Articles on: Artificial intelligence (AI)
This article is also available in:

Confidential AI in Brainframe

🤖 Brainframe Confidential AI



Brainframe’s AI co-pilots help you work faster on assets, risks, controls, policies, and compliance mapping — without sending sensitive material to a public AI service that could read or retain it.


Use them in wizards, document editors, governance linking, framework mapping, and framework Q&A — always with your review before anything is saved.



🔒 Why your data stays private


Brainframe’s AI features are built on Trusted Execution Environment (TEE) confidential computing, powered by Tresor AI — a European confidential-AI provider designed for governance, risk, and compliance work.


Unlike pasting content into ChatGPT, Copilot, or similar tools, your asset descriptions, risk registers, control documentation, and policy text are handled with a zero-access architecture:


  • Encrypted end to end — Content is encrypted on the way in, processed only inside a sealed environment by the supplier that they are unable to access. Readable text exists only in your Brainframe workspace.
  • Processed where no one can look — AI runs inside hardware-sealed enclaves. Neither the AI provider nor the underlying cloud operator can read these prompts or responses. This is enforced by hardware, not by policy alone.
  • Proven on every answer — Each AI response carries a cryptographic verification receipt showing that your request was handled inside attested, sealed hardware. That turns “we use a secure provider” into evidence you can use in audits, due diligence, and regulatory reviews.


In one line: You get modern AI productivity on your most confidential GRC work — with a hardware-backed guarantee that our providers cannot read it, and proof that supports your compliance posture.


Brainframe AI is powered by Tresor AI confidential compute. Learn more at the Tresor AI trust and documentation pages.



⚙️ Before you start: Workspace settings


Workspace administrators control whether AI is available at all.


Where to find it: Workspace Configuration → Integrations → Artificial intelligence.



Setting

What it means

Enable AI features

Turns AI on or off for the entire workspace. When disabled, AI buttons are hidden or unavailable for all users.

Default Brainframe AI

Uses Brainframe’s managed confidential AI (Tresor AI). Recommended for most workspaces.

Custom provider

Optional: connect your organisation’s own OpenAI-compatible endpoint if you have a specific requirement to use a different provider.


Only workspace administrators can change these settings. When AI is disabled, users see a message that an administrator must enable it first on AI buttons.



🏢 Company context (shared across AI features)


Many AI features work better when Brainframe knows who your organisation is. Company context is collected once and reused across wizards, document AI, and framework Q&A.


Typical fields include your organisation’s short name, website, and a description of what the company does. You can fill this in manually or use Generate with AI / Expand with AI to draft a fuller description from a short note.


The first time you use document AI assist and company details are still empty, Brainframe prompts you to complete this screen — the same flow used in the asset wizards.



Data used

  • Company short name, website URL (and crawled data from homepage), organisation description
  • Workspace variables configured for your organisation profile



🪄 Wizards


Wizards are designed to save time. Confidential AI receives the full GRC context of your workspace so suggestions are relevant to your controls, risks, frameworks, and assets — not generic checklists.



Launch from: My Compliance, relevant table views (assets, core business assets), or the risk matrix (risk assessment wizard).



📦 Identify and document primary assets wizard


This wizard helps you identify and document your organisation’s core business assets — the services, processes, and data sets that underpin your management system.


Add assets manually, or let AI propose core services, processes, and important data sets from your company context, then create them in one step.



Data used

  • Company context (name, website, description)
  • Existing core business assets already in the workspace
  • Asset names and brief notes you enter in the wizard



🏗️ Create asset, and identify risks & controls wizard


This wizard walks you through company context, asset details, controls, risks, mitigation planning, and a summary before the asset is created.


AI is optional throughout. Every step can be completed manually — linking controls, adding risks, and writing descriptions yourself. AI speeds up the work when it is enabled.


You can skip risk evaluation on the first screen when it is not needed for a given asset.


Step 1 — Asset details


  • Expand with AI — Turn a short asset name and brief notes into a fuller, structured description.



  • Identify supporting assets — Suggest supporting assets from your workspace catalogue and propose new ones where gaps exist.



Data used

  • Company context
  • Asset name and draft description you enter
  • Existing workspace assets (for supporting-asset suggestions)


Step 2 — Existing controls


  • Identify controls — Review your workspace control catalogue and compliance frameworks, then suggest controls that apply to this new asset. You choose what to keep, adjust implementation levels, and link or remove items.



