Want to offer AI governance under your own brand? Explore partnership models →

Compliance

Built for compliance — along with you for the journey.

Compliance is one of the hardest problems AI adoption brings: the rules keep moving, the frameworks overlap, and proving what your AI actually did lands on people who already have a day job. Brutor AI was purpose-built for it — controls in the path of every AI request and evidence written as the work happens. Not an afterthought, not a module bolted on later.

/two kinds of ai compliance/

Two problems arrive under the same name.

The rules that now cover AI

GDPR, HIPAA, SOC 2 and most sector rules were written before AI — but cover it too. Your existing obligations simply acquired a new surface: every prompt, every tool call, every agent action.

same obligations, new surface

The rules written for AI

The EU AI Act, ISO/IEC 42001, frameworks like the NIST AI RMF. Depending on your role and risk tier: inventory your AI systems, classify them, log automatically, run a management system.

new obligations, a new unit of account

That second kind changes what you have to account for: the unit is no longer the model or the app but the AI System — so it has to exist as a real object, with an owner, a purpose, a lifecycle stage and a risk tier. In Brutor it does, which is why the same registry answers “what AI are we running?” and “who is accountable for it?”.

And Brutor AI answers both kinds from the same place: the request path, where the AI actually runs. That’s the whole design — the controls and the evidence come from the platform doing its job, not from a compliance project running alongside it. Read the guide →

/how brutor answers/

Different regulations, overlapping questions.

They differ in vocabulary, thresholds, and paperwork. Underneath, most keep coming back to the same five — and the Brutor AI Gateway answers them on every call you route through it.

  • Who may use what?Access is scoped per team, app, and agent, and every agent carries its own identity rather than a shared key — so “who could reach this model” is a configuration you can show an auditor, not an investigation you have to run.
  • What data may leave?Sensitive content is caught in flight rather than discovered afterwards — and each catch becomes a line of evidence, not just a block.
  • Where must a human decide?The actions you designate as high-risk wait for a person to approve them, and the record shows who approved what, and when.
  • What actually happened?Every request and control decision is written as it happens, attributed to the user, the agent, and the AI System behind it.
  • Can you prove it later?Those records carry your framework tags and export date-scoped — the exact window an auditor asks about, produced in the meeting rather than three weeks after it.

Four layers of control, in the request path.

The gateway runs all four on every routed call, scoped per resource group — give sales a stricter configuration than engineering — and each writes tagged audit lines as it works.

Guardrails

PII, prompt injection, secrets, and toxic content — on input and output, blocked or redacted.

chat_output → pii → redact

Semantic policies

For what pattern-matching misses: write the constraint in plain language, a judge model checks every request.

shadow mode first, then enforce

Argument policies

Syntax-aware control of tool calls — SQL, URLs, shell, file paths parsed before they run.

deny non-read · deny multi-statement

Agent policies

Per-agent capability grants: what it may call, what returns a 403, what waits for a human.

allow · deny · approval required
How compliance evidence is produced: a control fires in the Brutor AI Gateway, the decision is written as a tagged audit record, and exported date-scoped per regime for the auditor

One request, end to end: a control fires, the decision is written as a tagged record, and the evidence exports per framework.

And all of it is policy-as-code. A resource group’s full configuration — guardrails, policies, approvals, framework settings — exports as YAML you can version, review as diffs, and re-apply. When an auditor asks what changed and who approved it, the answer is a Git history.

Scope, plainly

All of this happens on traffic routed through the gateway. AI you use outside it — Copilot seats, ChatGPT, a vendor’s built-in AI — appears in the Brutor AI Asset Registry as observed assets, inventoried and costed, clearly marked as observed.

Which is why routing more of it is the best move you can make: every asset you bring behind the gateway converts from policy-and-vendor-trust into enforced-and-evidenced — and picks up guardrails, budgets, and agent controls on the way in.

/evidence & frameworks/

Tagged at the moment a control fires.

In the Brutor Admin Console you declare the frameworks you follow. From then on every routed call is stamped down to the criterion as the decision happens — and frameworks compose, so a single row can carry several tags without duplicating anything.

Brutor Admin Console, compliance posture: declared frameworks with tagged request-log counts and per-regime auditor exports

Compliance posture in the Admin Console: which frameworks you’ve declared, tagged-row counts for any date window, and an “Export for auditor” CSV per regime.

proxy log · audit record
request   POST /v1/proxy/llm · surface chat_output · resource group sales
guardrail pii_detectionREDACTED (email, IBAN)
tags      soc2.cc6.6 · eu_ai_act.high · iso_42001
evidence  date-scoped CSV export per regime

The control fired, the data was redacted, and the evidence tagged itself — no quarterly evidence-gathering exercise required.

Five frameworks, wired in.

SOC 2

What your customers’ security teams ask for first. Tags carry the Common Criteria number — which criterion, not just which framework.

GDPR Article 30

One row per detected processing event — the raw material of a record of processing that covers AI traffic.

HIPAA

PHI access tracked per call, in the shape accounting-of-disclosures requests and BAA evidence ask for.

EU AI Act

Risk tier set per resource group, inherited by every routed call. Transparency obligations apply now; high-risk lands December 2027.

ISO/IEC 42001

Not just automated tagging — guidance towards compliance.

The AI management standard European buyers ask about most, and increasingly a procurement requirement rather than a badge. Beyond tagging, the Admin Console tracks readiness across the standard’s 38 Annex A controls: what’s implemented, what’s partial, what’s still open — each with an accountable owner and its evidence, some satisfied automatically by platform activity — plus a one-click evidence pack for the auditor.

Brutor Admin Console, ISO/IEC 42001 readiness: control-by-control coverage with accountable owners and a downloadable evidence pack

Readiness control by control, with the proof bundled into one evidence pack.

Following something else? A sector rule, an internal AI policy, a customer’s questionnaire — the same machinery answers it. More frameworks are on our roadmap, weighted by what customers actually answer to — tell us which you need.

/why brutor/

Where Brutor stands out.

  • Evidence you can’t backfill. Questionnaire answers are assembled after the fact. A tagged request log is contemporaneous — written while the control fired.
  • Proof that controls fired, not that they exist. Compliance automation shows your policy is signed and your settings are on. Brutor shows the policy stopped a specific call, at a specific second.
  • Agents are evidence subjects. Every agent has an identity, so the accountability chain is in the record, not inferred from a shared key.
  • Frameworks compose, they don’t repeat. One control set, many regimes: enable another framework and the same enforced decisions start carrying its tags too.

Read next: Built-in compliance: why it doesn’t have to slow you down (literally!) — the two kinds of AI compliance, what to do about the AI you can’t route, and how the evidence you’re already collecting shortens security reviews and opens regulated markets.

/start the conversation/

See how you can walk into the AI audit with evidence.

Download the free trial, or book a 30-minute demo with our team.

Scroll to Top