Brainpan.AI is a consultancy operating a static marketing and research website. There is no application, no user account, no login, and no customer database behind this site. That architecture is the substance of most of what follows: the majority of the privacy and security questions a procurement reviewer asks are answered by the fact that there is very little here to collect, store, or lose. This page states plainly what does happen, who else touches it, and what this company is and is not certified to claim. Effective 2026-07-31.
1. Privacy statement
Brainpan.AI collects personal data in exactly two places on this site, both of which are forms a visitor chooses to complete. Nothing is collected passively.
The contact and audit request form
The form at /contact/ collects a full name, a business email address, a job title or role, a company URL, and an optional free-text description of the visibility challenge the visitor wants help with. A privacy consent checkbox must be ticked before the form will submit. These fields are used for one purpose: to respond to the inquiry and, where the visitor asks for it, to scope and deliver an engagement. They are not sold, rented, or shared for anyone else’s marketing.
The research and report signup
Where this site offers a downloadable research artifact, the form collects an email address and, in some placements, a first name. That address is used to deliver the requested document and subsequent research from Brainpan.AI. Every message carries a one-click unsubscribe, and unsubscribing removes the address from all future sends.
Legal basis and retention
Inquiry data is processed on the basis of the visitor’s request to be contacted; research-list data is processed on the basis of consent given at signup and withdrawable at any time. Inquiry records are retained while a commercial conversation is live and for a reasonable period afterwards for business-record purposes. Research-list addresses are retained until unsubscribed or until the list is retired.
Your rights
Regardless of jurisdiction, Brainpan.AI honors requests to access, correct, export, or delete the personal data it holds about an individual. Send the request to kwalsh@brainpan.ai with the subject line Data request. Requests are acknowledged within 5 business days and completed within 30 days. Rights under the EU General Data Protection Regulation and comparable US state privacy statutes are honored on the same terms, and there is no charge for a first request.
Children
This site is a business-to-business property. It is not directed at children, and Brainpan.AI does not knowingly collect personal data from anyone under 16.
2. Data handling
This section is the one most procurement reviews need, so it is stated as directly as possible.
What Brainpan.AI does not process
- No customer systems access. Brainpan.AI research does not require, request, or receive access to a client’s analytics platform, CRM, ad accounts, content management system, or production infrastructure. Where a client chooses to grant access for a specific engagement, that access is scoped and governed by the engagement agreement, not by this site.
- No end-customer data. Brainpan.AI does not process a client’s customers’ personal data. Nothing in the AIVI™ research program touches consumer records.
- No special-category data. No health, biometric, financial-account, government-identifier, or other special-category personal data is collected anywhere on this site.
- No payment data. Purchases are completed on Stripe’s own hosted checkout. Card numbers never reach Brainpan.AI systems and Brainpan.AI never sees them.
What the research program processes
Every figure in a published AIVI™ index is derived from public model outputs collected by Brainpan.AI against public AI assistants. No client relationship, analytics account, or data export contributes to any score. Brand names, published URLs, and model responses are the entire input set, and the underlying scoring rules are published in full in the AIVI™ methodology document. This is a deliberate design choice: research built only on public inputs can be published, audited, and challenged by anyone, and it creates no confidentiality exposure for any party.
Where data goes
Form submissions are transmitted over TLS to the processors named in Section 3 and delivered to a Brainpan.AI business mailbox. There is no server-side application on this site, so nothing a visitor submits is written to a database under Brainpan.AI’s control. International transfers are governed by the standard terms of the processors named below.
Client confidentiality
Engagement deliverables, client-supplied materials, and anything learned in the course of an engagement are confidential and are not published, quoted, or used as case-study material without written permission. Where a client is named in a published AIVI™ index, that naming is based on public model output and would have occurred whether or not a relationship existed.
3. Subprocessors
Four third parties touch data related to this site. There are no others, and this list is maintained here rather than supplied on request.
| Processor | Function | Data involved |
|---|---|---|
| Web3Forms | Delivery of contact and audit-request form submissions to a Brainpan.AI mailbox | Name, business email, role, company URL, and the optional free-text message |
| MailerLite | Research and report distribution list | Email address and, where supplied, first name |
| Stripe | Payment processing for research products, on Stripe-hosted checkout | Billing details entered directly into Stripe; Brainpan.AI receives a transaction record only |
| GoDaddy | Web hosting for this site | Standard web server request logs |
Adding or replacing a subprocessor is a change to this page, and this page is versioned by its effective date. A reviewer who needs to be notified of changes can ask to be added to a notification list at kwalsh@brainpan.ai.
5. Security posture
The honest description of this company’s security posture is that its attack surface is small by construction, and that it holds no formal certification. Both halves of that sentence matter to a reviewer, so both are stated.
What reduces risk here
- Static architecture. This site is pre-rendered HTML, CSS, and JavaScript served from disk. There is no application server, no database, no user authentication, and no administrative interface exposed to the public internet — which removes the categories that account for most website compromise.
- No credential store. Because there are no accounts, there are no passwords, sessions, or tokens belonging to visitors to steal.
- Transport security. The site is served over HTTPS, and all form transmissions to the processors in Section 3 are encrypted in transit.
- Minimal third-party code. No advertising, analytics, tag-management, or session-replay scripts run on these pages, so there is no third-party JavaScript supply chain to compromise.
- Payment isolation. Checkout happens on Stripe-hosted pages, so PCI scope sits with Stripe rather than with this site.
