Customer Story

How Brainframe added AI to GRC without exposing client data.

Brainframe is the all-in-one GRC platform where security and compliance teams keep their entire management system. It launched AI co-pilots built on Tresor's confidential inference, giving its clients AI on their compliance data without handing that data to a third-party AI vendor or subcontractor, plus verification receipts that show exactly where and how that data was processed.

Davy Cox portrait

"We hold our clients' most sensitive compliance data. We can't add AI to a GRC platform without a confidential foundation."

Davy Cox, CEO, Brainframe

Snapshot

Brainframe

Brainframe logo
Industry
Governance, Risk & Compliance (GRC) software
Region
Luxembourg / EU - Made in EU, cloud or self-hosted
Tresor product
Confidential Inference API
Use case
AI GRC co-pilots for policies, procedures, recommendations, and T&C / DPA review on confidential compliance data
Outcomes
  • Confidential GRC co-pilots on Tresor's zero-access inference
  • Live on Tresor in one week via the OpenAI-compatible API
  • Uses verification receipts to show clients exactly where and how data was processed

The Challenge

The system of record for an entire compliance posture cannot become an AI leak.

A GRC platform is the system of record for an organisation's security and compliance posture. The same data that makes AI useful inside Brainframe is the data its clients can least afford to expose.

In Brainframe, that means policies and procedures, risk assessments, asset registers, audit evidence, incident-response plans, vendor reviews, and data-processing agreements, all mapped across more than 80 frameworks from ISO 27001 to NIS2, DORA, and GDPR.

It is also some of the most confidential data an organisation holds. Brainframe's clients, from auditors to banks and healthcare providers, treat a leak of their compliance evidence not as an embarrassment but as a regulatory event. Many run Brainframe self-hosted precisely to keep that data close.

So when Brainframe set out to add AI co-pilots for drafting policies, suggesting recommendations, and reviewing contracts and DPAs, it hit the wall most software companies stepped straight past: the co-pilot needs to read exactly the data the client most wants to keep sealed.

What sits inside Brainframe

  • Policies and procedures
  • Risk assessments
  • Asset registers
  • Audit evidence
  • Incident-response plans
  • Vendor reviews
  • Data-processing agreements
  • Mappings across 80-plus frameworks

Why that matters

For Brainframe's buyers, confidentiality is part of the product, not a nice procurement line. AI only works here if the trust boundary stays exactly where it was before.

Why Public AI Was A Non-Starter

The default path broke the product promise on day one.

Brainframe needed AI it could put in front of regulated clients and stand behind. The usual two options both failed that test for different reasons.

Public model APIs

Sending prompts to a public AI endpoint would route Brainframe's clients' compliance evidence through a third party that could read every word. For a platform built for auditors and banks, that breaks the product promise immediately.

Running models in-house

Owning the GPUs, operations, updates, and incident response would pile infrastructure work onto a focused product team, while still leaving clients without proof of what happened to their data.

For a vendor whose whole job is helping clients verify their controls, "the AI vendor could see it" is not a footnote. It is a dealbreaker.

The Solution

Confidential inference underneath the product, not on top of it.

Brainframe built its co-pilots on Tresor's Confidential Inference API. Because the API is OpenAI-compatible, it dropped into the stack without a rebuild and went live on Tresor within about a week.

Zero-access processing

Every prompt and document is handled inside an attested secure enclave, so confidential compliance data does not have to be exposed to a third-party AI vendor or subcontractor in the inference path.

Verification receipts

Brainframe can walk clients through cryptographic proof of which model ran, where it ran, and inside which sealed environment. The evidence does the heavy lifting in security conversations.

EU residency and OSS models

Inference in EU regions on an open-source stack, without another outside vendor getting a copy, matches the sovereignty story Brainframe already sells to regulated European clients.

How It Came Together

1 week

from decision to working integration

Brainframe's engineers pointed their AI calls at Tresor instead of rearchitecting around a new provider. The confidential foundation went in underneath the product, not on top of it.

  • Confidential foundation underneath the product
  • No rebuild around a new provider surface
  • Workspace under evaluation for the next step

What's Now Possible

AI co-pilots that keep the trust boundary intact .

Brainframe's GRC co-pilots are live for policy and procedure generation, recommendations, and T&C / DPA review, all on confidential inference rather than a public AI path.

Policy and procedure generation

Clients can generate first drafts on top of their own compliance posture instead of starting from a blank page.

Recommendations on live GRC context

The co-pilots can suggest next steps and improvements against the data already sitting inside the system of record.

T&C and DPA review

Sensitive contract review can run on confidential inference instead of forcing legal and compliance teams to choose between speed and exposure.

The Quieter Win

"We added AI" is usually a yellow flag for a security buyer. With Tresor, Brainframe turns it green: it can show, with receipts, that adding AI did not widen the trust boundary at all.

Confidential-by-design became something Brainframe can prove, not just assert. That is a stronger answer in client conversations today and a foundation the team is already extending, with Tresor's confidential Workspace under evaluation as the next step.

Brainframe never had to choose between shipping AI and keeping its core promise.

For a company whose clients hand over their most sensitive compliance data, that was not a nice-to-have. It was the only acceptable way to build.