ExBrain
Security at Ex.Brain

Security is not a feature we added. It is the foundation we built.

Every brain knows only what it is allowed to know. Every access is checked. Every action is logged.

The default is no

Access is never assumed.

If access has not been explicitly granted, the answer is no. Not for a new hire, not for a contractor, not for an AI Member, not for us. Permissions are granted one by one, and every request is checked at the moment it happens, not once at setup. Checked at the door, and checked again at every room.

Brain-level guardrails

Five things that are always true.

01

Only what it is allowed to know

Every brain sees only the information it has been granted. A department brain cannot read the boardroom, and a contractor cannot see the company. What is not granted does not exist for that brain.

02

Never assumed, always checked

Permissions are evaluated every single time, on every request. Nothing is inherited by accident, and nothing stays open after access is revoked.

03

Everything logged, nothing erasable

Every access and every sensitive action lands in an audit log that cannot be edited or deleted. Not by an admin, not by us. What happened is always provable.

04

Learning with a human in the loop

Brains learn from your company's work, but nothing becomes memory on its own. The brain suggests, a human approves, and only then does it remember. Self-improving, never ungoverned.

05

Built by people who have done this at scale

We do not build our own authentication; identity runs on battle-tested infrastructure with MFA and SSO. And the access architecture was designed by a team that spent two decades securing identity and access at the largest software companies in the world.

One company, three views

Same brain. Three completely different views.

Jordan in marketing asks about a campaign and sees only her twelve marketing memories. Sam in finance sees forty-seven budget records and nothing else. Alex, a new contractor, can see exactly three things out of almost four thousand. Nothing appears until someone grants it.

JordanMarketing
0 of 3,847
SamFinance
0 of 3,847
AlexContractor
0 of 3,847
AI under the same rules

AI Members do not get a free pass.

An AI Member gets access the same way an employee does: granted, scoped, and revocable. You decide what it can see, what it can do, and how much budget it can spend on a task. It cannot grant itself anything. Every action it takes is reported back to a human and lands in the same audit log as everyone else. An AI teammate with a manager, not an agent running loose.

What learning never touches

Your data is not the product.

Brains learn from your company's work for your company alone. What a brain learns from your data stays inside your company and is never used to train models for anyone else. Sources you restrict produce no learning at all. And when a brain works beyond your walls, like an Engagement Brain serving your clients, it carries only the know-how you approved. Your private data stays home.

You hold the keys

In control on day one, and on the last day.

See every grant that exists and revoke any of them instantly, for a person or an AI Member. Export your audit logs whenever you want. And if you ever leave, your data leaves with you: export everything, with a guaranteed window after cancellation. No hostage data, no dead ends.

And the basics, always
Encryption in transit and at restMulti-factor authentication and SSOTenant isolation by designImmediate access revocationBuilt to support enterprise compliance requirements
Straight answers

The questions your security team will ask.

Does Ex.Brain train AI models on our data?

No. What a brain learns from your data serves your company only. It is never used to train models for other customers, and restricted sources produce no learning at all.

Who can see what, by default?

Almost nothing. Access starts closed and is granted permission by permission. A new person or AI Member sees only what someone explicitly gives them.

What happens when someone leaves?

Their access ends immediately, everywhere, including anything an AI Member was doing on their behalf. The work and knowledge they created for the company stays with the company.

Can we audit who accessed what?

Yes. Every access and every sensitive action is recorded in an append-only log that cannot be edited or deleted. You can review it and export it.

What can an AI Member access or spend?

Only what you grant. Its permissions are scoped like an employee's, its budget is a hard limit you set, and every action it takes is reported to a human and logged.

See it protecting a company like yours.

Book a demo and see the brains at work. Every serious evaluation then gets a dedicated security session with our team, where we walk your security people through the full architecture.

Every brain knows only what it is allowed to know.