> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://docs.brainframe.com/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# Confidential AI in Brainframe

# 🤖 **Brainframe Confidential AI**

${youtube}[Brainframe Confidential AI explained](fUAElo_7JTM)

Brainframe’s AI co-pilots help you work faster on assets, risks, controls, policies, and compliance mapping — without sending sensitive material to a public AI service that could read or retain it.

Use them in **wizards**, **document editors**, **governance linking**, **framework mapping**, and **framework Q&A** — always with your review before anything is saved.

---

## 🔒 Why your data stays private

Brainframe’s AI features are built on **Trusted Execution Environment (TEE)** confidential computing, powered by **Tresor AI** — a European confidential-AI provider designed for governance, risk, and compliance work.

Unlike pasting content into ChatGPT, Copilot, or similar tools, your asset descriptions, risk registers, control documentation, and policy text are handled with a **zero-access architecture**:

* **Encrypted end to end** — Content is encrypted on the way in, processed only inside a sealed environment by the supplier that they are unable to access. Readable text exists only in your Brainframe workspace.
* **Processed where no one can look** — AI runs inside hardware-sealed enclaves. Neither the AI provider nor the underlying cloud operator can read these prompts or responses. This is enforced by hardware, not by policy alone.
* **Proven on every answer** — Each AI response carries a cryptographic verification receipt showing that your request was handled inside attested, sealed hardware. That turns “we use a secure provider” into evidence you can use in audits, due diligence, and regulatory reviews.

In one line: **You get modern AI productivity on your most confidential GRC work — with a hardware-backed guarantee that our providers cannot read it, and proof that supports your compliance posture.**

> Brainframe AI is powered by Tresor AI confidential compute. Learn more at the [Tresor AI trust and documentation pages](https://tresor.ai/).

---

## ⚙️ Before you start: Workspace settings

Workspace administrators control whether AI is available at all.

**Where to find it:** Workspace Configuration → **Integrations → Artificial intelligence**.

![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_1caas2q.png)

| Setting | What it means |
| ---- |
| **Enable AI features** | Turns AI on or off for the entire workspace. When disabled, AI buttons are hidden or unavailable for all users. |
| **Default Brainframe AI** | Uses Brainframe’s managed confidential AI (Tresor AI). Recommended for most workspaces. |
| **Custom provider** | Optional: connect your organisation’s own OpenAI-compatible endpoint if you have a specific requirement to use a different provider. |

Only workspace administrators can change these settings. When AI is disabled, users see a message that an administrator must enable it first on AI buttons.

---

## 🏢 Company context (shared across AI features)

Many AI features work better when Brainframe knows **who your organisation is**. Company context is collected once and reused across wizards, document AI, and framework Q&A.

Typical fields include your organisation’s **short name**, **website**, and a **description** of what the company does. You can fill this in manually or use **Generate with AI** / **Expand with AI** to draft a fuller description from a short note.

The first time you use **document AI assist** and company details are still empty, Brainframe prompts you to complete this screen — the same flow used in the asset wizards.


![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_2q43wy.png)
**Data used**
* Company short name, website URL (and crawled data from homepage), organisation description
* Workspace variables configured for your organisation profile

---

# 🪄 Wizards

Wizards are designed to save time. Confidential AI receives the **full GRC context** of your workspace so suggestions are relevant to your controls, risks, frameworks, and assets — not generic checklists.

![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_b9qr2v.png)

**Launch from:** **My Compliance**, relevant **table views** (assets, core business assets), or the **risk matrix** (risk assessment wizard).

---

## 📦 Identify and document primary assets wizard

This wizard helps you identify and document your organisation’s **core business assets** — the services, processes, and data sets that underpin your management system.

Add assets manually, or let AI **propose** core services, processes, and important data sets from your company context, then create them in one step.

![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_12kh19d.png)

**Data used**
* Company context (name, website, description)
* Existing core business assets already in the workspace
* Asset names and brief notes you enter in the wizard

---

## 🏗️ Create asset, and identify risks & controls wizard

This wizard walks you through company context, asset details, controls, risks, mitigation planning, and a summary before the asset is created.

AI is optional throughout. Every step can be completed manually — linking controls, adding risks, and writing descriptions yourself. AI speeds up the work when it is enabled.

You can **skip risk evaluation** on the first screen when it is not needed for a given asset.

### Step 1 — Asset details

* **Expand with AI** — Turn a short asset name and brief notes into a fuller, structured description.

![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_1sv6naw.png)

* **Identify supporting assets** — Suggest supporting assets from your workspace catalogue and propose new ones where gaps exist.

![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_10cwmd0.png)

**Data used**
* Company context
* Asset name and draft description you enter
* Existing workspace assets (for supporting-asset suggestions)

### Step 2 — Existing controls

* **Identify controls** — Review your workspace control catalogue and compliance frameworks, then suggest controls that apply to this new asset. You choose what to keep, adjust implementation levels, and link or remove items.