Data used

  • Company context
  • Asset name and description
  • Existing workspace controls (register controls)
  • Selected compliance frameworks and their requirements
  • Control implementation levels in your catalogue


Step 3 — Risk assessment


  • Identify risks — Analyse linked controls and their implementation level to identify compliance risks, link to existing workspace risks, and surface new risks from your risk register. Suggestions are grouped so compliance-related gaps are easy to spot first.



Data used

  • Company context
  • Asset name and description
  • Controls linked in the previous step (and their implementation levels)
  • Existing workspace risks
  • Risk register entries
  • Risk type / methodology configuration


Step 4 — Missing controls and mitigation plan


  • Identify missing controls — Find controls from your catalogue that should be in place but are not yet linked.



  • Suggest additional controls — After the first pass, ask for further suggestions beyond the initial set.



  • Autocomplete mitigation plan — Draft or refine the mitigation plan from your risk treatment template, linked controls, identified risks, and missing controls.



Data used

  • Company context
  • Asset name and description
  • Identified risks (existing, register, and newly suggested)
  • Linked and missing controls
  • Risk type template for mitigation planning
  • Register controls from your full workspace catalogue


After AI has run on a step, you can still edit everything manually before creation or linking.



📊 Conduct risk assessment on assets wizard


This wizard guides you through a combined risk assessment for one or more existing assets you select. Based on the risk type and framework you choose, it reuses linked controls and risks to propose missing risks and controls, then helps you build a shared mitigation plan.


  • Define the risk type (methodology, measures, …), the assets to include, and the framework for the mitigation plan.



  • Identify existing risks, register risks, and new risks across the selected assets — and choose which assets each risk applies to.



  • Identify missing controls and assign them to the relevant assets.



  • Optionally auto-generate a mitigation plan document that brings together everything selected during the wizard.



Data used

  • Company context
  • Selected asset names and descriptions
  • Controls already linked to each selected asset (and implementation levels)
  • Risks already linked to each selected asset
  • Existing workspace risks and risk register entries
  • Risk type configuration and mitigation template
  • Applicable compliance framework requirements



📄 On documents


✏️ Document content (edit and create)


While editing a document in the simple editor or Markdown editor, use Edit with AI (the AI button next to Save) to improve or fill in the document body. You can work on the full document or selected text only.


When creating a new document, the same AI assist is available on the document body before you save — so you can draft policies, procedures, and descriptions from the start.



Shortcut examples include:


  • Translate (for example, into French)
  • Improve clarity and tone
  • Expand with more detail
  • Summarize
  • Fix grammar and spelling
  • Make shorter


You describe what you want, preview the result, and apply it only when you are satisfied. Nothing is saved until you choose to save the change.


Data used

  • Document title and identifier
  • Document body (full text or selected passage)
  • Document properties and metadata
  • Linked tasks and linked documents
  • Company context (when configured)



🌐 Document language translation


For multilingual documents, open the language menu on a text-based document and choose Translate to … for a language that is not yet on the document.


Brainframe uses your workspace confidential AI to produce a translation immediately in the editor. You can review the result and accept or reject it before saving — the same review-first pattern as Edit with AI.




Data used

  • Document title and body in the source language
  • Target language you select
  • Document properties relevant to the translation





🔗 Document governance tab


On documents classified as assets, risks, or controls, the Governance tab offers AI-assisted identification of related governance records — so you spend less time on manual linking.



Document type

AI can help you identify

Control

Applicable assets · Related risks

Risk

Applicable assets · Missing controls

Asset

Missing controls · Related risks


When you run an identify action, Brainframe proposes matches in a review dialog. You select the items you want, then link existing documents or create new ones. AI suggests; you decide.


Data used

  • The open document’s title, type, and body content
  • Company context
  • Workspace catalogue of assets, risks, and controls
  • Risk register entries (where relevant)
  • Controls already linked to the document (for gap analysis)



📐 In frameworks


🗺️ Control multi-framework overview (Framework Mapping)


On the multi-framework mapping view, each framework column has an Auto map action.


Use it to suggest links between your existing control documents and that framework’s requirements. Suggestions are grouped by framework category. Review each proposed link, remove any you disagree with, then apply the ones you accept in one step.





