Trust Center
Trust starts with explicit boundaries: what data enters the system, who can access it, which actions AI may take, and when a person must step in.
Request documentationMake important controls visible and understandable.
Human review for sensitive decisions
Traceable ownership and activity
Define, restrict, observe, and improve.
- 01
Define
Document approved knowledge, roles, permissions, and escalation conditions.
- 02
Restrict
Limit access and AI actions to the work each role and workflow requires.
- 03
Observe
Keep conversation, action, and ownership context available for review.
- 04
Improve
Review failures and edge cases, then update the underlying rule or process.
The areas every customer should be able to evaluate.
Data handling
Role-based access
AI action limits
Human escalation
Review connected access
Incident readiness
Review the controls that apply to your intended workflow.
Start with the data and actions your team plans to use. Identify the customer information in scope, who needs access and which integrations are connected. Then review the Spacebrain documents that apply to those modules and that workflow.
For AI-assisted work, confirm which sources are available, which actions the configured workflow may take and where a person reviews or takes over. For connected services, check the account permissions and requirements that apply.
A general product description cannot replace the documentation for your specific setup.
Use the linked Privacy Policy and Terms as a starting point. Email support@spacebrain.ai with the modules and integrations in your review to request the current assessment document or other applicable information.
- Data and access
- Describe the information entering the workflow and the users who need to work with it.
- AI and human decisions
- Identify the supported actions, review steps and questions that require a qualified person.
- Privacy and security documents
- Request the current material that applies to the modules, connections and contractual review you are considering.
CASA AL1
CASA Level 1 security assessment
Spacebrain completed and passed an App Defense Alliance CASA Level 1 security assessment. The summary below shows 20 controls marked Pass across six areas. Request the assessment document.
20 / 20controls marked Pass
Authentication
| ID | Control | Result |
|---|---|---|
| 1.1 | Implement strong password security measures | Pass |
| 1.2 | Disable default accounts on public application access interfaces | Pass |
| 1.3 | Out-of-band verifiers must be random and not reused | Pass |
Session Management
| ID | Control | Result |
|---|---|---|
| 2.1 | URLs must not expose authentication material | Pass |
| 2.2 | Invalidate sessions on logout, user request, and password change | Pass |
| 2.3 | Implement and secure application session tokens | Pass |
| 2.4 | Protect sensitive account modifications | Pass |
Access Control
| ID | Control | Result |
|---|---|---|
| 3.1 | Implement access controls to protect data and APIs | Pass |
| 3.2 | Secure OAuth integrations to protect user data and prevent unauthorized access | Pass |
| 3.3 | Exposed administrative interfaces must use appropriate multi-factor authentication | Pass |
Communications
| ID | Control | Result |
|---|---|---|
| 4.1 | Protect data through strong cryptography | Pass |
Data Validation and Sanitization
| ID | Control | Result |
|---|---|---|
| 5.1 | Validate and sanitize input | Pass |
| 5.2 | Handle untrusted files securely | Pass |
Configuration
| ID | Control | Result |
|---|---|---|
| 6.1 | Keep all components up to date | Pass |
| 6.2 | Disable debug modes in production environments | Pass |
| 6.3 | Do not use the Origin header to make authentication or access-control decisions | Pass |
| 6.4 | Protect the application against subdomain takeover | Pass |
| 6.5 | Do not log credentials or payment details | Pass |
| 6.6 | Clear client-side storage securely on logout | Pass |
| 6.7 | Store server-side secrets securely | Pass |
Trust center questions
Clear answers about Spacebrain, setup, and what to expect.
Does Spacebrain replace professional judgment?
No. Sensitive medical, legal, financial, employment, and other professional decisions require qualified human review.
Can AI actions be limited?
Yes. Workflows should define permitted actions, required information, and conditions that trigger a handoff.
Where can customers request security information?
Contact support@spacebrain.ai with your security, privacy, or procurement questions.
Where can I find privacy information?
Read our Privacy Policy for details about how Spacebrain handles information. Contact support@spacebrain.ai with security or procurement questions.