Security & platform engineering
Software built
to a security
standard.
Braineetech is a software company. We build web platforms, browser extensions, and mobile apps — most of it security and platform infrastructure, all of it engineered the same way.
- 8,000+
- Detection templates
- 200+
- Secret patterns
- 20+
- Compliance frameworks
Representative interface — not live customer data.
§01 Approach
We build the
controls, not the
paperwork.
Braineetech develops specialised software for organisations where a security failure is a business-ending event — regulated industries, critical infrastructure, and platforms holding data they cannot afford to lose.
We are a software company, not only a security vendor. Alongside that work we build in other categories — business operations, social — and we ship whatever form the problem needs: web platforms, browser extensions, mobile apps.
What stays constant is how they are built. Least privilege by default, auditable changes, and no shortcuts on data handling, whether the user is a security team or someone opening a browser tab.
Each product solves one problem completely rather than several partially. They share an identity model, an evidence format, and a deployment story, so a team can adopt one and add the rest without a migration.
Security is a product decision, not a review gate.
Controls belong in the platform where engineers already work — not in a checklist appended after the architecture is frozen.
Machine identities outnumber human ones.
Service accounts, API keys, and AI agents now hold the majority of production privilege. We govern them on the same control plane as employees.
Evidence beats assertion.
Every finding maps to an asset, a framework control, and a remediation path. Posture claims that cannot be exported are not posture.
§02 Product index
MagicHub
Application Platform
Sectora
Application Security
CompliOne
Governance & Compliance
VeraID
Identity Security
CloudVera
AI & Cloud Operations
Kordox
Business Operations
Soltik
Social Platform
§02.01 MagicHub
MagicHub
Your product’s identity layer, defined visually and pinned to a region.
MagicHub is an identity and user-data platform for product teams. Each project gets its own authentication surface — magic links, passkeys, and password sign-in with the policies you set — plus a visual schema builder for the user profile behind it. Schema changes move through draft, review, and publish with breaking-change detection instead of hand-written migrations, and every project is pinned at creation to an EU, US, or AP data plane it never leaves.
Per-Project Authentication
Magic links, WebAuthn passkeys, and password sign-in, each enabled per project, with password policy, session lifetime, concurrent-session caps, failed-attempt lockout, and API keys and HMAC signing secrets scoped the same way.
Visual Profile Schema Builder
Thirty field types — from text and reference to signature, location, and rich text — arranged on a canvas with live preview, field groups, import/export, and a permission simulator showing what each role can read and write.
Environment Publishing
Promote schemas through development, staging, and production with version history, environment diffs, breaking-change warnings, and rollback — plus AI-assisted field suggestions when starting from scratch.
Regional Data Planes
Project data, logs, activity, and file storage live in the EU, US, or AP region chosen at creation and cannot be moved, with usage metered per monthly active user and an add-on catalogue for extended logs, storage, and AI features.
§02.02 Sectora
Sectora
Find the vulnerability before the adversary files the report.
Sectora covers the whole application lifecycle rather than a single scanner. Static, dependency, and dynamic analysis run against the same asset inventory as secrets scanning, attack-surface discovery, and supply-chain checks, and findings are correlated against a vulnerability index built from NVD, GHSA, OSV, KEV, and EPSS. What the scans learn then feeds enforcement — an edge WAF, a CI/CD gate, and a managed browser agent — and exports as framework-mapped evidence into SIEM and ticketing.
Code to Runtime Testing
SAST with AI-assisted triage, dependency and licence analysis, DAST across web, REST, GraphQL, and gRPC backed by 8,000+ detection templates, and an autonomous pentest agent that runs scoped engagements and files redacted evidence.
Supply Chain & Secrets
Malicious release detection, slopsquat and typosquat analysis, and SBOM matching, alongside 219 secret patterns scanned over git history and container layers with live credential verification and per-provider rotation playbooks.
Shield & Browser Agent
An edge WAF whose rules are informed by your own DAST results, with exception rules, false-positive learning, and geo policy — plus a managed browser extension that scores installed extensions, blocks phishing and lookalike domains, and detects credential and session theft.
AI & Vibe Code Risk
Shadow-AI and MCP discovery, LLM security testing, and a composite A–F repository grade that estimates how much of a codebase is AI-generated and weighs it against vulnerabilities, dependency health, hallucinated packages, and licence violations.
