Controls and evidence
Compliance remains your decision. The evidence should not have to be reconstructed.
GAIA Brain is designed to enforce configured controls and retain technical evidence from the running transaction. It does not certify a customer, determine lawful basis or replace professional judgment.
What the design can support
A reviewable route from user and source to human decision.
Customer-controlled deployment
The proposed deployment runs in infrastructure controlled by the customer or its approved implementation partner. That gives the customer operational control and responsibility; it is not automatically an EU-residency or compliance conclusion.
Configured protected-value egress
The built mechanism can substitute supported protected values before an external call and restore valid surrogates locally. The feature is default-off pending witnessed activation. Residual context can still be personal or confidential, so external-provider analysis remains necessary.
Clearance-aware knowledge
Retrieval paths carry user and source scope so the model context can be restricted before generation. The customer must validate identity groups, source permissions and every relevant retrieval/export path.
Provider and exit visibility
Local and external models sit behind a registry/router. This can reduce hidden point-to-point integrations, but every provider, fallback and customer-hosted component still belongs in ICT-risk and exit planning.
Technical evidence from execution
Hash-chained events, memory-audit records and DPIA/RoPA/export endpoints can document configured behaviour. Tamper-evident is not immutable; administration, checkpoints, retention and restore remain part of the deployment.
Domain control mapping
A sector layer can link approved sources, obligations, policies, controls, owners, evidence, review and exceptions for a bounded workflow. The legal interpretation and final control design remain with the customer and its advisers.
Accessibility
The public site targets Level AA accessibility.
This site targets Level AA of WCAG 2.1 and 2.2. That is a build target, not a certification. Accessibility testing and remediation continue as the site changes.
Current boundary
What we do not claim.
As assessed on 10 October 2026, the source is just short of MVP, with a large internal test harness and a healthy operator-hosted development instance. There is no official customer deployment, general availability, external security certification or regulator endorsement.
The main protected-egress flags remain default-off. Detection of special-category data (GDPR Article 9) in free text is switched on separately. Key material is sealed to the host’s TPM and backups are encrypted before they leave the host. The development installation runs on an encrypted disk; on a pilot, disk encryption is set up and verified on the customer’s infrastructure. The final pilot configuration still requires customer-hosted deployment, witnessed gates and representative acceptance tests.
Using GAIA Brain does not make an organisation compliant. It can provide configured controls and technical evidence that support the organisation’s own GDPR, DORA, AI Act and sector-governance work.