Current architecture
Cerebrax uses authenticated browser sessions, tenant-scoped organisation records, deny-by-default API routing, and read-scoped MCP agent tokens. Evidence remains associated with the corresponding company record.
Review required
Complete this page with approved information about hosting, encryption, monitoring, incident response, backups, deletion, and compliance before making customer commitments.
Security contact
[Security contact name and email]