Platform

the brutor ai control plane

One control plane. Every AI request enforced, recorded and costed in the same place.

Every element behind the Brutor AI Control Plane, what each one does, and how enforcement in one place becomes evidence, cost control and assurance everywhere else. All of it ships together — nothing is priced per module.

Diagram slot — simplified, above the foldA three-lane version of the architecture below: sources → the plane → the registry, no interior detail. (Designer: the full drawing is 1460 units wide and renders its labels at roughly 8px inside this frame — it needs a simplified lead-in and a stacked mobile fallback.)
GOVERNED IN THE REQUEST PATH OBSERVED ONLY — CANNOT BE ROUTED FOUND BY DISCOVERY — OBSERVE-ONLY AI Systems ROUTABLE Agents Assistants Applications Workflows Integrations Services yours — built to call Brutor Chat clients NON-ROUTABLE ChatGPT Claude Desktop Microsoft Copilot claude.ai vendor apps — can’t be routed through Brutor Shadow AI Agents · MCP servers Assistants · Apps running without anyone’s approval Discovery agents adapters · signed events ROUTE TRAFFIC every call, in path IMPORT TRAFFIC from provider APIs SIGNED EVENTS Brutor User Portal governed chat workspace BRUTOR AI GATEWAY — THE AI CONTROL PLANE Assurance prove it stayed within policy — and say when it changed Observe the AI you buy — accounted for AI COST CONTROL — ACROSS BOTH one usage ledger · tokenomics: cost per completed task & cost-growth class · budgets, chargeback & breach alerts GOVERN — THE MECHANISM Policy · Limits · Routing policy-as-code · who may use what · budgets · failover Guardrails PII · injection · secrets, both ways Compliance framework tagging · ISO 42001 guidance · evidence exports Enforced on every hop — never advisory. ASSURANCE — THE PROOF run ledger · liveness · drift with a cause · replay before you ship IMPORT PROVIDER TRAFFIC Vendor enterprise APIs ChatGPT · Claude · Copilot usage Costed, alerted — budgets warn same ledger as governed spend Counted in your AI inventory basic compliance data — EU AI Act · ISO 42001 scope Enforcement stays with the vendor’s own controls — Brutor adds the visibility. Discover find the AI nobody told you about SHADOW-AI DISCOVERY Device & endpoint adapters signed, observe-only events Registered as Discovered lands in the registry below Coverage is the point: you cannot govern an estate you have not finished counting. AI ASSET REGISTRY — EVERY ASSET, ONE PLACE Governed enforced in path Observed imported & costed Discovered awaiting onboarding CONVERT — ONBOARD WITH A PRE-FILLED QUESTIONNAIRE AI RESOURCES — WHAT BRUTOR FRONTS Models 300+ models · 39 providers · self-hosted MCP servers tools, per-tool policy Agent skills governed, versioned procedures Agents A2A peers · identities KEY Governed in the request path Observed only — imported, never enforced Brought under governance

Enforcement in one place produces the records. The records become your evidence, your costs and your assurance. That is why this is one plane and not seven tools.

Governed

Enforced in the request path

Your own AI Systems route through the Gateway. Everything applies: guardrails both ways, policy, budgets, identity, and a record of every decision.

Observed

Imported and costed

The AI you buy runs in the vendor’s own app, so nothing can stand in the path of those calls. Usage is imported instead: inventory, cost in the same ledger, budget alerts.

Discovered

Found, and awaiting onboarding

Shadow AI, surfaced by adapters on the scanners you already run. It lands in the registry with an owner and a purpose — and a one-click, pre-filled path to Governed.

the hard case

Everything above applies to every AI request. Agents are where it gets hard.

A model chooses its own next step as it runs, so a test you ran yesterday can’t guarantee it will do the right thing today. And when one degrades — or quietly stops working altogether — nothing goes red: the calls all come back marked successful. That is what element /02/ AI Systems Assurance exists for: define, promote, run, watch, respond — a closed loop, not a launch checklist.

The agent lifecycle, end to end →

run it your way

From download to production.

Nobody in this category will tell you what the first month looks like. Here it is.

01

Day one

Download, run, route. The trial is a single Rust binary; integration is a base-URL change. Existing SDKs keep working. First traffic governed the same day.

