Certifications and Compliance
Our ISO 27001 certificate and SOC 2 Type II report are available from the Trust Center, alongside the active control list and our declared subprocessors. For anything it doesn’t cover, contact your account manager or email our DPO, terence@getvirtualbrain.com.
Data Handling
A Dedicated, Secure Environment
VirtualBrain runs in a dedicated secure environment for your organization, designed for the confidentiality standards enterprise clients expect:- EU-hosted infrastructure: Your documents and data are processed and stored in the European Union, on a hybrid AWS and Azure architecture running primarily in Paris with nodes in Frankfurt
- Enterprise AI models: Answers are generated by frontier models served through AWS Bedrock and Azure AI Foundry, hosted in the EU with no transfer outside EU borders, under a zero-retention, zero-training policy
- Permission mirroring: Synced cloud sources keep their original access rules; nothing is widened by connecting them
- You control deletion: Remove documents at any time; deleting a Brain removes its documents and their stored extracts, including deliverables. Brain data is securely deleted within 30 days of deletion or disconnection, and an administrator can request full deletion of all company data
Your Data Never Trains Models
VirtualBrain does not use your documents or queries to train AI models. Your data is used exclusively to provide you with answers.Data Encryption
- In transit: TLS 1.2 / 1.3 encryption for all data transfers
- At rest: AES-256 encryption for stored documents, with column-level encryption on extracted text and encryption keys held in AWS KMS and Azure Key Vault
Data Residency
All customer data is hosted on European Union servers by default:- European Union: Default for all customers, with data centers in Paris and Frankfurt. No data flows outside the EU
- Custom regions: Contact your account manager
Access Controls
Authentication
VirtualBrain supports two ways to sign in:- Email and password sign-in, with multi-factor authentication.
- Single sign-on (SSO) with Google and Microsoft work accounts over OpenID Connect, including Microsoft Entra ID (formerly Azure AD) tenant configuration. When SSO is enabled, you sign in with the work account you already use, with no separate VirtualBrain password to create or rotate, and access follows your firm’s existing identity controls for joiners and leavers.
Permissions Model
Access in VirtualBrain is controlled at two levels:Brain-Level Permissions
Each Brain has its own access controls:- Private: Only you can access (the default)
- Specific users: Grant a named colleague Full access or read-only
- Teams: Share with a whole team at once.
Infrastructure Security
Cloud Infrastructure
VirtualBrain runs on enterprise-grade cloud infrastructure:- Hybrid AWS and Azure architecture, in SOC 2 certified EU data centers
- Multi-AZ architecture with at least 99.95% availability, resilient to the loss of a data center
- Daily backups stored in a separate region
- AWS WAF and AWS Shield for DDoS protection, with a single entry point (one load balancer, TCP/443 only) into a segmented VPC
Application Security
- Annual penetration test by Bastion Technologies
- Quarterly vulnerability scans (Qualys)
- Peer code review on every change
- Secure development lifecycle (SDL)
- Bug bounty program
Audit and Monitoring
Activity Logs
Enterprise plans include comprehensive audit logs, exportable on demand:- User login/logout events
- Document uploads and deletions
- Brain access and modifications
- App runs and query history
Retention
- Standard plans: 90-day activity log retention
- Enterprise: Customizable retention periods
Incident Response
VirtualBrain maintains a documented incident response plan:- Detection: Automated monitoring and alerting
- Containment: Immediate isolation of affected systems
- Notification: Customer notification within 24 hours
- Recovery: Full restoration and root cause analysis
Vendor Security
We vet all third-party vendors for security:- Cloud and AI infrastructure, AWS (Bedrock) and Microsoft Azure (AI Foundry). The enterprise agreements are with AWS and Microsoft, not with the providers whose models run on their platforms
- No data sharing with sub-processors without consent
- Regular vendor security assessments
Security Contact
For security questions, concerns, or to report vulnerabilities:- Email: terence@getvirtualbrain.com, our DPO
- Response time: Within 24 hours
Trust Center
ISO 27001 certificate, SOC 2 Type II report, active controls, and declared subprocessors
Enterprise Security
Discuss custom security requirements