The most private AI for finance.

From where it runs to who can read what, Cobrain is built so a firm's documents stay the firm's: read where they live, under the permissions they already carry, and never trained on.

EU regionApplication and database in eu-central-1, one region.
GDPR by designRetention is yours to set. Nothing is trained on.
Agents in microVMsIsolated EU sandboxes, destroyed after each run.
Model residencyPinned per model, EU or US, wherever the provider offers it.

Trusted data handling

Attachments never leaveBytes stream through the application into the sandbox. No file URL is minted for an agent, so there is nothing to exfiltrate.
Redacted responsesEvery upstream response body is redacted before it reaches a transcript, so a vendor's 401 cannot echo a credential into a chat.
Nothing trained onYour documents are indexed for search and read at answer time. They train nothing, ours or anybody else's.

Enterprise-grade access

Closed at the doorA folder you cannot read is absent from the tree, absent from search and absent from the agent's view. The rule is the read, not a filter after it.
Lent, never takenA connection is one person's consent to one account. The agent never holds a vendor token; the application makes the call.
Roles the firm setsOwner, admin, editor and member, with capabilities the workspace can retune. Owner and admin always hold everything.

How it runs

Sovereign hostingApplication and database in one EU region. Agent sandboxes are EU microVMs torn down with the turn.
The model is yours to chooseThe frontier labs under one contract, and the region pinned per model. A model without an EU region says so.
Read-only by defaultA credential a firm stores is read-only unless somebody says otherwise, and there is a way to write a value and no way to read one back.
Frequently asked questions

FAQ

Application and database run in a single EU region, eu-central-1. Agent sandboxes are EU microVMs that are destroyed after each run.