02

First week

Shape it to the organization: resource groups, budgets, policies, guardrails. Teams onboard — and the Portal gives them a better tool than the one it replaces.

03

Week two

Assurance kicks in. Baselines learned from real runs; drift and liveness verdicts begin. Until they are ready, the verdict reads learning — never a green light it hasn’t earned.

04

Day thirty

An inventory, one cost ledger, evidence accumulating and agents under assurance. And if you walk away, that is a config change too.

No rewrite. No migration project. No new SDK.

why your stack can’t already do this

Your AI calls never pass through anything you built.

This is the first question a technical evaluation asks, so here is the plain answer.

Today

The call leaves your network for a vendor endpoint directly. Your API gateway is not on that path. Your SIEM records an egress, not a prompt or a tool call. Your identity provider is never consulted, so nothing can say which agent acted or on whose behalf. And a CASB cannot read an agent’s intent.

With Brutor

One base-URL change puts a governed hop back on that path — inside your boundary, in front of every model, tool and agent. Checked on the way through, recorded on the way out. No detectable latency added at tested concurrencythe benchmark is published.

Screenshot slot — Mission Control, cost & usageSpend across routed and imported traffic, by team and by AI System, with a budget approaching its warn threshold. (Highest-value capture on the page: it proves “one ledger” is a real screen.)
the elements

What’s behind the plane.

The elements of one system — each usable on day one, each feeding the others.

// in the path
/01/

Brutor AI Gateway

The enforcement core. Three protocols on one governed hop — LLM, native MCP and native A2A v1.0 — plus skills and knowledge: guardrails and policies enforced as responses stream, budgets that refuse before the call is made, and every decision recorded as it happens. No detectable latency added at tested concurrency.

WatchTBD
AI Gateway →
/02/

AI Systems Assurance

Not just Day 1. Day 201. The part that makes a lifecycle whole — and the part almost nothing else has. Every AI System learns its own baseline from its own real runs — step counts, tool mix, cost, terminal states — and while that baseline is still forming the verdict reads learning, never a passing grade it hasn’t earned. After that a system reports healthy, learning, degraded, drifting, stalled, silent, suspended — or unknown. Drift arrives with its most likely cause: a model version, a changed tool set, a new input pattern. Health is always the worst component — never the average.

WatchTBD
Assurance →
// knowing your estate
/03/

AI Asset Registry

Every model, tool, agent and AI System — with an owner, a purpose and a true state: Governed, Observed or Discovered. The inventory the EU AI Act and ISO 42001 actually ask for. If nothing else, you leave with this.

WatchTBD
See it →
/04/

Shadow AI Discovery

Adapters for the scanners you already run send signed, observe-only events into the plane. Found AI lands as Discovered — and onboards to Governed with a pre-filled configuration.

WatchTBD
Discovery →
/05/

MCP Registry

Your governed subregistry of approved tools and MCP servers — the official registry spec, inside your walls. The yellow pages; the gateway is the switchboard.

WatchTBD
MCP Registry →
// seeing & deciding
/06/

Mission Control

The watching side: cost and usage across routed and imported spend, budget alerts, drift and liveness alerts per AI System — and exports to your own observability stack.

WatchTBD
See it →
/07/

Admin Console

The deciding side: resource groups, policies, guardrails, agent grants, framework declarations and the ISO 42001 readiness tracker — everything exportable as policy-as-code with a Git history.

WatchTBD
See it →
// for your people
/08/

Brutor User Portal

The governed chat workspace your teams actually prefer: company knowledge, the right model per task, agent skills, batch processing — every message on the same rails. White-label it, or build your own on the same API.

WatchTBD
User Portal →
Screenshot slot — AI Asset RegistryThe list view with Governed / Observed / Discovered visible on one screen, and one row mid-onboarding. (The single most persuasive screen in the product — and the proof of “you leave with the registry”.)
Screenshot slot — assurance verdictsTwo AI Systems side by side: one reading learning, one with drift flagged — cause: model updated. (Showing the honest state is more credible than an all-green board.)
Screenshot slot — Admin ConsoleA policy being edited, with the resource group it applies to and the Git commit that recorded it. (Backs policy-as-code with something a reviewer can see.)