§02.03 CompliOne
CompliOne
Compliance as a continuous control, not an annual scramble.
CompliOne runs the whole governance function, not one regulation. A shared control library maps across GDPR, CCPA/CPRA, LGPD, PIPEDA, POPIA, Israel’s Amendment 13, ISO 27001, 27701, 42001, 22301 and 9001, SOC 2, HIPAA, DORA, NIS2, TISAX, PCI DSS, NIST CSF, and GxP, so one piece of evidence satisfies every framework it touches. Around it sit risk, vendor, audit, asset, workforce, incident, and privacy operations — and an agency mode for firms running all of it on behalf of clients, with white-labelled portals, vCISO workplans, board reports, and a retrieval-backed GRC agent that answers from your own evidence base.
Controls, Policy & Audit
One control library with cross-framework mappings and a Statement of Applicability, policy templates carrying approval, review, and acknowledgement workflows, and internal audit programmes with findings, root-cause analysis, and CAPA.
Risk & Third Party
Enterprise risk register with bow-tie analysis, treatments, key risk indicators, and configurable methodology — alongside vendor questionnaires, DPAs, subprocessor registers, and attack-surface monitoring served through a supplier portal.
Privacy & Consent Operations
Cookie and tracker scanning behind a lightweight embeddable widget with geo-targeted consent rules, data subject and access requests with identity verification, plus RoPA, DPIA, data flows, retention and deletion schedules, and transfer safeguards on EU or US data planes.
Security & Workforce
Vulnerability management with SLAs, threat intelligence matched to your tech stack, incident response with playbooks and evidence, business continuity testing, change management, access reviews, asset and BYOD registers, and policy and awareness campaigns with quizzes.
§02.04 VeraID
VeraID
The control plane for every identity — human and machine.
VeraID issues identity and governs it. It runs as a standards-compliant provider — OpenID Connect, SAML, SCIM, passkeys, MFA, and conditional access, with an app portal and an access gateway — while discovering the service accounts, API keys, and AI agents no directory owns. Both halves share one policy engine, one audit trail, and one risk score, and export to Splunk, Slack, Teams, PagerDuty, and Jira.
Identity Provider
OpenID Connect and SAML with dynamic client registration, device authorisation, and pushed authorisation requests; inbound and outbound SCIM provisioning; passkeys and MFA; and conditional access policies evaluated per session with a logged decision for every one.
Non-Human Identity Discovery
Scans AWS, GCP, and Azure for service accounts, roles, and keys, correlates them to the employees who own them through Okta, Entra ID, and Google Workspace, and tracks credential health, rotation schedules, and emergency revocation.
Access Governance
Just-in-time access with approval and auto-approval policies, attestation campaigns for periodic review, privilege and blast-radius analysis, behavioural baselines with anomaly alerts, and offboarding that follows an identity to every system it touched.
AI Agent Governance
Registers agents, their instances, sessions, and individual actions; enforces per-agent policy with human approval gates; discovers shadow agents and MCP servers; monitors AI platform usage against budget; and flags prompt injection against a behavioural baseline.
§02.05 CloudVera
CloudVera
Run AI in production with the gateway, the guardrails, and the trace in one place.
CloudVera is the operations plane for AI and serverless workloads. A gateway fronts eleven model providers with virtual keys, budgets, routing, and cost controls; guardrails inspect every prompt and completion; and traces, replays, and live tail follow requests across Cloudflare Workers, Vercel, and AWS Lambda. Its prompt-injection detector is a fine-tuned classifier trained in house, not a third-party API call.
AI Gateway
One endpoint across OpenAI, Anthropic, Google, Mistral, DeepSeek, Groq, Cohere, xAI, Perplexity, Together, and Workers AI, with virtual keys, per-tenant budgets and rate limits, model routing and fallback, A/B testing, quality scoring, and cost optimisation.
Guardrails & Red Team
Prompt-injection and jailbreak detection from an ensemble led by a fine-tuned in-house classifier, plus PII redaction, output filtering, a violation queue, red-team exercises, and shadow-AI discovery for the models teams adopted without asking.
Agent Governance
JavaScript and Python agent SDKs with project scaffolding, an agent debugger and browser, approval queues for privileged actions, per-agent audit trails, and security review for MCP servers.
Serverless Observability
Distributed tracing, live tail, and request replay with full KV, R2, and D1 context across Cloudflare, Vercel, and Lambda; cold-start and waste analysis; deploy risk scoring with canary, rollback, and traffic mirroring; and incident correlation with playbooks and a war room.