![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_1h795yr.png)

**Data used**
* Company context
* Asset name and description
* Existing workspace controls (register controls)
* Selected compliance frameworks and their requirements
* Control implementation levels in your catalogue

### Step 3 — Risk assessment

* **Identify risks** — Analyse linked controls and their implementation level to identify compliance risks, link to existing workspace risks, and surface new risks from your risk register. Suggestions are grouped so compliance-related gaps are easy to spot first.

![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_1c9df3n.png)

**Data used**
* Company context
* Asset name and description
* Controls linked in the previous step (and their implementation levels)
* Existing workspace risks
* Risk register entries
* Risk type / methodology configuration

### Step 4 — Missing controls and mitigation plan

* **Identify missing controls** — Find controls from your catalogue that should be in place but are not yet linked.

![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_gnyn0o.png)

* **Suggest additional controls** — After the first pass, ask for further suggestions beyond the initial set.

![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_1js2iop.png)

* **Autocomplete mitigation plan** — Draft or refine the mitigation plan from your risk treatment template, linked controls, identified risks, and missing controls.

![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_2sswgo.png)

**Data used**
* Company context
* Asset name and description
* Identified risks (existing, register, and newly suggested)
* Linked and missing controls
* Risk type template for mitigation planning
* Register controls from your full workspace catalogue

After AI has run on a step, you can still edit everything manually before creation or linking.

---

## 📊 Conduct risk assessment on assets wizard

This wizard guides you through a **combined risk assessment** for one or more **existing assets** you select. Based on the risk type and framework you choose, it reuses linked controls and risks to propose missing risks and controls, then helps you build a shared mitigation plan.

* Define the **risk type** (methodology, measures, …), the **assets** to include, and the **framework** for the mitigation plan.

![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_f1i0dc.png)

* Identify **existing risks**, **register risks**, and **new risks** across the selected assets — and choose which assets each risk applies to.

![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_1yfkfh8.png)

* Identify **missing controls** and assign them to the relevant assets.

![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_1un5qqa.png)

* Optionally **auto-generate a mitigation plan** document that brings together everything selected during the wizard.

![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_2sswgo.png)

**Data used**
* Company context
* Selected asset names and descriptions
* Controls already linked to each selected asset (and implementation levels)
* Risks already linked to each selected asset
* Existing workspace risks and risk register entries
* Risk type configuration and mitigation template
* Applicable compliance framework requirements

---

# 📄 On documents

## ✏️ Document content (edit and create)

While **editing** a document in the **simple editor** or **Markdown editor**, use **Edit with AI** (the **AI** button next to **Save**) to improve or fill in the document body. You can work on the **full document** or **selected text only**.

When **creating** a new document, the same AI assist is available on the document body before you save — so you can draft policies, procedures, and descriptions from the start.

![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_bsqc6q.png)

Shortcut examples include:

* Translate (for example, into French)
* Improve clarity and tone
* Expand with more detail
* Summarize
* Fix grammar and spelling
* Make shorter

You describe what you want, preview the result, and apply it only when you are satisfied. Nothing is saved until you choose to save the change.

**Data used**
* Document title and identifier
* Document body (full text or selected passage)
* Document properties and metadata
* Linked tasks and linked documents
* Company context (when configured)

---

## 🌐 Document language translation

For multilingual documents, open the **language menu** on a text-based document and choose **Translate to …** for a language that is not yet on the document.

Brainframe uses your workspace confidential AI to produce a translation **immediately in the editor**. You can review the result and accept or reject it before saving — the same review-first pattern as **Edit with AI**.

![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_1ebdfxu.png)


**Data used**
* Document title and body in the source language
* Target language you select
* Document properties relevant to the translation



---

## 🔗 Document governance tab

On documents classified as **assets**, **risks**, or **controls**, the **Governance** tab offers AI-assisted identification of related governance records — so you spend less time on manual linking.

![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_d08w16.png)

| Document type | AI can help you identify |
| ---- |
| **Control** | Applicable assets · Related risks |
| **Risk** | Applicable assets · Missing controls |
| **Asset** | Missing controls · Related risks |

When you run an identify action, Brainframe proposes matches in a **review dialog**. You select the items you want, then link existing documents or create new ones. AI suggests; you decide.

**Data used**
* The open document’s title, type, and body content
* Company context
* Workspace catalogue of assets, risks, and controls
* Risk register entries (where relevant)
* Controls already linked to the document (for gap analysis)

---

# 📐 In frameworks

## 🗺️ Control multi-framework overview (Framework Mapping)

On the **multi-framework mapping** view, each framework column has an **Auto map** action.

Use it to suggest links between your existing **control documents** and that framework’s **requirements**. Suggestions are grouped by framework category. Review each proposed link, remove any you disagree with, then apply the ones you accept in one step.

