Security
Trust starts with precise claims.
BraidRoute is early. This page separates the architecture we are building, the controls currently implemented, and independent evidence when it exists.
Current status · reviewed 2026-09-01
Evidence before assurance
- Implemented
- The public operator application is explicitly bounded to synthetic demonstration data.
- In progress
- Organization, project, environment, and tenant authorization boundaries are being designed and tested for early access.
- Planned
- Production secret handling, redaction, classification, and minimum-data controls are not yet published as implemented.
Security contact: Contact channel is being prepared. Do not transmit vulnerability details through the early-access form.
Isolation and access
In progressThe intended model separates organization, project, environment, and tenant scope, uses least-privilege service accounts, and requires recipient-bound authorization for client access. No untested isolation control is claimed here as available.
Data and secrets
PlannedEncryption status, secret boundaries, field redaction, data classification, and minimum-data behavior will be documented against the infrastructure actually operated. Architecture intent is not evidence of an operational control.
Audit and release integrity
In progressThe synthetic demo includes actor-attributed audit events. Planned product controls attach resource versions, release records, and replay choices to executions. Tamper resistance and retention properties are not yet claimed.
Regions, retention, and deletion
PlannedSupported regions, residency, retention windows, backup behavior, and deletion procedures are not yet published. We will not imply residency from a planned architecture.
Incident and reliability evidence
PlannedA maintained public status page, support policy, backup and restore evidence, and incident process are not currently available to link. They will appear here only when operated and maintained.
Compliance
PlannedBraidRoute is not currently claiming SOC 2, ISO 27001, HIPAA, PCI DSS, or any other certification unless a completed, independently verifiable artifact is linked here.
Documents
- Security overview
- In preparation
- Architecture diagram
- In preparation
- Privacy notice, DPA, and subprocessor list
- Unavailable pending approved documents