Dutch by design. Your data stays yours.
A Dutch company, EU law, and a Privacy Shield that strips names, email addresses and personal context before a single token reaches an AI model.
Bramm · EU cloud
Real values stay here
AI model
Sees only tokens
Built on EU law.
A Dutch entity, subject to EU law and European jurisdiction. Built to help organisations achieve and maintain ISO 27001 certification.
EU stack, top to bottom.
Storage, backups, vector indices, support — all in EU data centres operated by EU entities. Run by a team in the Netherlands.
Verifiable, not promised.
Open the audit log and see exactly what was redacted, what was sent and what came back. Every prompt, inspectable.
Others promise they won't train on your data.
Bramm makes sure the model never sees it.
Names become tokens.
Sarah de Vries becomes PERSON_007 before leaving your platform. The model reasons about tokens. Bramm puts the real names back inside your tenant.
Retrieved context, too.
Policy paragraphs and ticket history are pseudonymised with the same map. No context leak.
Free-text PII, caught by pattern.
BSN, IBAN, phone numbers, emails, postcodes, credit cards — redacted before send. Validated, counted, never stored.
Every answer carries a "Show what was sent to the AI" button. The ISO can inspect the exact redacted prompt the model received — every time.

Built in the EU · Dutch company, hosted in EU data centres · Mistral EU-hosted available end-to-end · Never used for AI training
The audit log
Every Bramm interaction, inspectable.
Every prompt and response is recorded as a structured entry. The ISO can open any row and see exactly what was sent, what came back, and what the Privacy Shield removed — without ever seeing the redacted values themselves. CSV export, configurable retention per plan.
What lands in every entry
- ·Timestamp, user and role
- ·The original question — kept inside your tenant
- ·The redacted question the AI actually received
- ·The redacted system prompt preview
- ·A truncated answer (first 400 characters, never full PII)
- ·The model used and token estimates
- ·Per-category dictionary replacement counts
- ·Per-pattern PII redaction counts
- ·Restrictions applied — which data areas were withheld
- ·Citations — which policy IDs were quoted
Bramm Sovereign
Choose the model behind Bramm.
The Privacy Shield sits between Bramm and every model, so your data stays yours regardless. Sovereign lets you pick which model does the reasoning.
Gemini 3 Pro
Deep reasoning. Control design, cross-policy interpretation.
GPT-5
The most familiar brand. A second opinion from a different lineage.
Claude Sonnet 4.5
Nuance and tone. The strong fit for ISMS work.
Mistral Large 🇪🇺
EU-hosted. Your data never leaves Europe, end to end.
Sovereign doubles your plan price. No fine print.
GDPR posture
Built under EU law. Behaves like it.
Data residency
Storage, backups and support all in EU data centres operated by EU entities. Sovereign-Mistral keeps the model in Europe end-to-end.
DPA, ready before the call
Standard data-processing agreement available pre-sale, no negotiation required for typical mid-market scope.
Right to be forgotten
Deactivated users have their audit-log entries pseudonymised, not deleted. Compliance preserved, identity removed.
Sub-processors, in the open
Transparent list maintained in the trust centre. You configure which are permitted in your tenant.
Tenant-scoped, encrypted at rest
Your data lives in a tenant of one. Encryption at rest and in transit is the floor, not a tier.
Master switch
Bramm can be turned off in one click — useful during incident response, or while a new policy is being drafted.
Questions about a specific control, sub-processor or audit need?