Skip to content

Trust Center

Trust starts with explicit boundaries: what data enters the system, who can access it, which actions AI may take, and when a person must step in.

Request documentation

Make important controls visible and understandable.

01

Least-necessary access

02

Human review for sensitive decisions

03

Traceable ownership and activity

Define, restrict, observe, and improve.

  1. 01

    Define

    Document approved knowledge, roles, permissions, and escalation conditions.

  2. 02

    Restrict

    Limit access and AI actions to the work each role and workflow requires.

  3. 03

    Observe

    Keep conversation, action, and ownership context available for review.

  4. 04

    Improve

    Review failures and edge cases, then update the underlying rule or process.

The areas every customer should be able to evaluate.

Data handling

Role-based access

AI action limits

Human escalation

Review connected access

Incident readiness

Review the controls that apply to your intended workflow.

Start with the data and actions your team plans to use. Identify the customer information in scope, who needs access and which integrations are connected. Then review the Spacebrain documents that apply to those modules and that workflow.

For AI-assisted work, confirm which sources are available, which actions the configured workflow may take and where a person reviews or takes over. For connected services, check the account permissions and requirements that apply.

A general product description cannot replace the documentation for your specific setup.

Use the linked Privacy Policy and Terms as a starting point. Email support@spacebrain.ai with the modules and integrations in your review to request the current assessment document or other applicable information.

Data and access
Describe the information entering the workflow and the users who need to work with it.
AI and human decisions
Identify the supported actions, review steps and questions that require a qualified person.
Privacy and security documents
Request the current material that applies to the modules, connections and contractual review you are considering.

CASA AL1

CASA Level 1 security assessment

Spacebrain completed and passed an App Defense Alliance CASA Level 1 security assessment. The summary below shows 20 controls marked Pass across six areas. Request the assessment document.

20 / 20controls marked Pass

Authentication

Authentication — result
IDControlResult
1.1Implement strong password security measuresPass
1.2Disable default accounts on public application access interfacesPass
1.3Out-of-band verifiers must be random and not reusedPass

Session Management

Session Management — result
IDControlResult
2.1URLs must not expose authentication materialPass
2.2Invalidate sessions on logout, user request, and password changePass
2.3Implement and secure application session tokensPass
2.4Protect sensitive account modificationsPass

Access Control

Access Control — result
IDControlResult
3.1Implement access controls to protect data and APIsPass
3.2Secure OAuth integrations to protect user data and prevent unauthorized accessPass
3.3Exposed administrative interfaces must use appropriate multi-factor authenticationPass

Communications

Communications — result
IDControlResult
4.1Protect data through strong cryptographyPass

Data Validation and Sanitization

Data Validation and Sanitization — result
IDControlResult
5.1Validate and sanitize inputPass
5.2Handle untrusted files securelyPass

Configuration

Configuration — result
IDControlResult
6.1Keep all components up to datePass
6.2Disable debug modes in production environmentsPass
6.3Do not use the Origin header to make authentication or access-control decisionsPass
6.4Protect the application against subdomain takeoverPass
6.5Do not log credentials or payment detailsPass
6.6Clear client-side storage securely on logoutPass
6.7Store server-side secrets securelyPass

Trust center questions

Clear answers about Spacebrain, setup, and what to expect.

Does Spacebrain replace professional judgment?

No. Sensitive medical, legal, financial, employment, and other professional decisions require qualified human review.

Can AI actions be limited?

Yes. Workflows should define permitted actions, required information, and conditions that trigger a handoff.

Where can customers request security information?

Contact support@spacebrain.ai with your security, privacy, or procurement questions.

Where can I find privacy information?

Read our Privacy Policy for details about how Spacebrain handles information. Contact support@spacebrain.ai with security or procurement questions.