Compliance

Compliance should be visible in daily work, not just in a binder.

Pulsar GRC and Zmianowo organise two common compliance areas: controls, risks and evidence — and training, tests and confirmed completion.

People analysing documents and responsibility boundaries

Products

Two products, two areas of responsibility

Compliance is not one screen. In practice it needs separate flows for audits, evidence, training and competence.

Pulsar GRC

Compliance, audits and evidence

Pulsar GRC helps describe risks, assign tasks, collect evidence and keep corrective actions on track.

Product page
Zmianowo

Training with confirmed completion

Zmianowo supports training, tests and completion records when an organisation needs a record that the team has been through the required procedures. A completion record does not replace a certificate or any qualification awarded by an accredited body.

Product page

Standard

Mechanisms that support compliance

GDPR

Personal data

The scope of data should follow from the purpose of the process, and access must be limited to the roles that need it.

AI

AI with oversight

AI features require explicit context, a checked result and a clear place for the human decision.

Evidence

History and documentation

Key statuses, approvals and changes should be reconstructable without stitching history together by hand.

Evidence for the customer

A security and compliance pack available on request

During the onboarding conversation we go through the documents needed to assess the supplier. We do not publish operational parameters before the service scope is confirmed.

Data

Data processing agreement and sub-processors

On request we provide a template data processing agreement and the list of providers that may take part in delivering the service.

Operations

Hosting, backups and recovery

The hosting, backup and disaster recovery model is confirmed per deployment and written into the cooperation documents.

System

Management system status

The security management system is maintained as a process. Certification is not an active public offer; the document scope is confirmed after qualification.

Public documents and the limits we place on AI are described in the Trust and data section.

Maintenance

How the product is maintained

Maintenance covers support, hosting, backups, security procedures and a development plan. The scope is confirmed at onboarding; responsibility for how the process is used stays with the customer.

Support

Support after launch

The customer gets an agreed contact channel for operational questions, reports and decisions about further development.

Procedures

Security and incidents

Before launch we discuss access, roles, personal data, exports and how incidents are handled.

Deployment

Customer responsibility

The customer decides process owners, rules of use and how the team works. Brillnet supports configuration and the first scenarios.

Sources and limits of our claims

Regulations are a reference point, not an automatic promise of compliance.

The primary legal sources are the official texts of the GDPR and the AI Act. The scope of obligations depends on the organisation's role, the process and the deployment. A product can support evidence gathering and control of the work — it does not replace legal analysis or the process owner's decision.