C
OCCEAN
Contact
Trust

Security & AI Transparency

What Commerce Brain™ can do, what it will never do, and the controls that keep your business data safe.

Last updated · March 12, 2026Version · 2.6Reading time · 10 min read

How Commerce Brain™ works

Commerce Brain™ is an executive reasoning engine. It reads signals from your connected commerce, finance, and marketing systems, cross-references them against your Decision Memory (private layer), and produces ranked decisions with evidence and confidence.

Evidence-based
Every recommendation cites the signals behind it.
Confidence scored
0–100 confidence with uncertainty made explicit.
Never autonomous
Financially material actions always require a human.
No invented data
Brain refuses to guess when evidence is insufficient.

What Commerce Brain™ never does

  • It never invents financial numbers, KPIs, or historical facts.
  • It never executes financially material actions without human approval.
  • It never blends your Decision Memory (private layer) with another business's data.
  • It never trains third-party foundation models on your identifiable business data.

Encryption

In transit
TLS 1.3 for every request.
At rest
AES-256 across all datastores.
Keys
Managed KMS, rotated every 90 days.

Compliance & Certifications

SOC 2 Type II
Audit in progress · Q3 2026.
GDPR
Full data subject rights honored.
CCPA
California resident rights supported.

Secure Authentication

  • Password hashing with Argon2id.
  • Optional two-factor authentication (TOTP + WebAuthn).
  • SSO via SAML 2.0 and OIDC on the Enterprise plan.
  • Session revocation on password reset and suspicious login.

Audit Logging

Every privileged action is logged with actor, timestamp, and payload hash. Logs are immutable and retained for 400 days.

Immutable audit log
Tamper-evident append-only ledger.

Role Permissions

Role-based access control ships out of the box with Owner, Admin, Operator, and Viewer roles. Enterprise adds custom roles and scoped API tokens.

RBAC
Least-privilege by default.

Backups

Continuous backups
Point-in-time recovery, 35 days.
Geo-redundant
Replicated across three availability zones.

Disaster Recovery

Documented DR plan with RPO ≤ 15 minutes and RTO ≤ 4 hours. Full DR exercises are executed twice a year.

Incident Response

Our on-call team responds to Sev-1 incidents within 15 minutes. Customers are notified without undue delay of any confirmed incident affecting their data.

24/7 on-call
Global follow-the-sun rotation.

Data Isolation

Decision Memory™

Decision Memory (private layer) is row-scoped and cryptographically isolated per tenant. Decision Memory (anonymous layer) operates only on anonymized aggregates. The two memories can never be mixed.

Contact & Vulnerability Disclosure

Report vulnerabilities responsibly to security@occean.com. We acknowledge receipt within 24 hours and coordinate disclosure with researchers.