Trust and governance

This is where privacy, isolation, and AI accountability actually live.

The commercial surface has to make the operational truth legible. BrainCaps trust is defined by isolation tiers, operator boundaries, evidence discipline, and product decisions that can survive scrutiny.

Core rule

The customer surface can scale only if tenant isolation and proof quality scale with it.

Isolation tiers

Tenant sensitivity changes the operating bar.

A single shared story is not enough. BrainCaps already distinguishes sandbox use, standard customer use, and more demanding regulated or sensitive patterns.

T1

Internal sandbox only.

Allowed for synthetic data, non-sensitive demo datasets, and internal experimentation only.

T2

Minimum for standard client tenants.

Tenant-scoped boundaries, operator discipline, retention controls, and production-grade access assumptions become mandatory.

T3

Required for sensitive or regulated cases.

Dedicated isolation expectations increase when the tenant is regulated, highly sensitive, or contractually constrained.

Control planes

Trust is an operating model, not a footer claim.

Privacy, AI governance, operator accountability, and evidence discipline need clear ownership and repeatable execution paths.

Privacy operations

Retention, export, deletion, RoPA, DSR, DPIA, and subprocessor discipline must exist as operating routines, not just as legal text.

AI governance

Use-case qualification, capability inventory, AI Act posture, model boundaries, and review before new AI-enabled behaviors are introduced.

Operator accountability

No invisible cross-tenant access, no silent break-glass habits, and no admin drift from the private console into the customer surface.

Evidence discipline

Health, provenance, entitlements, and trust claims should be supportable by concrete evidence packs rather than marketing-only assertions.

Reference frameworks

Standards are targets, not decorative badges.

The commercial surface can name the operating bar, but it should not pretend the evidence already exists if the controls are not yet closed.

Security target

ISO/IEC 27001 and SOC 2 Type II

These define the minimum seriousness expected for access control, change discipline, incident response, and evidence-backed operations.

Privacy target

GDPR and ISO/IEC 27701

RoPA, DSR handling, retention, deletion, lawful basis, and subprocessor discipline must be supportable by real operating routines.

AI target

EU AI Act, ISO/IEC 42001, and NIST AI RMF

Use-case qualification, model boundaries, human accountability, and change review should exist before new AI-enabled behavior reaches sensitive tenants.

Surface separation

Clear surfaces are part of the trust model.

When public copy, shared shell, customer workspace, and private admin are mixed together, access boundaries get blurry. The architecture should stay understandable from the outside.

braincaps-web

Public explanation, positioning, trust framing, and routing into the product journey.

PortalHQ

Shared identity, organizations, billing, access, and the transversal customer shell.

braincaps-app

Customer workspace for memory, ingestion, usage, and product-scoped configuration.

braincaps360

Private operator console, never mixed into the public or customer route map.