The controls the CFO, the CISO, and the regulator can all sign.
Every product and every engagement runs on the same posture. This page is where we write it down, in plain English, in one place. If you need paperwork for a security review, email security@datacaffe.ai and we'll send it.
Where we are, in three states.
Every claim below is auditable. Self-declarable controls are marked In place. Independent audits currently in flight are In progress with a target quarter. Anything committed but not yet started is Planned.
Data-subject rights + DPA on request
California resident opt-out honored
AES-256, per-tenant keys
TLS 1.3, HSTS enforced
OIDC + SAML 2.0 for admin surfaces
EU · US · India regions available
Audit in progress · report Q4 2026
Gap assessment complete · certification 2027
Available for healthcare tenants on request
Security
ISO/IEC 27001:2022 across the platform and every product deployment. SOC 1 Type II attested for our order-processing and financial-integration flows. Third-party penetration testing on the customer-facing surfaces every year, plus an internal red team that gates every production model on Breww.
- ISO/IEC 27001:2022
- SOC 1 Type II attestation
- Annual third-party pen tests
- SSO / SAML by default
- Encryption in transit and at rest
Privacy
GDPR-aligned data-processing agreements for every deployment. India DPDP Act ready. Regional data residency (India, EU, Singapore, US, Middle East) available on enterprise plans. Right-to-erasure workflows are wired into every product — not a manual ticket.
- GDPR & UK GDPR DPAs
- India DPDP Act aligned
- Regional data residency
- Right-to-erasure workflows
- Sub-processor register published
Compliance & reporting
ESGCaffe ships coverage for BRSR Core, CSRD, GRI, TCFD, and ISSB S1/S2 out of the box — plus a dozen more frameworks on the same underlying data model. For financial-services deployments, model risk is aligned to SR 11-7 and PS 6/23 by default.
- BRSR Core coverage
- CSRD readiness
- GRI, TCFD, ISSB alignment
- SR 11-7 / PS 6/23 model risk
- RBI, MAS, PRA-aligned incident playbooks
Model risk & AI governance
Every production model on Breww ships with an evaluation harness, an incident playbook, human-in-the-loop attestation, and a retirement plan. That last one matters — most vendors leave it out. Every model dies eventually. We plan for that on day one.
- Slice-level evaluations
- Live drift detection
- Human-in-the-loop attestation
- Named model owners
- Retirement plans on file
Security or compliance question?
Reach our security team directly. We answer within one business day — attaching whatever paperwork you need.
