Compliance · governance
Evidence for regulated AI in production
Export audit and alerts from the same layer that protects your agents — deployed in your environment. Built for GDPR accountability and NIS2 incident workflows, not external SaaS dependency.
GDPR — processing under your control
Burgus is deployed in infrastructure you operate. For agent traffic you route through the platform, you retain operational control over where processing occurs and what is retained.
- Data residency — platform, audit store, and exports remain in your on-premise or private-cloud deployment
- Metadata-first audit — timestamps, vendor, HTTP status, timing, and agent correlation by default; not full prompt or completion bodies
- Data minimisation — content-policy and behavioral layers analyse text ephemerally for matched rules; long-term retention is scoped to your configuration and exports
- Accountability artefacts — exportable audit history and alert records to support DPIAs, records of processing, and supervisory enquiries
- Processor role — Burgus Security BV supplies the platform; your organisation configures tenant scope and remains responsible for lawful basis and data subject rights in your deployment context
NIS2 — incident detection and evidence
For essential and important entities running AI agents in production, Burgus supports security operations and incident preparedness on the layer that actually secures your stack.
- Alert timelines — chronological history of security and policy alerts for triage and escalation
- Export bundles — JSON/CSV packs with events and latency summaries for internal CSIRT review
- Multi-agent traceability — delegation graphs and burst timelines when agents collaborate or fan out
- Operational independence — security layer runs in your environment; no external SaaS control plane required for day-to-day operations
- Combined reports — platform coverage, behavioral anomalies, and content-policy hits in one export surface
Export surfaces (operator MCP & REST)
- Compliance snapshot — traceability, latency, and error rollups for your deployment
- JSON or CSV export bundles — assessor-ready event packs
- Content-policy alert export — policy hit history with approval audit trail
- Platform coverage full report — rules, standards mapping, activation status
- Behavioral full report — anomalies with explain payloads
- Combined multi-agent security report — graphs, bursts, and alert rollups
Available via operator MCP and REST on your deployment. See Platform API.
Additional framework alignment
- OWASP LLM Top 10 — security coverage with standards matrix reporting
- MITRE ATLAS — agentic abuse and multi-agent patterns
- ISO 27001 / ISO 42001 — policy upload workflow and exportable alert history
- NIST AI RMF — behavioral detectors reference govern/map/measure practices
Data scope
Default audit is metadata-only. Content-policy and behavioral layers add ephemeral text analysis for matched rules — not long-term storage of full prompts unless your workflow exports alert records. All processing and retention boundaries are defined by your deployment and configuration.
Burgus supports your compliance and security operations — it does not replace legal counsel, DPO advice, or formal NIS2 conformity assessment. Home →