![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_1onz2a8.png)

![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_10d470e.png)

![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_147n0cx.png)

When linking a single control to requirements manually, you can also use **AI suggest** in the link dialog to pick matching requirement identifiers for that control.

**Data used**
* Framework name and requirement titles/descriptions
* Existing workspace control documents (titles and identifiers)
* Existing control-to-requirement links (so duplicates are avoided)

---

## 📋 Individual compliance framework page


![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_150u4bj.png)
### Auto control mapping

Use **Auto control mapping** in the framework header to suggest links between your **control documents** and **this framework’s requirements**.

Review suggestions by category, keep or remove individual mappings, then apply your choices in one step. Existing links are shown alongside new suggestions.


![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_147n0cx.png)

**Data used**
* Framework title and all requirement titles/descriptions
* Workspace control documents eligible for mapping
* Controls already linked to requirements in this framework

### Auto risk mapping

Use **Auto risk mapping** in the framework header to suggest which **risk documents** in your workspace should be linked to each **requirement** as related risks.

Brainframe proposes requirement–risk pairs in a review dialog. Remove any you disagree with, then apply the rest in one step — the same review-first pattern as control mapping.

![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_qppvk1.png)


**Data used**
* Framework title and applicable requirement titles
* Workspace risk documents (titles from your risk catalogue)
* Risks already linked to requirements in this framework


### Ask AI — chat about the framework

A **question icon** in the framework header opens **Ask AI about [framework name]** — a conversational panel grounded in your framework and everything linked to it.

Ask follow-up questions such as:

* “Where do we define …?”
* “Which elements need improvement …?”
* “Describe how we …”

The AI reviews linked **manual controls**, **automated controls**, **evidence**, **risks**, and **tasks**, then answers with **clickable references** that open the relevant item in a new tab.

**Scoped questions** — You can narrow the conversation:

| Where you start | What the AI focuses on |
| ---- |
| **Framework header** | The whole framework and all linked items |
| **Category header** | Controls, risks, and evidence in that category |
| **Individual requirement** | Only items linked to that requirement |

Use **Save conversation as document** to store the full Q&A as an **audit report** in your current folder — useful for internal audits and evidence packs.

![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_1me6919.png)

![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_zkb16.png)


**Data used**
* Company context
* Framework title, categories, and requirement titles
* Manual control documents linked to requirements (including document content)
* Automated control checks (status, integration source such as Aikido)
* Linked evidence documents
* Linked risk documents (titles and risk levels)
* Linked tasks (titles and status)
* Prior questions and answers in the same conversation (for follow-ups)


---

# 📈 Workspace configuration: KPI register import

In **Workspace Configuration**, when editing a **KPI register** (controls or risks), you can **Import from text** using AI.

Paste a block of plain text (for example from a spreadsheet export or workshop notes). AI extracts individual control or risk statements, assigns them to a standard category, and adds them to the register for your review before saving.

![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_11w2ofg.png)
![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_1jhid52.png)

![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_1936uwn.png)


**Data used**
* The pasted text you provide
* Standard control/risk category lists defined for KPI registers
* Existing register entries (when you choose to replace them)


---

## ✅ How to work with AI responsibly

1. **Enable AI in workspace settings** (administrators only).
2. **Complete company context** when prompted — it improves wizard, document, and framework answers.
3. **Use AI where it saves time** — wizards, document editing, governance linking, framework mapping, and framework Q&A all work without AI if you prefer full manual control.
4. **Always review before applying** — Suggestions are starting points. Check names, rationale, and links before you save, link, or apply mappings.
5. **Keep sensitive work inside Brainframe** — Use these built-in co-pilots instead of copying asset, risk, or control text into public AI tools.

---

## 📌 Summary

| Area | What AI helps with |
| ---- |
| **Workspace settings** | Enable/disable AI; choose default confidential AI or a custom provider |
| **Company context** | Generate or expand your organisation profile used across AI features |
| **Primary assets wizard** | Propose core business services, processes, and data sets |
| **Asset onboarding wizard** | Expand descriptions, supporting assets, controls, risks, missing controls, mitigation plan |
| **Risk assessment wizard** | Assess multiple existing assets together; risks, missing controls, shared mitigation plan |
| **Document content** | Rewrite, translate, summarize, and improve body text (edit and create) |
| **Document translation** | Translate document body to another language with preview before save |
| **Governance tab** | Identify and link related assets, risks, and controls |
| **Framework mapping (overview)** | Auto-map controls to requirements per framework; AI suggest per control |
| **Individual framework** | Auto control mapping · Auto risk mapping · Ask AI Q&A (framework, category, or requirement scope) · Save Q&A as audit report |
| **KPI register import** | Parse pasted text into categorized control or risk register entries |

Across all of these, the same principle applies: **your GRC data is processed confidentially**, you **review every suggestion** before it becomes part of your workspace, and each interaction is designed to strengthen — not undermine — your compliance posture.
