Law 21.719 fully enforceable on December 1, 2026 · days remaining · Law 21.663 already in force for Vital Importance Operators

Operations · Compliance · Artificial Intelligence

Operate while you comply

The consultancy delivers documents; the Agency oversees operations. Manage your assets, projects, people, suppliers, risks, incidents, plans, activities, and AI agents within the platform, and the evidence is automatically generated, traceable back to the article required by law.

Law 21.719 · Law 21.663 · ISO 27001 · NIST CSF · Made in Chile
Professional working on a computer with artificial intelligence and document management capabilities displayed on the screen
Evidence issued in real time

The real problem

Nobody breaks the law on purpose. The problem is not being able to prove it.

Your organization already backs up data, controls access, requests consent, and evaluates vendors. What it lacks is a dated, attributable, and traceable record of those operations—which is exactly what's required when an audit comes around.

Today

Compliance exists outside of operations

The organization works on its systems, and, on the other hand, someone transcribes what happened into a document management system, so they have something to respond with. The report is already outdated.

With BRAINLOF

Multiple high-use functions integrated: the operation happens inside and the evidence is issued in the same act. There is no delay in transcription.

Today

Each standard is a separate project

ISO 27001 on one hand, Law 21.719 on the other, quality and occupational safety in separate folders. The same controls are implemented three times.

With BRAINLOF

A single agnostic engine crosses the frames and establishes your baseline. An evaluated control unit meets all the required standards.

Today

There are not enough specialists.

Chile has an estimated shortage of 28,000 cybersecurity professionals. There aren't enough people to do this work manually, at any price.

With BRAINLOF

AI provides the framework with its controls, documents, and activities, and guides you step by step. What previously required a specialist can now be done by your team.

Today

The holder has no way to exercise their rights

RAT, consent, and the ARCO channel are mandatory for any organization that processes personal data, regardless of its size. Almost no one has them operational.

With BRAINLOF

ARCO portal, consent management, and live RAT powered by your own operations. Always included, never tied to a higher plan.

Today

Holdings, networks, and guilds cannot govern their members

A holding company doesn't see the state of its subsidiaries; a trade association recommends but cannot provide tools; a health network repeats the same work in each establishment.

With BRAINLOF

Real multi-organization: each subsidiary with its own brand, data, and encryption key; the parent company consolidates without seeing what doesn't belong to it.

Today

Your industry regulations are not in any software.

Health Superintendency Accreditation, CMF regulations, DS 132, CNA accreditation: no international suite models them, and translating them by hand takes months.

With BRAINLOF

Chilean sectoral frameworks are pre-configured, maintained, and updated when regulations change. No new project required.

This is what it looks like inside

Operational platform, not just documentary

Review some views of the platform operating on a demo institution. The data is fictitious; the structure and behavior are real.

Demonstration Institution Framework · Cybersecurity and Data Protection

The important reading is not where the risk is, but how much it has shifted. If the two matrices look the same, the controls are ineffective. Each cell reveals the risks it contains, along with their owner and the associated process.

Inherent risk · 23
Almost certain
0 MED
0 ALT
0 CRÍ
1 CRÍ
1 CRÍ
Likely
0 BAJ
0 MED
3 ALT
2 CRÍ
1 CRÍ
Possible
0 BAJ
2 MED
2 MED
5 ALT
0 CRÍ
Unlikely
0 BAJ
1 BAJ
3 MED
1 MED
1 ALT
Queer
0 BAJ
0 BAJ
0 BAJ
0 BAJ
0 MED

Impact 1 → 5 · vertical probability

Residual risk · the same 23
Almost certain
0 MED
0 MED
0 ALT
0 CRÍ
1 CRÍ
Likely
0 BAJ
2 MED
1 MED
1 ALT
0 CRÍ
Possible
1 BAJ
3 MED
4 MED
1 MED
0 ALT
Unlikely
2 BAJ
2 BAJ
2 MED
1 MED
0 MED
Queer
1 BAJ
1 BAJ
0 BAJ
0 BAJ
0 BAJ

After the applied treatment

The clock starts ticking from the recording, not from the meeting. Each incident carries a severity level, phase, responsible leader, and the notification deadline required by the policy—with the deadline in sight.

