Trust
What happens to your data
Brain holds your numbers, your decisions, and your plans. You should know where that sits, who can reach it, and how you get it back. Four answers, stated plainly.
Four facts, not four intentions
Each one describes how your installation is already built. Nothing below is a roadmap item.
-
Your data stays in the EU
Your Brain runs in the European Union, in the AWS Europe region in Ireland. The database, your uploaded files, and the search index all sit in that one deployment.
If your business needs a different arrangement, we tell you what is possible before you sign.
-
Your data is never used to train models
Nothing in your Brain trains a model. Not one of ours, and not a model provider's. We reach the models through their business APIs. Their terms exclude API traffic from training. We run no training of our own on customer content.
A model sees the question in front of it and the context needed to answer it. That working set produces the answer and nothing else.
-
You can take everything out, in open formats
Every record comes out as JSON. Documents keep their Markdown text, readable in any editor. Uploaded files come back exactly as you gave them to us. There is no proprietary container. You need no tool of ours to read the result.
We have taken full exports of live deployments. This is a path we use, not a feature we assume works. Timing and handover belong in your contract, where they can be held to, not in a promise on a web page.
-
Every customer has a separate deployment
Your Brain is its own installation: its own database, its own backend, its own address. There is no shared table with a customer column, because there is no shared table. One company's data cannot surface in another company's answer. The query has nowhere else to look.
Access is granted per deployment as well. Removing someone from your Brain is a change inside your installation and touches no one else's.
How it is built
The discipline is not new to us. Two decades of production systems and recognized cloud-engineering credentials sit behind these habits. They run through everything Elexive ships.
Tests and review gates on every change
Nothing reaches a customer installation on someone's word alone. Every change passes an automated gate before it can ship: code checks, type checks, the full test suite, and a dependency audit. A deployment that would leave functions missing is blocked before it happens.
Secrets are managed, not remembered
Every installation's keys and secrets live in a managed parameter store on AWS, per customer. That store is the durable source of truth. The keys are not in anyone's head, not in a spreadsheet, and not shared between installations.
Automation runs on a leash
Automation writes into a Brain as a named service account, with less authority than an administrator. It cannot delete data or manage users. Every write is attributed in the audit log. Revoking it is one switch.
Your security review, answered by the people who built it
We walk your security team through exactly what runs where and sit through their review ourselves. The answers come from the people who built the system, not from a certificate. If your process needs one, tell us early and we tell you where that stands.
Not a weekend build
A tool your team vibe-coded in a weekend can be a fine experiment. Its security posture is unknown, and no one is answerable for it. Working with us, you know exactly where your data lives, what touches it, and whose phone to call.
Bring us your first problem
If the answer you need is not on this page, ask us directly. We would rather answer a hard question about your data before you buy than after.