SECURITY
Your knowledge, governed.
A Company Brain concentrates what your organization knows. Its access model is the product, not a setting. This page states, in plain terms, how content is hosted, who can see what, how every change is accountable, and what LAN never does. Everything here is literally true of the platform we run today.
ACCESS
Everyone reads through their own eyes.
Your AI connects through each person’s own authenticated session. It sees exactly what that person is allowed to see, never more. There is no shared service account that quietly sees everything.
Session-scoped reads.
Every query, every graph walk, every listing is filtered to the caller before it returns. A page you cannot see never surfaces, not even as a snippet.
Three levels, one rule.
Every page is standard, confidential, or private. Confidential content is scoped to named audiences (Finance, Legal) that map to specific people. The same rule holds across search, reading, and graph traversal, not screen by screen.
Delegated, not centralized.
A policy line can restrict a whole folder or type at once (all Finance decisions, confidential to Finance) without tagging pages one by one. Department leads can govern their own area without being a full brain admin. Org structure stays visible like an org chart; the content inside is what gets governed.
HOSTING
Where your brain lives.
- Each company's brain lives in its own dedicated, isolated storage, hosted on LAN's own infrastructure. No third-party document store.
- If someone belongs to more than one company brain, real membership is re-verified before any request reaches another tenant’s data. A stale or mismatched credential is refused, not honored.
- The brain is an index, not a data lake. The value is in dense, cited summaries; your source files stay in the systems that own them and are opened on demand, not bulk-copied.
- Source documents you choose to retain are kept with a 10 GB included quota, each traceable to exactly which pages were derived from it.
- Data is encrypted in transit (TLS) and at rest, with role-based access control and audit logs.
ACCOUNTABILITY
Every change leaves a trace.
Audit trail.
Every action against your brain, by a person or an AI, is logged: who, when, what was touched, and denials as well as successes. Your own admins can query your company’s trail; events are retained 400 days.
Append-only history.
Changes are recorded in an ordered, append-only log. Nothing is silently overwritten or made to disappear without a trace.
Exact revert.
A bad write can be reverted to the exact bytes that were there before, verified, not an approximation.
Daily backups.
The whole brain is snapshotted every day, older copies retained for weeks, and any destructive operation takes a safety snapshot first. The audit trail is additionally backed up off-platform, daily, to Amazon Web Services storage in the United States, under the same 400-day window.
HOW WE BUILD IT
Security work never ships on a green test suite.
A passing test suite proves the cases we thought of. For anything that touches who can see what, that is not enough. Every access-control change goes through an adversarial review before it reaches you: several independent reviewers, each hunting a different class of failure, against the real merged code, not a mock.
The malicious insider
a member who tries to reach what their role should not.
The forged or missing credential
a stale, null, or cross-tenant token that should be refused.
Stale data
a cached or out-of-date view that could show more than it should now.
The spec mismatch
behavior that drifts from what the access model promises.
This has caught real issues before they reached customers, every time we have run it. We would rather find them ourselves.
COMMITMENTS
What we never do.
- Train models on your content. Your brain serves your AI clients and nothing else.
- Hold your AI provider tokens. You bring your own clients and your own keys.
- Sell, share, or mine your data.
WHAT WE RUN
What we run today.
Across our own stack, in production right now:
- Encryption in transit and at rest
- Role-based access control
- Full audit trail
- Daily backups
- Adversarial review of every access change
- Incident notice within 48 hours
PAPERWORK
The practical parts.
- The individual NDA is signed after the commercial proposal.
- A data processing agreement is available on request, with the full sub-processor list, the retention windows, and the international transfer clauses.
- Security questions go to info@lanbrain.ai.
LAN Ventures E.A.S. · RUC 80141770-8 · Asunción, Paraguay.