When linking a single control to requirements manually, you can also use AI suggest in the link dialog to pick matching requirement identifiers for that control.


Data used

  • Framework name and requirement titles/descriptions
  • Existing workspace control documents (titles and identifiers)
  • Existing control-to-requirement links (so duplicates are avoided)



📋 Individual compliance framework page



Auto control mapping


Use Auto control mapping in the framework header to suggest links between your control documents and this framework’s requirements.


Review suggestions by category, keep or remove individual mappings, then apply your choices in one step. Existing links are shown alongside new suggestions.




Data used

  • Framework title and all requirement titles/descriptions
  • Workspace control documents eligible for mapping
  • Controls already linked to requirements in this framework


Auto risk mapping


Use Auto risk mapping in the framework header to suggest which risk documents in your workspace should be linked to each requirement as related risks.


Brainframe proposes requirement–risk pairs in a review dialog. Remove any you disagree with, then apply the rest in one step — the same review-first pattern as control mapping.




Data used

  • Framework title and applicable requirement titles
  • Workspace risk documents (titles from your risk catalogue)
  • Risks already linked to requirements in this framework



Ask AI — chat about the framework


A question icon in the framework header opens Ask AI about [framework name] — a conversational panel grounded in your framework and everything linked to it.


Ask follow-up questions such as:


  • “Where do we define …?”
  • “Which elements need improvement …?”
  • “Describe how we …”


The AI reviews linked manual controls, automated controls, evidence, risks, and tasks, then answers with clickable references that open the relevant item in a new tab.


Scoped questions — You can narrow the conversation:


Where you start

What the AI focuses on

Framework header

The whole framework and all linked items

Category header

Controls, risks, and evidence in that category

Individual requirement

Only items linked to that requirement


Use Save conversation as document to store the full Q&A as an audit report in your current folder — useful for internal audits and evidence packs.





Data used

  • Company context
  • Framework title, categories, and requirement titles
  • Manual control documents linked to requirements (including document content)
  • Automated control checks (status, integration source such as Aikido)
  • Linked evidence documents
  • Linked risk documents (titles and risk levels)
  • Linked tasks (titles and status)
  • Prior questions and answers in the same conversation (for follow-ups)




📈 Workspace configuration: KPI register import


In Workspace Configuration, when editing a KPI register (controls or risks), you can Import from text using AI.


Paste a block of plain text (for example from a spreadsheet export or workshop notes). AI extracts individual control or risk statements, assigns them to a standard category, and adds them to the register for your review before saving.





Data used

  • The pasted text you provide
  • Standard control/risk category lists defined for KPI registers
  • Existing register entries (when you choose to replace them)




✅ How to work with AI responsibly


  1. Enable AI in workspace settings (administrators only).
  2. Complete company context when prompted — it improves wizard, document, and framework answers.
  3. Use AI where it saves time — wizards, document editing, governance linking, framework mapping, and framework Q&A all work without AI if you prefer full manual control.
  4. Always review before applying — Suggestions are starting points. Check names, rationale, and links before you save, link, or apply mappings.
  5. Keep sensitive work inside Brainframe — Use these built-in co-pilots instead of copying asset, risk, or control text into public AI tools.



📌 Summary


Area

What AI helps with

Workspace settings

Enable/disable AI; choose default confidential AI or a custom provider

Company context

Generate or expand your organisation profile used across AI features

Primary assets wizard

Propose core business services, processes, and data sets

Asset onboarding wizard

Expand descriptions, supporting assets, controls, risks, missing controls, mitigation plan

Risk assessment wizard

Assess multiple existing assets together; risks, missing controls, shared mitigation plan

Document content

Rewrite, translate, summarize, and improve body text (edit and create)

Document translation

Translate document body to another language with preview before save

Governance tab

Identify and link related assets, risks, and controls

Framework mapping (overview)

Auto-map controls to requirements per framework; AI suggest per control

Individual framework

Auto control mapping · Auto risk mapping · Ask AI Q&A (framework, category, or requirement scope) · Save Q&A as audit report

KPI register import

Parse pasted text into categorized control or risk register entries


Across all of these, the same principle applies: your GRC data is processed confidentially, you review every suggestion before it becomes part of your workspace, and each interaction is designed to strengthen — not undermine — your compliance posture.

Updated on: 15/07/2026

Was this article helpful?

Share your feedback

Cancel

Thank you!