Branded Mayhem Collective
br8n8gncTrust Center
Request access

Branded Mayhem Collective

Branded Mayhem Collective is the Richardson, Texas holding company behind 8gnc, the agency, and br8n, the practice that helps organizations build and operate AI capability.

Trust makes good work possible. We’re building company-level security and governance assurance so your teams can evaluate BMC with confidence and bring us into your organization with a clear understanding of how we work. Our program is designed to support your security reviews, procurement process and operating requirements.

Our founder’s professional certifications inform our work. Company assurance is a separate commitment: BMC has not yet been independently audited or certified. This Trust Center shares our controls, governance practices and remaining gaps as we build toward independent review.

Compliance

BMC is preparing its security and governance program for independent review. Our governance foundation was formally adopted and signed on August 6–7, 2026. We’re now closing remaining control gaps and building a documented record of how our controls operate in practice.

Our August 7, 2026 internal SOC 2 assessment recorded 73.7% readiness across 38 controls: 20 met, 16 partially met, and 2 not yet in place. Once the controls and supporting evidence are ready, we plan to engage an independent firm to perform the audit.

ISO/IEC 27001Information security managementReadiness
ISO/IEC 27017Cloud services securityReadiness
ISO/IEC 27018Personal data in the cloudReadiness
SOC 2Security, availability, confidentiality73.7% readiness
ISO/IEC 42001AI management systemsReadiness
NIST AI RMFAI risk managementReadiness
GDPREU data protectionReadiness
CCPACalifornia privacyReadiness

Resources

Data Processing AgreementRequired before client data reaches any system we operate.On request
Sub-processor and DPA registerEvery third party that touches client or operational data, with the status of each agreement.On request
AI tooling and client data policyWhich class of data may reach which AI tooling, and the DPA-backed route required before BMC operates client-data AI.On request
Privacy rights procedure and request channelAccess, deletion, correction and opt-out requests are accepted at hello@brandedmayhem.com and tracked through a documented procedure.Available
Remaining control gaps and where each stands. Published rather than gated.Published
Certification reportsNo independent firm has examined us, so no report exists to send. This page will say so until one does.Does not exist yet

Controls

Verified 7 August 2026
  • Full-disk encryption enforced on workstations
  • Host firewall enabled on workstations
  • TLS on all public surfaces, with HSTS and a hardened response-header set
  • Persistent application, database and agent-runtime state is confined to separate LUKS2-encrypted volumes; unencrypted server root disks hold replaceable operating-system and configuration state only
  • Production database and application listeners bind only to loopback or authenticated private paths, never directly to the public internet
  • Both production Linux hosts enforce named key-only administration, disabled root and password login, default-deny host firewalls, intrusion blocking, audit logging, mandatory access controls and unattended security updates
  • Multi-factor authentication required across the source-control organization
  • Secrets centralized in a managed secret store; no plaintext secrets in source
  • Security-awareness evidence includes 70 continuing-education credits across four dated credentials
  • AI system register, risk assessment and impact assessments adopted as maintained records for BMC-operated AI use
  • Pull requests required across all active repositories, with deletion and non-fast-forward updates blocked
  • Application error monitoring with alerting
  • Agent execution and the production data plane are isolated on separate hosts with disjoint runtime authority
  • Sub-processor inventory maintained, each vendor agreement verified against its actual terms
  • Privacy rights requests accepted through a monitored channel with a documented handling procedure
  • Global Privacy Control is honored on this site for advertising-consent signals
  • Data residency documented per system and disclosed in the sub-processor table
  • Production-data and agent-runtime snapshots are encrypted client-side before off-site storage, with separate primary and break-glass repository credentials
  • Current application, volume-state and encryption-header restores passed integrity checks
  • Source control mirrored one-way to separate off-site storage, daily
  • Uptime monitoring with alerting on public surfaces

Open gaps

Every entry names a remaining control gap and where it currently stands.

No certification, and the audit has not been performed
Where it stands

BMC holds no ISO, SOC 2, or equivalent certification. Readiness work is underway and controls are being brought to evidence against the frameworks above, but no independent firm has examined us and no report exists.

