One control plane. Every AI request enforced, recorded and costed in the same place.
Every element behind the Brutor AI Control Plane, what each one does, and how enforcement in one place becomes evidence, cost control and assurance everywhere else. All of it ships together — nothing is priced per module.
Enforcement in one place produces the records. The records become your evidence, your costs and your assurance. That is why this is one plane and not seven tools.
Enforced in the request path
Your own AI Systems route through the Gateway. Everything applies: guardrails both ways, policy, budgets, identity, and a record of every decision.
Imported and costed
The AI you buy runs in the vendor’s own app, so nothing can stand in the path of those calls. Usage is imported instead: inventory, cost in the same ledger, budget alerts.
Found, and awaiting onboarding
Shadow AI, surfaced by adapters on the scanners you already run. It lands in the registry with an owner and a purpose — and a one-click, pre-filled path to Governed.
Everything above applies to every AI request. Agents are where it gets hard.
A model chooses its own next step as it runs, so a test you ran yesterday can’t guarantee it will do the right thing today. And when one degrades — or quietly stops working altogether — nothing goes red: the calls all come back marked successful. That is what element /02/ AI Systems Assurance exists for: define, promote, run, watch, respond — a closed loop, not a launch checklist.
From download to production.
Nobody in this category will tell you what the first month looks like. Here it is.
Day one
Download, run, route. The trial is a single Rust binary; integration is a base-URL change. Existing SDKs keep working. First traffic governed the same day.
First week
Shape it to the organization: resource groups, budgets, policies, guardrails. Teams onboard — and the Portal gives them a better tool than the one it replaces.
Week two
Assurance kicks in. Baselines learned from real runs; drift and liveness verdicts begin. Until they are ready, the verdict reads learning — never a green light it hasn’t earned.
Day thirty
An inventory, one cost ledger, evidence accumulating and agents under assurance. And if you walk away, that is a config change too.
No rewrite. No migration project. No new SDK.
Your AI calls never pass through anything you built.
This is the first question a technical evaluation asks, so here is the plain answer.
The call leaves your network for a vendor endpoint directly. Your API gateway is not on that path. Your SIEM records an egress, not a prompt or a tool call. Your identity provider is never consulted, so nothing can say which agent acted or on whose behalf. And a CASB cannot read an agent’s intent.
One base-URL change puts a governed hop back on that path — inside your boundary, in front of every model, tool and agent. Checked on the way through, recorded on the way out. No detectable latency added at tested concurrency — the benchmark is published.
What’s behind the plane.
The elements of one system — each usable on day one, each feeding the others.
Brutor AI Gateway
The enforcement core. Three protocols on one governed hop — LLM, native MCP and native A2A v1.0 — plus skills and knowledge: guardrails and policies enforced as responses stream, budgets that refuse before the call is made, and every decision recorded as it happens. No detectable latency added at tested concurrency.
WatchTBDAI Systems Assurance
Not just Day 1. Day 201. The part that makes a lifecycle whole — and the part almost nothing else has. Every AI System learns its own baseline from its own real runs — step counts, tool mix, cost, terminal states — and while that baseline is still forming the verdict reads learning, never a passing grade it hasn’t earned. After that a system reports healthy, learning, degraded, drifting, stalled, silent, suspended — or unknown. Drift arrives with its most likely cause: a model version, a changed tool set, a new input pattern. Health is always the worst component — never the average.
WatchTBDAI Asset Registry
Every model, tool, agent and AI System — with an owner, a purpose and a true state: Governed, Observed or Discovered. The inventory the EU AI Act and ISO 42001 actually ask for. If nothing else, you leave with this.
WatchTBDShadow AI Discovery
Adapters for the scanners you already run send signed, observe-only events into the plane. Found AI lands as Discovered — and onboards to Governed with a pre-filled configuration.
WatchTBDMCP Registry
Your governed subregistry of approved tools and MCP servers — the official registry spec, inside your walls. The yellow pages; the gateway is the switchboard.
WatchTBDMission Control
The watching side: cost and usage across routed and imported spend, budget alerts, drift and liveness alerts per AI System — and exports to your own observability stack.
