testing and contractual review remain separate parts of your deployment decision.

How do we revoke an agent's access?

Use the administrative controls available for the agent credential and its assigned scope, then verify a new request is refused as intended. Include connected services and downstream outputs in the retirement checklist. Revoking future access does not erase information already copied into another system, and this page does not promise a universal propagation time.

Make the next security review concrete

Choose an approved collection, compare two identities, inspect the source evidence and review the actual access records. Start with a workflow small enough to understand before widening the scope.