Brownie AI / AI Usage Policy

Version: v1.1

Effective Date: September 1, 2026

Last Updated: September 5, 2026

Language: EN

What Brownie can do

Brownie can explain information-security concepts, identify possible gaps, suggest risks and controls, recommend next steps, assist with documentation, help organize readiness against a framework, and help prepare reports. Brownie always inherits your own account permissions - it never has broader authority than you do, and meaningful changes require your review and confirmation.

Human responsibility

Brownie can make mistakes. Brownie recommendations are not guaranteed facts, legal advice, audit opinions, certification, or compliance guarantees. Users remain responsible for reviewing decisions and implementation.

Readiness and framework disclaimer

Brownexus helps organize and track readiness against frameworks such as ISO/IEC 27001, SOC 2, and NIST CSF for your own internal reference. Brownexus does not certify ISO/IEC 27001, does not issue SOC 2 reports, does not provide a formal audit opinion, and does not replace an independent auditor or certification body. A readiness status shown in the product (for example, Supported or Needs evidence) reflects Brownexus's own deterministic evaluation of the facts you and Brownie have organized - it is never a percentage score, and it is never a claim of certification or compliance.

Data processing

Brownie may process prompts, asset descriptions, security context, and generated analysis through configured AI services to provide responses. Avoid entering secrets or unnecessary sensitive information into prompts.

Back to Legal Center