Code Incident Severity Phase Leader Next deadline
INC-2026-001 Ransomware on file server S1 Critical Phase 3 Cybersecurity Officer Wins in 1 hour 40 minutes
INC-2026-002 Phishing targeting internal accounts S2 High Phase 2 Cybersecurity Officer Wins in 6 hours
INC-2026-003 Spreadsheet display in shared folder S1 Critical Phase 4 Data Protection Officer Notified
INC-2026-006 Loss of equipment containing personal data S2 High Phase 2 Data Protection Officer Under evaluation
INC-2026-008 Malware on laboratory equipment S4 Low Phase 1 IT Support No deadline

Fixed and auditable rules based on the data your organization already has uploaded. It's not a model making opinions: it's a deterministic rule that reviews your own information and identifies the specific records that generate each finding. Then the AI makes suggestions; you decide.

16 critical processes with no declared risk

Processes marked as critical on the data map for which no one has yet stated what could go wrong.

Student clinical placements Medication dispensing Medical consultations Delivery of results to external centers Electronic medical record management +11 more
3 repositories with sensitive data without encryption

They store sensitive personal data or confidential information and do not declare encryption at rest.

Clinical records server Appointment scheduling form Clinical practice record
✦ Risk analysis with wizard: Convert these findings into proposed risks, written in natural language. You decide which ones are accepted, which ones are edited, and which ones are discarded.

Each control requires documentation, and each document has a defined frequency and responsible party. The system generates the evidence calendar and shows which regulations each item covers. A document management system stores files; this is a requirement.

Document Controls Class State Periodicity Coverage
Minutes of the constitution of the security committee GOV-03 Minutes or record Earring Unique ISO 27001 · 2
Catalog of personal data GOV-02 · PRV-01 Report In development Annual Law 21.719 · 4
Minutes of the review of the risk methodology RISK-01 Minutes or record Earring Annual ISO 27005
Matrix of profiles and privileges in systems IAM-02 · IAM-04 Matrix In development Monthly ISO 27001 · 3
Minutes of the security committee meetings GOV-03 Minutes or record Earring Quarterly Law 21.663 · 5

44 documents required by the active framework · the due dates calendar is automatically generated

CRM also leaves evidence. Every opportunity, contact, and campaign is based on legality and traceable consent, so the sales area is no longer the blind spot of RAT (Real-Time Advocacy).

Weighted forecast $60,075,000
Gross value $149,500,000
Open opportunities 14

Open Opportunities Funnel

Prospect
5
Qualification
4
Proposal
3
Negotiation
2

Pipeline weighted by stage

Prospectus Rating Proposal Negotiation

The regulatory obligation appears on the agenda of the person who has to comply with it. Committees, evidence deadlines, notification periods, and RAT reviews don't just exist in a report: they arrive on the responsible person's calendar, with their origin clearly visible.

Mon 3 Mar 4 Wed 5 Thu 6 Fri 7
08:00 09:00 GOV-03 Security Committee · Minutes Review of the RAT Law 21.719 10:00 IAM-02 privilege matrix evidence is defeated 11:00 ANCI Notification INC-2026-001 · 3 h 12:00 Closing of campaign for level 1 suppliers 13:00 14:00 Stage 3 of the Gantt chart · SGSI 15:00 MFA policy signature · 4 pending

Each activity retains the module and control that originated it. If it is rescheduled, the regulatory deadline does not change.

The platform assistant only sees documentation, never your data. It explains what each application does, the best order to configure it, and what is recorded in each field, limited to what the user's profile has available. It does not access your information or perform actions on your behalf.

Platform Assistant
I'll guide you through using and setting up the platform: what each application does, the best order to configure them, and what is recorded in each field. I only see the documentation for what's available in your profile; I don't access your data or perform any actions on your behalf.
How do I configure the admissions area profiles?
Ask how to use or configure an application…

Administration

Organization: Subsidiaries, branches, departments and units
Teams Working groups with their own scope
Profiles and privileges Profile → privilege → resource, by role and level
Cost centers: Allocation by unit, subsidiary, or program
Dashboards: Dashboards by role and consolidated by the group
Parameters: Brands, deadlines, taxonomies, and business rules

Demonstration views with fictitious data. The actual configuration depends on the framework and structure of each institution.

