Skip to content
DataCaffe.ai
Trust & Security

The controls the CFO, the CISO, and the regulator can all sign.

Every product and every engagement runs on the same posture. This page is where we write it down, in plain English, in one place. If you need paperwork for a security review, email security@datacaffe.ai and we'll send it.

Compliance snapshotLive posture

Where we are, in three states.

Every claim below is auditable. Self-declarable controls are marked In place. Independent audits currently in flight are In progress with a target quarter. Anything committed but not yet started is Planned.

GDPRIn place

Data-subject rights + DPA on request

CCPAIn place

California resident opt-out honored

Encryption at restIn place

AES-256, per-tenant keys

Encryption in transitIn place

TLS 1.3, HSTS enforced

SSO / SAMLIn place

OIDC + SAML 2.0 for admin surfaces

Data residencyIn place

EU · US · India regions available

SOC 2 Type IIIn progress

Audit in progress · report Q4 2026

ISO 27001In progress

Gap assessment complete · certification 2027

HIPAA BAAPlanned

Available for healthcare tenants on request

Security

ISO/IEC 27001:2022 across the platform and every product deployment. SOC 1 Type II attested for our order-processing and financial-integration flows. Third-party penetration testing on the customer-facing surfaces every year, plus an internal red team that gates every production model on Breww.

  • ISO/IEC 27001:2022
  • SOC 1 Type II attestation
  • Annual third-party pen tests
  • SSO / SAML by default
  • Encryption in transit and at rest

Privacy

GDPR-aligned data-processing agreements for every deployment. India DPDP Act ready. Regional data residency (India, EU, Singapore, US, Middle East) available on enterprise plans. Right-to-erasure workflows are wired into every product — not a manual ticket.

  • GDPR & UK GDPR DPAs
  • India DPDP Act aligned
  • Regional data residency
  • Right-to-erasure workflows
  • Sub-processor register published

Compliance & reporting

ESGCaffe ships coverage for BRSR Core, CSRD, GRI, TCFD, and ISSB S1/S2 out of the box — plus a dozen more frameworks on the same underlying data model. For financial-services deployments, model risk is aligned to SR 11-7 and PS 6/23 by default.

  • BRSR Core coverage
  • CSRD readiness
  • GRI, TCFD, ISSB alignment
  • SR 11-7 / PS 6/23 model risk
  • RBI, MAS, PRA-aligned incident playbooks

Model risk & AI governance

Every production model on Breww ships with an evaluation harness, an incident playbook, human-in-the-loop attestation, and a retirement plan. That last one matters — most vendors leave it out. Every model dies eventually. We plan for that on day one.

  • Slice-level evaluations
  • Live drift detection
  • Human-in-the-loop attestation
  • Named model owners
  • Retirement plans on file
Security

Security or compliance question?

Reach our security team directly. We answer within one business day — attaching whatever paperwork you need.