WatchTBDAdmin Console
The deciding side: resource groups, policies, guardrails, agent grants, framework declarations and the ISO 42001 readiness tracker — everything exportable as policy-as-code with a Git history.
WatchTBDBrutor User Portal
The governed chat workspace your teams actually prefer: company knowledge, the right model per task, agent skills, batch processing — every message on the same rails. White-label it, or build your own on the same API.
WatchTBDA human, exactly where you want one
Not a switch you flip in an emergency — a thread through the whole lifecycle. Mark an action approval-required when you define it; the Gateway holds it for sign-off rather than guessing; and a response can drop a whole AI System to approvals-only when its behaviour moves.
The same mechanism at all three points, so “where does a person decide?” has one answer instead of three.
Why one system beats a pile of point tools
Enforcement produces the records; the records become your evidence, your costs and your assurance. Buy these separately and you are the integration. See how the core works →
Agent Control
Every agent with an identity, a contract of what it may do, and limits enforced mid-call — then assurance for as long as it runs: baselines, drift with a cause, liveness, replay.
Agent Control →AI Cost Control
One ledger for routed and imported spend, budgets that refuse before the call is made — and routing, caching and batching that cut the bill itself. Tokenomics, measured: cost per completed task and each workload’s cost-growth class, from every recorded run.
AI Cost Control →Shadow AI Discovery
How the AI nobody registered gets found, given an owner and a purpose, and onboarded with a pre-filled form.
Find it all →Compliance
SOC 2, GDPR Art. 30, HIPAA, the EU AI Act, and ISO 42001 with 38 Annex A controls tracked — as a by-product of enforcement.
Evidence →New white paper: AI Systems Assurance
Why AI systems fail differently from traditional software — quiet failures inside requests that succeed, models that change under you — and how to answer the two questions that stall adoption: who signs their name under this, and how do we know it still works six months in. The four guarantees — bounded, alive, non-drifting, doing its job — with the evidence behind each.
Shaped to your organization, not a generic template.
Most AI governance tools hand you a one-size-fits-all structure. Brutor does the opposite: you define your organization once — teams, departments, cost centres, projects — and governance flows automatically through every level.
Define once.
Your real org chart becomes the governance model. Model it the way you actually operate, not the way a template assumes you do.
Two layers of inheritance — not one.
Most tools blur governance and tooling into a single setting. Brutor separates them on purpose:
Governance always cascades.
Usage limits, cost budgets, guardrails, audit trails, compliance policies — inherited top-down through the whole tree and locked in. A quarterly cap set at the parent binds every agent, portal and sub-project below it. There is no “opt out” here. That is the point.
Resources inherit by choice.
LLMs, MCP servers, skills, knowledge bases — each sub-group decides whether to pick up the parent’s catalogue or curate its own. One toggle: inherit, or don’t.
Inherit everywhere. Opt out where it matters.
A new team gets the default governance the moment it exists. A sub-group that needs different tooling — an R&D sandbox, a coding environment — turns resource inheritance off and keeps every governance lock.
No forced rewrites.
Reorganise, and policies recalculate down the new tree. No re-templating, no forty separate edits — and no agent can loosen a limit it inherited.
A config change, not a migration.
Getting on the control plane is one base-URL change — and nothing you do here is irreversible.
Deploy anywhere
A single Rust binary — on-premise, private cloud, Brutor SaaS, or white-labelled as your own. The trial is a download.
Open standards
OpenAI-compatible API, native MCP, native A2A v1.0 — existing clients keep working, and you never write code against a Brutor SDK.
Your observability
Decisions, alerts and metrics export to OpenTelemetry — your dashboards, not another silo.
Your identity provider
Users and agent identities anchor in your IdP — Brutor decides, it doesn’t store.
Policy-as-code
The whole posture as YAML with a Git history — reviewable, promotable, revertible.
Your evidence stays yours
The asset registry and the audit evidence export in standard formats, on demand — so what you accumulate here does not become ours. [confirm before publishing]
The whole plane, on your terms.
Download the free trial, or book a 30-minute demo with our team.
