Trust

The standards we operate under.

Brayns operates under the standards that regulators and vendor due diligence expect. This page sets out what each standard is and what it means for you as a customer.

GDPR

Compliant

WHAT IT IS

The General Data Protection Regulation is the European Union's law on the processing of personal data. It sets out the grounds on which personal data may be processed at all, the rights people hold over their own data, and the duties that fall on whoever decides how and why it is processed.

WHAT IT COVERS

Lawful basis and purpose limitation, the rights of the person whose data it is, the security of processing, and the conditions under which personal data may move outside the EU and EEA.

WHAT IT MEANS FOR YOU

Brayns is GDPR compliant, and personal data is handled under EU law, by design and by default. The roles matter here. For customer data in the platform, Brayns acts as processor and processes personal data only on documented instructions under a data processing agreement. For the personal data Brayns holds as controller, such as when you contact us or apply for a role, the legal bases under the GDPR are performance of a contract, our legitimate interests in operating and developing Brayns, your consent where we ask for it, and our legal obligations. We keep that processing in the EU and EEA wherever possible, and where a transfer outside it is unavoidable we rely on adequacy decisions or the European Commission's standard contractual clauses together with appropriate safeguards.

SOC 2 Type II

Independently audited

WHAT IT IS

SOC 2 is a reporting standard for service organisations, covering the controls a provider operates over security and the commitments that go with it. A Type II report differs from a Type I in what it examines. It does not ask whether controls were designed correctly on a single day, but whether they actually operated across a period of time.

WHAT IT COVERS

The design of a service organisation's controls, and the evidence that those controls ran as described, examined by an independent auditor.

WHAT IT MEANS FOR YOU

Our controls are independently audited and have been shown to operate over time. That is the part of a Type II report which carries weight in vendor due diligence, because it describes what happened rather than what was intended.

ISO 27001:2022

Certified

WHAT IT IS

ISO 27001 is the international standard for an information security management system. It describes how an organisation identifies the risks to the information it holds, decides which controls to apply to them, and keeps that judgement under review as the organisation and the threats against it change.

WHAT IT COVERS

Governance of information security, risk assessment and risk treatment, the selection and operation of controls, and the internal review that keeps the system current.

WHAT IT MEANS FOR YOU

Brayns holds certified information security management under ISO 27001:2022. Certification means security is run as a managed system with defined ownership and review, rather than as a set of practices that happen to be in place. We support your own audits as agreed.

ISO 27701:2019

Certified

WHAT IT IS

ISO 27701 extends an information security management system into a privacy information management system. It takes the structure of ISO 27001 and adds the duties that apply specifically to personal data, for organisations acting as a controller, as a processor, or as both.

WHAT IT COVERS

Privacy governance layered onto information security: how personal data is identified and handled, the separate responsibilities of controllers and processors, and the evidence that those responsibilities are being met.

WHAT IT MEANS FOR YOU

Brayns holds certified privacy information management under ISO 27701:2019. Because the standard extends ISO 27001 rather than standing apart from it, privacy is managed through the same system as security. Our technical and organisational measures are aligned with the standards listed on this page.

ISO/IEC 42001:2023

Certified

WHAT IT IS

ISO/IEC 42001 is the international standard for AI management systems. It applies the management-system structure familiar from information security to the particular questions that building and operating artificial intelligence raises.

WHAT IT COVERS

How an organisation governs the artificial intelligence it builds and runs: the policies behind it, the risks weighed, the roles accountable for decisions, and the review that keeps all of it current.

WHAT IT MEANS FOR YOU

Our AI management system is certified under ISO/IEC 42001:2023, the international standard most closely aligned with the EU AI Act's management-system expectations, alongside our information-security and privacy certifications.

EU AI Act

Built to meet the Act's requirements as they phase in

WHAT IT IS

The EU AI Act is the European Union's law on artificial intelligence. It sorts systems by the risk they present and attaches duties to each class, and its obligations phase in over a period rather than arriving at once.

WHAT IT COVERS

Risk management, technical documentation and record keeping, transparency towards the people a system affects, human oversight of that system, and governance of the data it is built on.

WHAT IT MEANS FOR YOU

Brayns treats the EU AI Act as a design requirement rather than a future problem, and the platform is built to meet the Act's requirements as they phase in. It is developed under a documented risk-management process covering model behaviour, data handling and operational failure modes. Model versions are named, dated and explained, and decisions carry reasoning that can be examined. Uncertain cases escalate to your people, and every action is on the record. Customer data is not used to train models, and deployments run inside your own perimeter.