The brick library

Every brick, in one place.

BrickGRC is modular by design. Pick the frameworks you actually need to comply with, plug into the storage and identity tooling you already run, and bring your own AI keys so prompts and data stay on your account. Below is the complete list of bricks shipped today.

Frameworks shipped today

Each framework is a self-contained brick — controls, evidence templates, audit-ready reports. Activate one or six. Pricing scales with what you actually use.

ISO 27001

All 93 Annex A controls (2022 revision), ISMS clauses 4–10, Statement of Applicability auto-generation, audit-ready exports for stage 1 and stage 2.

Read the ISO 27001 page →

SOC 2

Type I and Type II support across the five trust services criteria. Continuous-monitoring evidence, auditor-friendly exports, framework crosswalk to ISO 27001.

Read the SOC 2 page →

GDPR

Records of processing, lawful-basis tracking, data-subject-request workflow, sub-processor inventory, breach-notification timelines, DPA library.

Read the GDPR page →

NIS2

Risk management, incident reporting, supply-chain due diligence, and the cybersecurity policy obligations under the NIS2 directive.

EU AI Act

Risk-tier classification, conformity assessment, transparency obligations, post-market monitoring for AI systems under the EU AI Act.

Read the EU AI Act page →

ISO 42001 — AI governance

The AI management system standard. Policy, risk, lifecycle controls, and evidence templates aligned to ISO/IEC 42001:2023.

Read the AI governance page →

Bring your own storage

BrickGRC layers over the document infrastructure you already run. Evidence, policies and audit artifacts can stay in your environment — no forced migration into a proprietary silo.

Microsoft SharePoint

Native SharePoint Online storage backend. Documents, evidence and policies live in your existing SharePoint sites with the access controls you've already configured.

Microsoft Azure Blob

Azure Blob Storage as the document backend. Region selection and lifecycle policies remain under your control.

Amazon S3

S3-compatible storage backend. Bring your own AWS account, KMS keys, and lifecycle rules.

Google Drive

Google Workspace Drive integration for teams already standardised on Google.

Dropbox

Dropbox Business backend, with shared-folder permissions inherited.

Nextcloud

Self-hosted Nextcloud as a backend — for organisations that want EU-resident, customer-owned storage.

Identity providers and SSO

Provision users from your directory, sign in through your identity provider. No separate user management for compliance.

Microsoft Entra ID (Azure AD)

User and group sync via Microsoft Graph API. Conditional access and your existing role policies pass through.

Okta

Directory sync and SSO. Provision and de-provision compliance users alongside the rest of your stack.

Google Workspace

Workspace directory sync with group-based role mapping.

SAML 2.0

Generic SAML support — works with any compliant identity provider (Ping, OneLogin, Auth0, JumpCloud, …).

OIDC / OAuth 2.0

Generic OpenID Connect support for modern identity providers.

Your AI provider, your account, your billing

BrickGRC's AI Coach runs against the LLM key you provide. Prompts and evidence go through your provider relationship, your data-isolation rules, and your billing — never shared between tenants, never marked up.

OpenAI

GPT-4 / GPT-4o family. Custom baseURL supported, so OpenAI-compatible gateways and Azure OpenAI deployments work too.

Anthropic

Claude Sonnet, Opus, Haiku families. Bring your Anthropic API key.

Google Gemini

Gemini 2.5 Flash / Pro. Bring your Google AI Studio or Vertex AI key.

Cohere

Command and Embed model families.

Mistral

Mistral Large, Medium, Small. Open-weight models supported via Mistral's API.

Built-in trust bricks

Field-level audit log

Every change — who, what, when, before/after — is captured at field level for every entity. Immutable trail for the auditor and the regulator.

Encrypted credentials at rest

Integration credentials (storage backends, AI keys, identity providers) are encrypted before persistence. Operators cannot read them in cleartext.

Per-tenant isolation

Your AI prompts, evidence, and policies are scoped to your tenant. No cross-customer model training. No shared embedding indexes.

Pick the bricks that fit. Skip the ones that don't.

A 15-minute demo is the fastest way to see how the bricks combine for your stack — your frameworks, your storage, your identity provider, your AI keys.