Built for organisations that take AI governance seriously.
Brolli AI is designed from the ground up with privacy by design, Australian data sovereignty, and enterprise-grade security controls. We monitor AI tool usage across your organisation without ever seeing what your people do with those tools.
We see which sites employees visit. Nothing beyond that.
This is the most important thing to understand about how Brolli AI works. Brolli AI detects when a browser visits an AI tool site. That is the extent of what we observe. We cannot see what an employee types into that tool, what prompts they send, what files they upload, or what responses they receive.
We architecturally prevent individual employee monitoring. Before any data leaves the browser, user identity is replaced with a one-way cryptographic hash. That hash cannot be reversed to identify an individual. Not by your administrators. Not by us.
- The AI tool hostname (to match against our tool dataset)
- Session duration in seconds
- Timestamp, rounded to the nearest minute
- An opaque, irreversible user hash
- Acknowledge nudge responses
- Names, emails, or any other employee identity
- Page content, prompts, keystrokes, or anything typed into an AI tool
- Full URLs or browsing history
- Screenshots or screen recordings
If your employees want to know whether Brolli AI can see what they type into ChatGPT, the answer is no. The extension sees the domain. That's it.
Don't take our word for it — review the extension's listing, permissions, and requested data directly on the Chrome Web Store or Edge Add-ons store.
The same minimal-collection principle, extended to the desktop.
The Brolli Stealth desktop agent applies the same governance model beyond the browser, watching for known AI application processes running on macOS, Windows, and Linux. It matches against the same tool dataset as the extension — it does not read window content, inspect files, or capture anything an employee types.
On macOS and Windows it runs continuously and starts automatically when a device boots, the same way most endpoint security agents do — an individual employee can't turn it off. (Linux doesn't have that managed autostart yet — see How It Works for details.) What keeps this disclosed rather than covert is the tray icon: it is always present, and there is no hidden mode.
- The name of the AI application process detected (e.g. Claude.app, ChatGPT.exe)
- Session duration in seconds
- Timestamp, rounded to the nearest minute
- The same opaque, irreversible user hash as the extension
- Keystrokes, clipboard content, or anything typed into a desktop app
- Screenshots, screen recordings, or window content
- File contents or file names opened within a monitored app
- Network traffic content — only whether a known AI process is running
Enterprise-grade security, without enterprise complexity.
Your data stays in Australia. Full stop.
For government agencies, healthcare organisations, universities, and professional services firms, data sovereignty is not a nice-to-have. It's a hard requirement. Every piece of data that Brolli AI collects is stored and processed in AWS Sydney (ap-southeast-2). There is no offshore processing.
Designed with Australian compliance obligations in mind.
ISO 27001 certification and formal IRAP assessment for Brolli AI itself are on our roadmap as the product matures. We're being direct about what we have now versus what we're working toward.
If your organisation has specific compliance requirements that you'd like to discuss, contact us. We'd rather have that conversation early than have you discover a gap after you've deployed.
Talk to the team about your compliance requirements →