Security
How we think about security today, what we do not claim, and how to report a concern.
Last updated: 30 September 2026
Current version. This page describes how BrandWater AI works today. It is updated as the service launches, and the date above shows the latest version.
How we approach security
This website is a marketing site with no accounts and no customer data stored in it. It is served with security headers, including a Content Security Policy, HTTPS enforcement and clickjacking protection, and its contact form is validated, rate limited and same-origin only.
Sign in and workspace data are handled by the separate BrandWater app. Its security practices will be documented here as customer data handling launches.
Certifications and attestations
Independent certifications such as SOC 2 or ISO 27001 are on the roadmap. We will list any certification here with its scope and date once it is obtained.
Principles we design to
- Keep each brand's data separate from every other brand's.
- Manage access per person, with the least access needed.
- Keep an evidence trail so that findings and actions can be traced.
- Require approval before any action is taken.
Reporting a vulnerability
If you believe you have found a security issue on this website, email hello@brandwaterai.in with the subject line Security report. Please give us reasonable time to respond before sharing details publicly.