Compliance, audits and evidence
Pulsar GRC helps describe risks, assign tasks, collect evidence and keep corrective actions on track.
Product pageCompliance
Pulsar GRC and Zmianowo organise two common compliance areas: controls, risks and evidence — and training, tests and confirmed completion.
Products
Compliance is not one screen. In practice it needs separate flows for audits, evidence, training and competence.
Pulsar GRC helps describe risks, assign tasks, collect evidence and keep corrective actions on track.
Product pageZmianowo supports training, tests and completion records when an organisation needs a record that the team has been through the required procedures. A completion record does not replace a certificate or any qualification awarded by an accredited body.
Product pageStandard
The scope of data should follow from the purpose of the process, and access must be limited to the roles that need it.
AI features require explicit context, a checked result and a clear place for the human decision.
Key statuses, approvals and changes should be reconstructable without stitching history together by hand.
Evidence for the customer
During the onboarding conversation we go through the documents needed to assess the supplier. We do not publish operational parameters before the service scope is confirmed.
On request we provide a template data processing agreement and the list of providers that may take part in delivering the service.
The hosting, backup and disaster recovery model is confirmed per deployment and written into the cooperation documents.
The security management system is maintained as a process. Certification is not an active public offer; the document scope is confirmed after qualification.
Maintenance
Maintenance covers support, hosting, backups, security procedures and a development plan. The scope is confirmed at onboarding; responsibility for how the process is used stays with the customer.
The customer gets an agreed contact channel for operational questions, reports and decisions about further development.
Before launch we discuss access, roles, personal data, exports and how incidents are handled.
The customer decides process owners, rules of use and how the team works. Brillnet supports configuration and the first scenarios.
Sources and limits of our claims
The primary legal sources are the official texts of the GDPR and the AI Act. The scope of obligations depends on the organisation's role, the process and the deployment. A product can support evidence gathering and control of the work — it does not replace legal analysis or the process owner's decision.