Skip to content

Platform Features and Overview

Last updated: August 20, 2026

What Briard-AI does

Briard-AI helps an organization find its AI tools, make clear decisions about how each tool may be used, and keep proof of the work. A user does not need prior AI-governance knowledge. The guided path explains one choice at a time while Briard keeps the detailed governance record needed by authorized reviewers.

For small and mid-market regulated organizations and their advisors, it helps a team:

  1. inventory AI systems;
  2. document owners, intended use, hosting, data classes, and boundary decisions;
  3. answer plain-language governance questions mapped to framework controls;
  4. distinguish an attestation from evidence-backed support;
  5. attach approved evidence to the answer it supports;
  6. record internal reviews and testing activity;
  7. generate deterministic, reviewable artifact packages; and
  8. preserve integrity references in an organization-scoped ledger.

The platform is a documentation system. It does not replace security engineering, legal analysis, an assessor, a C3PAO, or a regulator.

Core workflow

Register a system -> Answer mapped questions -> Attach evidence -> Review readiness -> Record reviews/tests -> Generate artifacts -> Verify ledger references

Each step reuses the same system record and evidence references so teams do not have to recreate the same facts for every questionnaire or review package.

Workspace features

Dashboard and guided training

  • Shows registered systems, current documentation and evidence posture, recent artifacts, and recommended next steps.
  • Provides guided training for system registration, mapped questions, evidence upload, and artifact generation.

AI system registry

Each record captures:

  • system name and vendor;
  • optional model family;
  • accountable business and technical owner;
  • a plain environment name so separate networks, enclaves, labs, or customer environments do not get mixed together;
  • hosting environment;
  • inside-boundary, outside-boundary, prohibited-from-CUI, unknown, or not-applicable designation;
  • permitted data classes;
  • applicable framework packs; and
  • a minimum 200-character purpose statement describing users, inputs, outputs, decision role, prohibited data, and required human review.

The registry rejects regulated-data-like content in descriptive fields. Record the governing facts and references, not the regulated payload itself.

Mapped questions and findings

  • Questions are presented in plain language and mapped to versioned framework controls.
  • Saved answers are organization- and system-scoped.
  • Documentation coverage and evidence coverage are displayed separately.
  • Deterministic rules surface potential gaps such as an unsupported boundary decision or missing BAA evidence.
  • Findings are prompts for review and remediation, not legal or certification determinations.

Private evidence workflow

  • Evidence is attached to a specific saved answer.
  • Supported files are PDF, CSV, XLS, XLSX, DOC, DOCX, PNG, JPG, and JPEG, up to 25 MB.
  • The client calculates SHA-256; the server verifies file size and hash.
  • Files are written to private object storage, scanned for malware and active content, and sealed under a content-addressed key only after checks pass.
  • Failed, mismatched, or quarantined files are unavailable for use.
  • HTTPS references can be used where the workflow accepts a reference instead of a file.

Only upload approved, non-regulated evidence. Private storage is not permission to upload CUI, PHI, secrets, customer production data, or prohibited content.

NIST AI RMF and Texas AI readiness

Texas has two distinct regimes in this workflow. TRAIGA does not create a general affirmative AI inventory duty. Final 1 TAC Chapter 219 separately requires each Texas state agency and local government to designate an AI Risk Officer and establish a process to identify and inventory all heightened-scrutiny AI implementations.

For systems with the TRAIGA pack, Briard-AI can:

  • map answers across NIST AI RMF functions GOVERN, MAP, MEASURE, and MANAGE;
  • include sourced mappings to NIST AI RMF 1.0, the NIST Generative AI Profile, relevant TRAIGA review routes, and final 1 TAC Chapter 219 public-sector controls;
  • maintain eight separate, tenant-scoped records for every documentation category in Texas Business and Commerce Code Section 552.103(b);
  • show evidenced, partially evidenced, attested, gap, and not-assessed states;
  • append internal-review and internal-testing records; and
  • generate a TRAIGA Cure Binder with the eight-record Texas spreadsheet and structured JSON, registry snapshot, readiness assessment, evidence index, review history, testing log, source references, legal notice, and hash manifest.

For Texas state agencies and local governments, Briard-AI also provides plain-language records for the AI Risk Officer, heightened-scrutiny inventory and classification, written risk assessment, acceptable-use controls, training, and covered vendor-contract framework terms. Chapter 219 took effect March 18, 2026. DIR declined a requested additional 90-day implementation period and declined to provide inventory or assessment forms, a statewide AI Governance Repository, or a managed shared platform for small entities and local governments. DIR's public resources currently include the code of ethics, standardized notice, and an acceptable-use-policy example, but no inventory or risk-assessment template.

