SOTA web pattern: Trust & Data Control Center
This is the revised web direction after comparing current enterprise patterns from Salesforce, Google Cloud, Microsoft, OpenAI, and Atlassian.What the large providers actually do
The common pattern is layered, not legalistic:- A public Trust Center with security, privacy, subprocessors, compliance documents, product scope, and change history.
- In-product controls that let users disconnect integrations, inspect data, clear or delete it, and understand what an action will do.
- Admin controls for access, retention, connected sources, approvals, and audit history.
- Downloadable evidence for procurement: DPA, subprocessors, architecture, security answers, deletion commitments, and certifications only where real.
- Clear shared-responsibility language: the provider explains what it controls and what the customer controls.
Brein’s product output
Public /trust
Not a long policy page. It should have five entry points:
- How Brein handles data — plain-language data lifecycle.
- Security — encryption, access, backups, incidents, and limitations.
- Providers and sources — active, pilot, evaluated, and not enabled.
- Privacy controls — ARCO, opt-out, deletion, Google disconnect.
- Customer evidence pack — downloadable documents and last-updated dates.
active, pilot, conditioned, or
not enabled. Never display a certification, residency promise, or provider
as active without evidence.
In-product Datos y privacidad
This is the high-value surface, modeled after privacy dashboards rather than
consent banners. It should show:
- connected accounts and scopes;
- sources and providers used by the workspace;
- retention settings and upcoming expirations;
- export history;
- suppression and opt-out state;
- deletion requests and their status;
- workspace audit history;
- controls to disconnect, delete, download, or request help.
Contextual action explanations
The user sees a short explanation at the action boundary. The full provenance and policy decision is one click away. Enrichment, export, and send each have a separate explanation and authorization; none becomes a general-purpose consent.Admin and government view
Admins need a downloadableTrust Report for a selected period with:
- providers and policy versions;
- source categories;
- authorizations;
- exports and external actions;
- suppression/deletion outcomes;
- unresolved exceptions;
- incident or change log.
What not to copy from the big providers
- Do not claim SOC 2, ISO, FedRAMP, data residency, or zero retention without the actual scope and evidence.
- Do not create a giant compliance portal before the underlying controls work.
- Do not ask every user to make legal decisions.
- Do not hide material provider or data-use changes behind an undated policy.