A human, exactly where you want one

Not a switch you flip in an emergency — a thread through the whole lifecycle. Mark an action approval-required when you define it; the Gateway holds it for sign-off rather than guessing; and a response can drop a whole AI System to approvals-only when its behaviour moves.

The same mechanism at all three points, so “where does a person decide?” has one answer instead of three.

Why one system beats a pile of point tools

Enforcement produces the records; the records become your evidence, your costs and your assurance. Buy these separately and you are the integration. See how the core works →

Agent Control

Every agent with an identity, a contract of what it may do, and limits enforced mid-call — then assurance for as long as it runs: baselines, drift with a cause, liveness, replay.

Agent Control →

AI Cost Control

One ledger for routed and imported spend, budgets that refuse before the call is made — and routing, caching and batching that cut the bill itself. Tokenomics, measured: cost per completed task and each workload’s cost-growth class, from every recorded run.

AI Cost Control →

Shadow AI Discovery

How the AI nobody registered gets found, given an owner and a purpose, and onboarded with a pre-filled form.

Find it all →

Compliance

SOC 2, GDPR Art. 30, HIPAA, the EU AI Act, and ISO 42001 with 38 Annex A controls tracked — as a by-product of enforcement.

Evidence →

New white paper: AI Systems Assurance

Why AI systems fail differently from traditional software — quiet failures inside requests that succeed, models that change under you — and how to answer the two questions that stall adoption: who signs their name under this, and how do we know it still works six months in. The four guarantees — bounded, alive, non-drifting, doing its job — with the evidence behind each.

Get the white paper →

the difference, in depth

Shaped to your organization, not a generic template.

Most AI governance tools hand you a one-size-fits-all structure. Brutor does the opposite: you define your organization once — teams, departments, cost centres, projects — and governance flows automatically through every level.

Define once.

Your real org chart becomes the governance model. Model it the way you actually operate, not the way a template assumes you do.

Two layers of inheritance — not one.

Most tools blur governance and tooling into a single setting. Brutor separates them on purpose:

Governance always cascades.

Usage limits, cost budgets, guardrails, audit trails, compliance policies — inherited top-down through the whole tree and locked in. A quarterly cap set at the parent binds every agent, portal and sub-project below it. There is no “opt out” here. That is the point.

Resources inherit by choice.

LLMs, MCP servers, skills, knowledge bases — each sub-group decides whether to pick up the parent’s catalogue or curate its own. One toggle: inherit, or don’t.

Inherit everywhere. Opt out where it matters.

A new team gets the default governance the moment it exists. A sub-group that needs different tooling — an R&D sandbox, a coding environment — turns resource inheritance off and keeps every governance lock.

No forced rewrites.

Reorganise, and policies recalculate down the new tree. No re-templating, no forty separate edits — and no agent can loosen a limit it inherited.

engineering budget $500/mo model gpt-5.2 └─ ai-system: claims-copilot budget $200/mo ✓ inherited ceiling respected budget $1,000/mo ✗ refused — exceeds parent
Screenshot slot — the resource-group treeThe Resource Groups tree in the Admin Console — the real one, showing a governance limit inherited at two levels and one sub-group with resource inheritance switched off. (This is the screen that proves “two layers, not one” — use the product UI, not a redraw.)
fits your stack

A config change, not a migration.

Getting on the control plane is one base-URL change — and nothing you do here is irreversible.

Deploy anywhere

A single Rust binary — on-premise, private cloud, Brutor SaaS, or white-labelled as your own. The trial is a download.

Open standards

OpenAI-compatible API, native MCP, native A2A v1.0 — existing clients keep working, and you never write code against a Brutor SDK.

Your observability

Decisions, alerts and metrics export to OpenTelemetry — your dashboards, not another silo.

Your identity provider

Users and agent identities anchor in your IdP — Brutor decides, it doesn’t store.

Policy-as-code

The whole posture as YAML with a Git history — reviewable, promotable, revertible.

Your evidence stays yours

The asset registry and the audit evidence export in standard formats, on demand — so what you accumulate here does not become ours. [confirm before publishing]

Screenshot slot — compliance evidence exportThe framework view with coverage per framework, and a date-scoped export being generated for one of them. (Pairs with the ISO 42001 readiness tracker named in Admin Console.)
take control

The whole plane, on your terms.

Download the free trial, or book a 30-minute demo with our team.

Scroll to Top