§02.06 Kordox
Kordox
One workspace for every venture you run.
Kordox is one operations workspace for people running several ventures at once. Tasks, deals, leads, documents, tickets, and email live in a single system that adapts per project through user-defined objects and schemas rather than hardcoded modules — and it carries the client-facing half too: portals, booking pages, invoices, and signature requests, on your own sending domains.
Work, Pipeline & Leads
Tasks with dependencies, watchers, reminders, time entries, and custom statuses; kanban deal management with an account view and workload across teams; and a lead engine with embeddable forms, source tracking, scoring, dedup, and routing rules.
Client-Facing Operations
A token-authenticated client portal, public booking pages with calendar sync, invoices with online payment, e-signature and document requests, and a shared inbox and ticket queue over connected Gmail and Outlook accounts.
Builder Studio & Automations
Define custom objects, field schemas, and saved views per project without migrations, then wire trigger, condition, and action rules over them with full execution history.
Connected Money & Agents
Fifteen first-party agents — invoice chaser, churn detector, margin watcher, deal forecaster, and cloud, ad, and AI spend sentinels among them — running over data pulled from Stripe, Shopify, Square, PayPal, Plaid, AWS, GCP, Cloudflare, Google and Meta Ads, HubSpot, Salesforce, and your own OpenAI and Anthropic usage.
§02.07 Soltik
Soltik
The web is more interesting together.
Soltik is a social platform built around shared browsing. A companion extension turns any page into a place people can talk, annotate, and watch together; the web platform behind it gives creators community hubs, a site builder on their own domain, storefronts, courses, podcasts, and live video — replacing the link-in-bio, membership, newsletter, and community tools they would otherwise stitch together.
Social Browsing
Join live conversations and annotations on any page, share browsing sessions, trails, and watch parties, and surface what the people you follow are reading — instead of browsing alone.
Communities & Hubs
Channels, direct and group messages, events, and reading groups, with per-hub tooling for research labs, newsrooms, galleries, workshops, and salons.
Creator Sites & Commerce
Bio links and a site builder with CMS, blog, forms, SEO tools, and custom domains; storefronts with inventory, shipping, tax, staff, and campaigns; and courses with certificates, podcasts, newsletters, subscriptions, loyalty, and affiliates.
Live & AI Studio
Live streaming, live shopping, and stories, with AI video, effects, transcription, and assisted page building — plus template, plugin, filter, and prompt marketplaces on top.
§03 Coverage
One engineering standard, every domain.
Application Security
SAST, SCA, DAST, API and secrets scanning, and supply-chain analysis, correlated against NVD, GHSA, OSV, KEV, and EPSS.
Delivered by SectoraIdentity & Access
A standards-compliant provider — OIDC, SAML, SCIM, passkeys, conditional access — over governance for human, service, and agentic identities.
Delivered by VeraIDGovernance & Compliance
One control library and evidence base spanning GDPR, CCPA, ISO 27001/27701/42001, SOC 2, HIPAA, DORA, PCI DSS, and GxP, with risk, vendor, and audit operations around it.
Delivered by CompliOne · SectoraAI Security
Prompt-injection classification, jailbreak and shadow-AI detection, agent approval gates, budget controls, and MCP server governance.
Delivered by CloudVera · VeraID · SectoraPlatform Engineering
Per-project authentication, visual profile schemas, and environment-aware publishing on regional data planes.
Delivered by MagicHubCloud Operations
Cross-provider tracing, request replay, deploy risk scoring, and cost analysis for serverless and AI workloads.
Delivered by CloudVeraBusiness Operations
Multi-project workspaces with pipeline, lead engine, client portals, billing, and financial rollups from connected systems.
Delivered by KordoxSocial & Creator
Shared browsing, community hubs, creator sites and storefronts, and live commerce.
Delivered by Soltik§04 Enterprise posture
Built to survive
your procurement
review.
Every product ships against the same control set, with regional data residency, enforced access boundaries, and exportable evidence for auditors.
§05 Contact
Start with the
threat model.
Tell us what you are protecting and which controls you are accountable for. We will map it to the products that apply — and say so plainly when none do.
No commitment required. We reply within 72 hours.
- General
- [email protected]
- Security
- [email protected]
- Residency
- EU and US data planes, selected per tenant