Encrypted backup and restore controls have point-in-time, not recurring, evidence
Where it stands

The permanent data and agent hosts each have encrypted off-site repositories with independent primary and break-glass credentials. Application data, volume state and encryption-header restores passed integrity checks on 3 August 2026, and both repository credentials were tested independently. Those are current point-in-time results; they are not yet retained operating evidence across an observation window.

Governance is newly adopted, so operating history is thin
Where it stands

The core policy set, risk register, AI management charter and privacy determinations were reviewed, signed and adopted by the Owner on 6 and 7 August 2026, with versioned adoption records on file. What does not exist yet is history: recurring reviews, measured indicators and cadence evidence all start from this month.

The incident-response plan is adopted but not yet exercised
Where it stands

The incident-response policy was adopted on 6 August 2026 with monitoring and escalation paths in place. No tabletop exercise has yet produced evidence that the plan executes under pressure.

Vulnerability and centralized security monitoring remain incomplete
Where it stands

The production Linux hosts now have audit logging, intrusion blocking, mandatory access controls, automatic security updates, persistent journals and runtime health monitoring. BMC still does not operate a complete vulnerability-scanning program, EDR or SIEM, scheduled centralized log reviews, managed-device enforcement, or application allowlisting. Repository rules also do not yet require an approving review or passing status check before merge.

The access review is not fully attested
Where it stands

Access-control procedures and inventories exist, but the current review is not complete across every system and does not yet carry the Owner attestation needed for audit evidence.

One content platform routes to AI providers we do not control
Where it stands

Our content management platform names OpenAI, Google Cloud and Anthropic as its own sub-processors, and its agreement does not limit hosting to the European Union. Content placed in that platform can therefore reach AI providers through the vendor’s supply chain rather than ours. Our internal policy governs what we put into AI tools; it does not reach what a vendor does downstream, and we would rather say so than let the sub-processor list imply a tighter boundary than exists.

One content platform operates outside DPA coverage, under a documented use restriction
Where it stands

Sanity stores structured site content for one property and offers no self-serve data-processing agreement. Rather than leave that ambiguous, we audited the full dataset on 7 August 2026: no end-user records, lead records, form submissions, or account records exist there — the project is restricted to public-bound editorial and marketing content, whose only identified personal data is the operator’s own author byline. On that basis we adopted a signed current-use limitation determination: Sanity is prohibited from holding client personal data, end-user personal data, form data, or personnel data, and the audit re-runs on any schema change or annually. Sanity’s own attestation is SOC 2 Type 2; the ISO 27001 certification on its security page belongs to its infrastructure provider, and we will not repeat that claim on its behalf.

No DPA-backed BMC-operated client AI plane or active technical routing control
Where it stands

A fail-closed routing guard has been implemented and unit-tested in source, but it is not yet activated in BMC’s operating dispatcher. No BMC-operated client AI route is active today. Client data therefore has no permitted fallback to a personal subscription; client work remains in the client’s own licensed environment until the operating control and commercial evidence are complete.

No Content-Security-Policy
Where it stands

Public surfaces carry HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy, but no CSP.

HSTS preload staged, not complete
Where it stands

HSTS is live on all three domains with a one-year max-age and includeSubDomains. The preload token now serves on this domain; the other two carry it in configuration but have not shipped the deploy that puts it on the wire. No domain has been submitted to the browser preload list, and submission is not accepted until a domain is already serving the token.

Subprocessors

Cloudflare
Hosting, CDN, DNS, WAF
Global edge
Hetzner
Infrastructure hosting the self-hosted data and isolated agent-compute planes
Nuremberg, Germany (EU)
Convex (self-hosted)
Application data
Nuremberg, Germany (EU)
Anthropic
AI processing
United States
Google Workspace
Email, calendar, documents
United States
GitHub
Source control
United States
Tailscale
Private network for administrative access
United States
Doppler
Secrets management
United States
Resend
Transactional email
United States
Sentry
Error monitoring
United States
Stripe
Payments
United States
Sanity
Content management
United States / EU
Storyblok
Content management
EU-headquartered; hosting not EU-limited
UptimeRobot
Uptime monitoring
United States

FAQ