The Texas Government AI Risk Record fills that operational recordkeeping gap. It is support material, not an official DIR form or a legal or applicability determination.

The workflow always returns a non-legal posture. A mapping or complete-looking package does not establish substantial compliance, safe-harbor eligibility, an affirmative defense, or a legal outcome. Counsel review remains required.

Evidence packages

Available artifact templates include:

  • AI Acceptable Use Policy;
  • Purpose and Intent Record;
  • AI System Registry Export;
  • NIST AI RMF Alignment Report;
  • Internal Testing Log;
  • TRAIGA Cure Binder;
  • Texas Government AI Risk Record;
  • Defense AI Use and Boundary Record (voluntary; not a CMMC-required artifact);
  • POA&M Line Items;
  • Prime Questionnaire Pack;
  • HIPAA Vendor and BAA Register;
  • Vendor AI Questionnaire;
  • Executive Posture One-Pager;
  • Cyber-Insurance AI Questionnaire;
  • Employee AI Acknowledgment and Training Log; and
  • AI Incident Log.

Availability depends on the active plan, selected framework pack, and artifact type. Standard artifacts are available as deterministic JSON and PDF packages. TRAIGA Cure Binders also support ZIP export with member hashes.

Tamper-evident ledger

  • Material workspace actions can append organization-scoped ledger events.
  • Events use canonical payload hashes and hash-chain links.
  • Ledger verification reports a clean chain or the first detected divergence.
  • When configured, RFC 3161 timestamps can anchor a ledger head externally.

Ledger verification shows integrity continuity. It does not prove that the underlying statement was true, complete, approved, or legally sufficient.

Account, support, and data rights

  • TOTP MFA enrollment and verification.
  • Billing plan and entitlement status.
  • Structured support requests with status history.
  • Workspace export for owners and administrators.
  • Correction and deletion request workflows subject to identity verification and ledger-retention review.

Roles and access

The workspace recognizes Owner, Admin, Contributor, and Viewer role labels. Server-side tenant checks isolate every organization. Privileged actions have additional controls:

  • The initial self-service Checkout requires the confirmed workspace owner.
  • Owner and administrator sessions must complete AAL2 MFA before accessing tenant data and privileged workflows.
  • Billing Portal access and workspace export require Owner or Admin access.
  • Cross-organization requests are denied before records or private objects are returned.

Your organization should assign the minimum role needed and promptly remove access that is no longer required.

Plans and framework packs

Current plan behavior is defined by the in-product Billing page and server-side catalog:

Each eligible organization can start with one 30-day free trial. The trial requires no payment method, includes Professional features for up to ten systems, does not renew, and cannot create an automatic charge. A verified owner separately chooses a paid plan only if the organization wants to continue after the trial.

PlanMonthly list priceTypical useAI systems includedFramework accessNotes
Solo$149/monthOne organization beginning a focused program1Core plus one selected framework packSelf-service monthly subscription; additional systems are $40 each/month
Professional$399/monthA team managing several systems and frameworks10Core, CMMC, TRAIGA, and HIPAASelf-service monthly subscription; additional systems are $40 each/month
Partner$99/client organization/monthAdvisors managing client organizations3 per client organizationCore, CMMC, TRAIGA, and HIPAASales-assisted monthly subscription; quantity and minimum billing; additional systems are $40 each/month

Paid plans do not impose a hard AI-system limit. The Billing page shows the included allowance and the monthly price change before additional paid capacity is confirmed. Prices, promotions, and availability can change. Treat the hosted Billing page and signed subscription entitlement as authoritative.

Security and data-handling model

  • Metadata-only form design with regulated-data warnings.
  • Managed authentication with organization-scoped access and TOTP MFA.
  • Database-enforced tenant isolation.
  • Private storage, integrity verification, file-safety scanning, and organization-scoped access.
  • Strict transport and browser security headers.
  • Rate limiting on public and abuse-sensitive routes.
  • Provider credentials remain server-side.
  • No generative-model API receives customer text, evidence, prompts, or artifacts in the current runtime.

See the public Security page for the customer-facing security boundary.

Current scope limitations

  • Briard-AI does not calculate an SPRS score.
  • It does not scan customer infrastructure or enforce network segmentation.
  • It does not determine whether a cloud service is authorized for a particular regulated workload.
  • Microsoft tenant connector contracts exist, but live use depends on customer-controlled Entra tenant registration and admin consent.
  • Generated or templated material requires human review before external use.
  • A complete workflow does not equal certification, compliance, or legal protection.

Back to Client Documentation

Briard-AI and KAIDAN are products of Unfettered Minds LLC. Governance documentation and review support. Not legal advice or certification.