UpBrains AI

Trust & security

Automate quotes and invoices without compromising your data

Distributors route their most sensitive commercial documents through UpBrains AI. Here is how we keep that data protected at every step.

Compliance at a glance

  • EU-U.S. DPF + UK Extension

    Certified under the EU-U.S. Data Privacy Framework and the UK Extension to the EU-U.S. DPF

    dataprivacyframework.gov
  • GDPR alignment

    Privacy program aligned with GDPR requirements

  • SOC 2 controls

    Our security program implements SOC 2 security controls

  • Encryption in transit & at rest

    Customer data is encrypted in transit and at rest

  • Tenant isolation

    Company data is isolated per tenant across storage and processing

Security posture

What protects your documents

1234
  • 1

    Encryption in transit

    TLS protects every connection in and out of UpBrains AI.

  • 2

    Encryption at rest

    Stored data is encrypted with advanced encryption standards.

  • 3

    Tenant isolation

    Your data is scoped to your tenant, never visible to another customer.

  • 4

    Human in the loop

    Approvals and exception queues keep a person in control of consequential decisions.

Encryption in transit and at rest

Data at rest is encrypted using advanced encryption standards, and data in transit is protected with SSL/TLS. Your documents are encrypted from the moment they leave your inbox.

Tenant isolation

Every company operates in its own isolated tenant. Your quotes, POs, invoices, and extracted data are scoped to your account and never visible to another customer.

GDPR alignment

Data Processing Agreements, consent management, data minimization, and secure handling underpin our GDPR posture. The full detail lives in our privacy notice.

SOC 2 controls

Our security program implements SOC 2 security controls.

Data residency

Our servers are located in the United States. Transfers from the EU and UK are protected by European Commission Standard Contractual Clauses. Certified under the EU-U.S. Data Privacy Framework and the UK Extension to the EU-U.S. DPF.

Responsible AI with human review

AI outputs are designed for human-in-the-loop review: extraction confidence, approval steps, and exception queues keep a person in control of every consequential decision. Customer data is never used to train general AI models.

Vulnerability disclosure

Found a security issue? Report it to our security team and we will investigate promptly. We welcome good-faith research on our services.

Privacy practices, data retention, and your rights are documented in the privacy notice; cookie usage is covered in the cookie policy.

Report vulnerabilities to info@upbrains.ai.

Your data, your models

Customer data never trains general AI models

Neither UpBrains AI nor the AI service partners we use as sub-processors use your data to train their general models. If you train custom extractors on your own quotes, POs, or CoAs, the resulting models belong to your account alone.

Read the security and GDPR answers in the FAQ →

See your inbox become an operations hub

See your own quotes, orders, and invoices processed in minutes.

Encryption, tenant isolation, and human review. Trust & security