Every brand in its own perimeter.
A brand’s judgement is the most valuable thing it will put into this platform. This page describes how it is kept, who can reach it, and what we never do with it. We would rather say what we do not have yet than claim what we cannot prove.
Tenant isolation: one brain per brand, no leakage.
Each brand runs in its own tenant, with its own context, its own assets and its own judgement. What one brand teaches never reaches another — not another client’s brand, and not another brand inside the same group.
For groups with several banners, this is architecture rather than configuration: each insignia keeps its identity, its rules and its learning distinct.
To be verified
Describe the real mechanism: RLS per tenant, index separation, key scope.
Not for launch — paginas-internas.md
Your data does not train anyone else’s model.
Client data is never used to train third-party models. What your team declares, approves and refuses stays inside your tenant and serves your brain only.
- Operator access requires a declared session
- With a stated reason and an expiry, rather than standing credentials.
- The provider chain is verified
- The subprocessor map is available under the compliance dossier.
To be verified
Verify each of the three claims against the current architecture.
Not for launch — paginas-internas.md
Every generated piece carries its origin.
An audit trail per piece is what turns compliance from a claim into a record. Each generated piece stores what produced it, under which brand version, with which rule applied, and who approved or refused it — with the reason in writing.
Six months later, any piece can answer three questions: where did this come from, what allowed it, and who decided. That is what makes an audit exportable rather than reconstructed.
GDPR, LGPD and the EU AI Act.
Compliance here is functionality, not a badge: a versioned policy registry, lineage per asset, a written justification for every approval, exportable audit and regional configuration.
- Data protection
- Data processing agreement, purpose and instructions, subprocessors, security, retention and deletion, data subject rights, international transfers, and support for a DPIA where the risk requires it.
- EU AI Act
- The Article 50 transparency rules have applied since 2 August 2026. The platform supports machine-readable marking of synthetic content and keeps provenance for every generated piece.
To be verified
Machine-readable marking and C2PA: confirm whether it exists today, or mark it as roadmap with a date.
Not for launch — paginas-internas.md
Who owns the generated content.
You own what your brand puts in, and you own what comes out. The assets you upload, the rules you declare and the judgement your team builds are yours.
Exportability is a right, not a favour. If you leave, your brand context and your assets go with you.
To be verified
Align with the terms of use and with counsel. IP indemnity clause: confirm whether it exists.
Not for launch — paginas-internas.md
What we do not have yet.
We are not ISO 27001 or SOC 2 certified today, and we are saying so here rather than leaving the question open.
What exists today is the architecture described on this page and the compliance dossier, available under NDA for procurement review. The certification roadmap is shared on request.
Security contact.
For vulnerability reports, security questionnaires or the compliance dossier:
security@br4ndcode.com
To be verified
Address to be confirmed — there is no mailbox of our own yet (spec.md §13, pending item 6). Printed as text, never as a live link.
Not for launch — paginas-internas.md
More on the brand intelligence running behind it, and on who builds BR4NDCODE.