Security
Built as if the record were hostile.
Cerebrax holds the messages your company decided things in, and hands them to models. Both of those facts shaped how it is built.
Tenancy and access
- Tenant-partitioned records
- Evidence and records are stored per organisation. Queries resolve against one tenant; nothing crosses between them.
- Google OAuth with PKCE
- Sign-in runs through Google with a PKCE challenge and a secure, host-scoped state cookie.
- Deny-by-default API routing
- Routes require an authenticated principal and an explicit tenant match before they return anything.
- Private responses
- Account and record endpoints are served no-store, so tenant data is not cached by intermediaries.
Agent access
- Read-only tool surface
- The MCP endpoint exposes four read tools. There is no write path, so no agent can move a claim into your record.
- Scoped, revocable tokens
- Each agent gets its own cbrain-agent token bound to a single tenant. Revoking one agent leaves the others working.
- Untrusted content marking
- Every result carries content_trust: untrusted-ledger-content. Your team’s words are data for a model to reason over, never instructions to follow.
- Per-call audit log
- Transport, request id, and calling agent are recorded for each call, so you can answer what an agent read and when.
Record integrity
- Source-quote gate
- A claim without a supporting message is not recorded. It waits in review instead of becoming something the company believes.
- Superseded, not overwritten
- Decisions are replaced by new versions rather than edited in place, so history stays replayable.
- Visible failure
- Failed imports and unparsed evidence surface as dead letters. Gaps in coverage are shown, not smoothed over.
What we do not claim yet.
A security page that only lists strengths is not worth reading. Here is where we actually are.
- We hold no SOC 2, ISO 27001, or equivalent certification.
- We have not completed an independent penetration test.
- Hosting, encryption, backup, retention and incident-response specifics are not yet published in a form we would put in a contract.
- Slack, Telegram and Google Drive connectors are in development and are not carrying customer data.
If any of these blocks a decision for you, say so and we will give you our timeline rather than a comfortable answer.
Reporting a vulnerability.
Mail security@cerebrax.io with steps to reproduce. We will acknowledge it, keep you posted while we fix it, and credit you if you want the credit.