Bralak AI

Security

Security practices designed to support enterprise and compliance requirements.

Bralak holds no security certification and does not claim one. What follows is how systems are built, and every item is something you can ask us to demonstrate on a call.

Practice

Data handling

Where your data goes is decided before any of it moves, and written down rather than assumed.

  • Data flow mapped and agreed in writing before implementation begins
  • Encryption in transit and at rest across every service in the path
  • Minimum necessary data: only the passages or fields required to complete the task
  • Retention periods set per data category and configured, not left to default
  • Where a hosted model provider is unacceptable, open models are deployed in your environment

Practice

Access and authorisation

Permission is applied at retrieval, not at the answer — so a system cannot leak through a summary what a user could not open directly.

  • Retrieval filtered by the asker’s existing entitlements
  • Least-privilege service accounts, scoped per integration
  • Role-based access with 2FA on every administrative surface
  • Environment separation between development, preview and production
  • Secrets in environment variables only — no API key ever reaches browser code
  • Credential rotation, with the access scope agreed in writing beforehand

Practice

AI guardrails

These are structural rather than configurable. A control that can be switched off under delivery pressure is not a control, so the ones that matter are properties of the design instead of settings in it.

  • Actions classified by reversibility; irreversible actions require human confirmation by default
  • Each tool validates its own inputs, and an agent is only given the tools it needs
  • Prompt-injection defences, tested against a fixed adversarial suite
  • Output constraints and validation before anything reaches a system of record
  • Retrieval below a confidence threshold returns a refusal, never a generated guess
  • Model choice sits behind an abstraction, so a provider can be replaced without redesign

Practice

Auditability and observability

Behaviour is inspected after the fact rather than inferred, which is the difference between a system you can operate and one you have to trust.

  • Every run traced with its inputs, decisions, tool calls and outputs
  • Distributed tracing across agent handoffs, so a wrong outcome is attributable to a step
  • Full audit trail on any action that writes to a system of record
  • Error monitoring with alerting on failure-rate thresholds
  • Evaluation suites wired into CI, so a regression blocks a release rather than being found in production

Practice

Engineering practice

The unglamorous work that decides whether a system survives contact with volume.

  • Server-side validation on every input, without exception
  • Rate limiting on every public surface
  • Idempotency, retry with backoff and dead-letter handling on every integration
  • Dependency scanning with automated alerts
  • Code review and CI gates before anything reaches production
  • Architecture and data-flow review with your security team, before implementation rather than after

Your Next Intelligent System Starts Here.

Tell us what you’re trying to improve, automate or build. We’ll help you identify the right AI strategy and engineering path.