What Brainpan.AI does not claim
Brainpan.AI is not SOC 2 Type I or Type II attested and is not certified to ISO/IEC 27001. It is a small independent consultancy and it does not hold those certifications today. Any vendor questionnaire asking for them should be answered accordingly rather than routed around. Where a client’s procurement process requires specific controls for an engagement — named-personnel restrictions, defined data-handling terms, deletion commitments, or a signed DPA — those are negotiated in the engagement agreement, and Brainpan.AI will sign reasonable terms.
Frameworks this work is written against
Research practice follows the vocabulary of the NIST AI Risk Management Framework, particularly its emphasis on documented measurement, disclosed limitations, and traceable provenance — which is why every AIVI index names the methodology version that produced it. Site accessibility targets WCAG 2.2 Level AA.
Reporting a vulnerability
Send security reports to kwalsh@brainpan.ai with the subject line Security report. Reports are acknowledged within 2 business days. Good-faith research that avoids privacy violations, service degradation, and data destruction will not be pursued.
6. Research data and licensing
Published AIVI™ index data is open. The Q2 2026 Insurance edition — the leaderboard JSON, its OpenAPI description, and the per-brand records — is licensed under Creative Commons Attribution 4.0 International. It may be reused, redistributed, and built upon, including commercially and including inside AI-generated answers, provided attribution is given to Brainpan.AI with a link to the source page. The endpoints are declared as schema.org Dataset resources so machine consumers can identify the license programmatically.
Two commitments attach to that data. Field names and structures are frozen for the life of a published edition, so anything built against them keeps working. And any organization named in a published index may challenge a figure under the correction policy — a standing commitment that applies whether or not that organization is a client, with published service levels and a public record of determinations.
Brand names, carrier names, and trademarks appearing in Brainpan.AI research are the property of their respective owners and are used for identification and comparative commentary. Their appearance implies no affiliation with, endorsement by, or client relationship with Brainpan.AI.
7. Intellectual property
Site content, written analysis, frameworks, and the AIVI™ scoring model are the property of Brainpan.AI, except where a more permissive license is stated. Published index data carries the CC BY 4.0 license described in Section 6; the surrounding editorial analysis does not.
Quoting from this site for commentary, research, or journalism is welcome with attribution and a link. Republishing substantial portions of an article, or reproducing frameworks and methodology as one’s own, is not. AIVI™ and the AI Visibility Index name are marks of Brainpan.AI.
8. Terms of use
Content on this site is provided for general information. It is not legal, financial, or regulatory advice, and it does not create a consulting relationship — that begins only with a signed engagement agreement, whose terms control over anything on this page in the event of a conflict.
Published research describes observed model behavior during a bounded collection window. AI systems change continuously and without notice, so no representation is made that a figure remains current after its edition’s window, and no outcome is guaranteed from acting on published analysis. Known limitations are documented in Section 7 of the methodology rather than left implied.
Outbound links are provided for reference. Brainpan.AI does not control third-party sites and is not responsible for their content or their practices. To the fullest extent permitted by law, this site is provided as is, and Brainpan.AI is not liable for indirect or consequential losses arising from its use.
9. Procurement and vendor review
Vendor questionnaires, security reviews, and DPA requests go to kwalsh@brainpan.ai. They are answered directly by the founder rather than routed through a sales process, and turnaround is typically under a week.
| Question | Answer |
|---|---|
| Do you process our customer data? | No. See Section 2. |
| Do you require access to our systems? | Not for research. Engagement-specific access, if any, is scoped in the engagement agreement. |
| Are you SOC 2 or ISO 27001 certified? | No. See Section 5. |
| Will you sign a DPA or NDA? | Yes, on reasonable terms. |
| What subprocessors do you use? | Four, listed in full in Section 3. |
| Do you use cookies or analytics? | Neither. See Section 4. |
| Where is data hosted? | Site hosting is GoDaddy; form and list data sit with the processors in Section 3. |
| Can we be removed from a published index? | Figures are corrected under the correction policy where they are wrong. Accurate figures are not withdrawn. |
Contact. Kevin Walsh, Founder — kwalsh@brainpan.ai, +1 703 951 7195, LinkedIn. Brainpan.AI is the data controller for personal data collected through this site, and Kevin Walsh is the contact for privacy, security, and procurement matters.
Frequently asked questions
Does Brainpan.AI need access to our analytics or CRM?
No. Every figure in a published AIVI™ index is derived from public AI model outputs. No client relationship, analytics account, or data export contributes to any score, which is what makes the research publishable and independently checkable.
Are you SOC 2 or ISO 27001 certified?
No. Brainpan.AI is an independent consultancy and holds neither certification today. The site is a static property with no application server, no database, and no user accounts, which removes most of the categories those audits assess — but that is a description of the architecture, not a substitute for an attestation. Where an engagement requires specific controls, they are negotiated in the engagement agreement.
Does this site use cookies or track visitors?
No cookies are set and no analytics run. There is no Google Analytics, tag manager, ad pixel, or session-replay script, and the site’s JavaScript writes nothing to browser storage. Fonts are self-hosted, so no third-party font provider sees visitor IP addresses.
Our brand appears in one of your indices. Can we have it removed?
Published indices report what public AI models actually said. A figure that is wrong will be corrected under the correction policy, which is open to any organization whether or not it is a client, with published service levels. An accurate figure will not be withdrawn, and declined requests are logged alongside upheld ones.
Will you sign our DPA, NDA, or vendor agreement?
Yes, on reasonable terms. Send it to kwalsh@brainpan.ai; review is handled directly by the founder and typically completes within a week.
