The brick library

Every brick, in one place.

BrickGRC is modular by design. Pick the frameworks you actually need to comply with, plug into the storage and identity tooling you already run, and bring your own AI keys so prompts and data stay on your account. Below is the complete list of bricks shipped today.

Frameworks shipped today

Each framework is a self-contained brick, controls, evidence templates, audit-ready reports. €100/mo per brick on the Modular plan. Free during the 30-day trial, the Design Partner cohort, and on Enterprise.

ISO 27001 +€100/mo on Modular

All 93 Annex A controls (2022 revision), ISMS clauses 4–10, Statement of Applicability auto-generation, audit-ready exports for stage 1 and stage 2.

Read the ISO 27001 page →

SOC 2 +€100/mo on Modular

Type I and Type II support across the five trust services criteria. Continuous-monitoring evidence, auditor-friendly exports, framework crosswalk to ISO 27001.

Read the SOC 2 page →

GDPR +€100/mo on Modular

Records of processing, lawful-basis tracking, data-subject-request workflow, sub-processor inventory, breach-notification timelines, DPA library.

Read the GDPR page →

NIS2 Coming soon

Risk management, incident reporting, supply-chain due diligence, and the cybersecurity policy obligations under the NIS2 directive.

EU AI Act +€100/mo on Modular

Risk-tier classification, conformity assessment, transparency obligations, post-market monitoring for AI systems under the EU AI Act.

Read the EU AI Act page →

ISO 42001, AI governance +€100/mo on Modular

The AI management system standard. Policy, risk, lifecycle controls, and evidence templates aligned to ISO/IEC 42001:2023.

Read the AI governance page →

NIST AI RMF +€100/mo on Modular

The NIST AI Risk Management Framework, Govern, Map, Measure, Manage. Crosswalk to the EU AI Act and ISO 42001, with evidence templates for each function.

Bring your own storage

BrickGRC layers over the document infrastructure you already run. Evidence, policies and audit artifacts can stay in your environment, no forced migration into a proprietary silo. Always free, included on every plan.

Microsoft SharePoint

Native SharePoint Online storage backend. Documents, evidence and policies live in your existing SharePoint sites with the access controls you've already configured.

Microsoft Azure Blob

Azure Blob Storage as the document backend. Region selection and lifecycle policies remain under your control.

Amazon S3

S3-compatible storage backend. Bring your own AWS account, KMS keys, and lifecycle rules.

Google Drive

Google Workspace Drive integration for teams already standardised on Google.

Dropbox

Dropbox Business backend, with shared-folder permissions inherited.

Nextcloud

Self-hosted Nextcloud as a backend, for organisations that want EU-resident, customer-owned storage.

One sign-in story. One source of truth.

Provision users from your existing directory or HR system. Sign in through SAML, OIDC, or social login. No separate user management just for compliance. Always free, included on every plan.

SAML 2.0

Generic SAML 2.0 support, works with any compliant identity provider (Okta, Auth0, OneLogin, Ping, Keycloak, JumpCloud, ADFS …). Org-wide enforcement and JIT provisioning.

OIDC / OAuth 2.0

Generic OpenID Connect support for modern identity providers. Bring any issuer URL plus client credentials.

Google sign-in

One-click Google OAuth login for individual users. Useful for fast onboarding before the org-wide SSO rollout.

Microsoft sign-in

One-click Microsoft OAuth login for individual users, work or personal Microsoft accounts.

Microsoft Entra ID (Azure AD)

User and group sync via Microsoft Graph API. Conditional access and your existing role policies pass through.

Okta

Directory sync and SSO. Provision and de-provision compliance users alongside the rest of your stack.

Google Workspace

Workspace directory sync with group-based role mapping.

SCIM 2.0

Generic SCIM 2.0 endpoint, provision and de-provision users from any IdP that speaks SCIM. Bearer-token auth, configurable sync interval.

JumpCloud

JumpCloud directory sync with org-ID scoping for multi-tenant API keys.

BambooHR

Sync employees, departments, and job titles from BambooHR, the HR system becomes the source of truth for who gets compliance access.

Workday

Workday HCM directory sync via REST API. OAuth 2.0 with tenant-scoped client credentials.

Rippling

Rippling employee directory sync, keeps the compliance tenant aligned with your live employee roster.

Reach your team where they already work

Compliance deadlines, workflow updates, and engagement alerts land in the inbox or channel your team already watches, no separate compliance app to babysit. Always free, included on every plan.

Email (SMTP)

Bring your own SMTP, Gmail, Office 365, SendGrid, Postmark, any compliant server. STARTTLS or SSL/TLS, your sender address, your deliverability story.

Slack

Push compliance alerts and workflow notifications into any Slack channel via Incoming Webhooks.

Microsoft Teams

Native Microsoft Teams Incoming Webhook integration, compliance updates surface in the same channels your engineering and security teams already use.

Plug into the workflow you already run

Compliance work isn't a side-quest. Push remediation tickets into your issue tracker, sync audit milestones to the team calendar, fan out events to anything you can hit with a webhook. Always free, included on every plan.

Jira

Create remediation tickets and link evidence directly from BrickGRC controls. Atlassian Cloud or Server, scoped to your default project.

Azure DevOps

Push work items to Azure Boards from compliance findings. Personal Access Token auth, configurable default project.

Google Calendar

Sync audit milestones, review cycles, and renewal deadlines to a Google Calendar your team already watches.

Outlook Calendar

Microsoft 365 Calendar integration, compliance dates land alongside everything else on your team's schedule.

Generic webhook

Fan out any BrickGRC event to any HTTP endpoint. Sign payloads with a shared secret, choose your HTTP method, route into your own automation.

Your AI provider, your account, your billing

BrickGRC's AI Coach runs against the LLM key you provide. Prompts and evidence go through your provider relationship, your data-isolation rules, and your billing, never shared between tenants, never marked up. Always free, included on every plan.

OpenAI

GPT-4 / GPT-4o family. Custom baseURL supported, so OpenAI-compatible gateways and Azure OpenAI deployments work too.

Anthropic

Claude Sonnet, Opus, Haiku families. Bring your Anthropic API key.

Google Gemini

Gemini 2.5 Flash / Pro. Bring your Google AI Studio or Vertex AI key.

Cohere

Command and Embed model families.

Mistral

Mistral Large, Medium, Small. Open-weight models supported via Mistral's API.

Built-in trust bricks

Field-level audit log

Every change, who, what, when, before/after, is captured at field level for every entity. Immutable trail for the auditor and the regulator.

Encrypted credentials at rest

Integration credentials (storage backends, AI keys, identity providers) are encrypted before persistence. Operators cannot read them in cleartext.

Per-tenant isolation

Your AI prompts, evidence, and policies are scoped to your tenant. No cross-customer model training. No shared embedding indexes.

Pick the bricks that fit. Skip the ones that don't.

A 15-minute demo is the fastest way to see how the bricks combine for your stack, your frameworks, your storage, your identity provider, your AI keys.