The category difference

Almost everything sold as compliance in Chile is a document manager with workflow

Upload the document, approve it, save it, and let someone remember it in a year. It's useful for organizing paperwork, but the evidence is still the paper—and the audit doesn't ask about the paper, it asks about the transaction behind it.

The usual approach

Document manager and workflow

Policy and procedure repository, with approvals and reminders. The organization continues to operate externally, on its own systems, and someone has to manually transcribe what happened there and transfer it here.

  • The document is the end, not the consequence.
  • The evidence is transcribed, and that's why it's delayed.
  • Nothing forces what is written to coincide with what is done

Our approach

Multiple frequently used functions, integrated together

Daily operations take place within the platform: assets, projects, people, suppliers, firms, campaigns, and customer service. The document is issued as a result of these operations, not the other way around.

  • A single piece of data feeds management, risk, and compliance.
  • The evidence is dated and attributed, but without a transcription.
  • What is written and what is done cannot differ: they are the same record

The difference lies in the crossing

For all work fronts, a single engine that runs through them all

Each module operates independently and delivers its data to the others and to the AI-powered multi-standard engine. This cross-referencing generates evidence—dated, attributed, and traceable back to the specific article required by law—which is something a document management system cannot produce by design.

  • You capture a piece of data once and it serves assets, risk, people, and compliance all at once.
  • One engine for all frames: ISO 27001, NIST CSF and laws 21.719 and 21.663.
  • The AI reasons about that crossing with strict isolation by organization.
Diagram: Each module feeds into the compliance engine and the others

The functions that are integrated

Multi-standard compliance assessment by control
ISO 27001 and 27005 ISMS compliance in operation
Critical assets CMDB and complete inventory management
Data map and RAT purposes and legality
ARCO channel requests and rights of the holder
Person-traceable consent
ISO 27005 risks and heat maps
Incidents with configurable management and deadlines
Gantt chart planning , programs and projects
Management of people: employees, customers, suppliers, and subscribers
CRM for customers and opportunities
Third-Party Supplier Risk Assessment (TPRM)
Campaigns and surveys with closing dates
Electronic signature with second factor
Biometric identity document-face
Key encrypted documents by organization
Multi-brand extranet portals by subsidiary
24/7 AI-powered customer service agents
Schedule of activities and deadlines in your week
RBAC administration multitenant structure, roles and privileges

Each function operates independently and delivers data to the others and to the compliance engine. This cross-functionality is what a document management system cannot, by design, produce, no matter how many approval workflows it adds.

Where do you enter?

Two ways to work with the platform

End Customer My organization must comply

Clinics and health networks, banks and fintech, municipalities and state services, mining operations, universities and all Vital Importance Operators qualified by ANCI.

  • Your industry framework already loaded, not a generic template
  • Evidence ready for audit from the first month
  • You start with what you need and add capabilities when the time comes.
View verticals by sector → Channel I bring compliance to a network

Consulting firms that implement, holding companies that govern subsidiaries, trade associations and guilds that need to raise the standard of all their members at the same time.

  • Multi-organization with its own brand through subsidiary or associate
  • Your methodology within the platform, not ours on top of it
  • Recurring income instead of projects that end
View channel program →

The central idea

When you operate, you've already fulfilled your obligations.

This isn't a marketing promise: it's a consequence of where the data resides. Since the asset, the project, the person, and the supplier are all within the platform, the control required by the standard is satisfied by the record already generated by the transaction.

12 solutions that feed off each other
6 Chilean sectoral verticals
1 motor for all frames
0 weeks gathering evidence
Professional reviewing management and compliance dashboards on screen

Native data protection

A single safeguarding standard for all your relationships

Law 21.719 does not distinguish between a client and a job applicant: both are considered data subjects. Every person you register enters the system based on legality, consent, and organizational isolation, and contributes to the same Record of Processing Activities.

