Security & Compliance
Enterprise-grade infrastructure, security, and compliance, built into the platform, not bolted on.
CMMI Level 3 · ISO 9001 · ISO 27001 · GDPR · HIPAA
Built on two decades of enterprise security
NeuraFlow is a product of Brain Station 23, a software company that has delivered enterprise-grade systems across banking, telecom, healthcare, and logistics for over 20 years. The security standards, certifications, and data governance practices behind NeuraFlow are the same ones Brain Station 23 has applied to enterprise deployments worldwide.
Certifications
- CMMI Level 3: process maturity and engineering rigour.
- ISO 9001: quality management system certification.
- ISO 27001: information security management certification.
- GDPR compliant: data handling aligned to EU data protection requirements.
- HIPAA-aligned practices: suitable for healthcare deployments.
Data isolation
Every NeuraFlow deployment is isolated at the tenant level. Your data never touches another customer's environment. Cross-tenant data sharing is not possible by design.
No training on your data
Conversations handled by NeuraFlow agents are never used to train or fine-tune any model, whether NeuraFlow's infrastructure or any third-party provider. Your data is yours.
BYOK: Bring Your Own Key
Connect your own LLM API key and pay your chosen provider directly. In BYOK mode, conversation data is sent directly to your provider without passing through NeuraFlow's model layer. You retain full control of your data and your model relationship.
Access control
- Role-Based Access Control (RBAC) with granular permission management at the organisation level.
- Configurable roles for agents, administrators, and reviewers.
- Audit logging of all configuration changes and access events.
Full audit trail
Every decision the agent makes is logged via Visual Execution History: what it understood, what it retrieved, which path it followed, and what it did. Every execution is inspectable and auditable. This is not just a compliance feature. It is what gives your team and your security reviewers full confidence in what the AI did.
Encryption and infrastructure security
- TLS 1.2+ encryption for all data in transit.
- AES-256 encryption for stored credentials and sensitive configuration data.
- Request logging and security event monitoring.
- Infrastructure hosted in SOC 2 compliant cloud environments.
Configurable data retention
Data retention policies are configurable to match your regulatory and compliance requirements. Upon contract termination, data is available for export for an agreed period before deletion.
Deployment options
- Cloud (default): managed by Brain Station 23.
- Hybrid: data residency in your environment, orchestration in the cloud.
- On-premise: full deployment within your infrastructure, available for enterprise clients.
Security review support
We support IT and security teams through their review process. Contact neuraflow@brainstation-23.com to request security documentation, architecture diagrams, or a dedicated security briefing.