Business relationship

Contacts and clients

Record with complete history, declared purpose and consent for each authorized contact channel.

Contractual relationship

Suppliers and third parties

Evaluated and monitored, with a treatment agreement and evidence that expires.

Employment relationship

Employees and collaborators

Sensitive employment relationship data is protected, with access limited by role and traceability of each query.

Service link

Patients, students and members

They log in through the extranet with identity verification, exercise their rights, and see what is done with their data.

Legal basis by data subject Traceable consent Isolation by organization Access traceability Feeds the RAT Registered right to object

Artificial intelligence

The AI executes. You're in control.

Within the platform, AI drafts, evaluates each control individually, reads documents, and provides voice support—and your people decide how far it goes, what requires a signature, and what needs to be reversed. Since Law 21.719 regulates automated decision-making, we provide you with the tools to govern all the AI used by your organization.

View the full AI layer

BRAINLOF Assistant

Generates the preliminary evaluation of Law 21.719 for the admissions area.

Done: 36 controls evaluated, 5 critical gaps prioritized, and a remediation plan with assigned responsibilities. 4 pieces of evidence pending. Should I generate the tasks?

Customer control

We give you the platform. You retain control.

A compliance platform handles an organization's most sensitive assets: its data, its evidence, and the decisions it makes about people. None of that can be left on the vendor's side.

Your data

Your own encryption key

Each organization stores its documents with its own key, in private storage. Neither the storage provider nor we have access to the content.

Your evidence

Exportable whenever you want

Your compliance history is yours and is available in audit format. Your continued participation should be a choice, not an exit cost.

Your AI

You set the thresholds

What can an agent handle alone, what requires a person's signature, and what is automatically reversed? Autonomy is defined by your team, system by system.

Your people

You define who sees what

Profile, privilege and resource: each person only has access to what their role and level in the structure enable, and each access is recorded.

Your reach

Add and subtract what you use

Modules, frameworks, and subsidiaries adapt as your needs change. No user limits and no paying for what you don't need.

Your brand

The portals are yours

Each branch serves its patients, providers, or members using its own logo and colors. The account holder sees your institution, not us.

What makes us different

Four advantages for better service.

This is a difficult combination to replicate, as we integrate seamlessly into complex coverage areas and adapt to your organization's operational needs if required. With consultants who possess extensive experience in the cybersecurity and technology market, we have created unique solutions not only for documentation but also for operational compliance, ensuring order and efficiency while our users provide continuous service.

Advantage 01

Operational layer with underlying compliance

GRC suites manage controls and monitor external systems. BRAINLOF also manages assets, projects, people, firms, campaigns, and identity: evidence originates internally, it's not imported.

Advantage 02

Chilean sectoral depth

Superintendency of Health, Law 20.584, DS 132 and SERNAGEOMIN, CMF regulations, Law 21.521 Fintec, CNA accreditation and DS 44. It is the barrier that an international entrant does not amortize in a market of this size.

Advantage 03

Multi-organization with branding by subsidiary

A parent company governs subsidiaries with strict isolation, and each subsidiary opens its own portals for providers, affiliates, or patients. This is what technically enables the network and channel model.

Advantage 04

Extranet with agents who serve your customers

Customers, students, subscribers, affiliates, or suppliers resolve their procedures 24/7 , supported by AI that verifies identity, executes and closes — and each interaction is based on legality, consent, documented record and strict compliance.

Reference case

Cristo Vive Foundation: primary care in Recoleta, with SGSI operating

Construction of a complete Information Security Management System under a hybrid framework of CIS, NIST and ISO 27001 for the CESFAM Cristo Vive, covering health regulations, telemedicine and electronic medical record, including laws 19.628, 21.719, 21.663, 20.584 and 21.459.

The CESFAM has been operating since 1993 through an agreement with the North Metropolitan Health Service and is part of the public health network. A provider like this handles sensitive data from an entire population, with extended hours and emergency care: there's no window to pause operations while compliance is implemented. Service agents, on the other hand, are available 24/7, regardless of the examination room's hours.

Population served

25,000

people from Recoleta and surrounding areas under the family health model

Annual visits

+20,000

people treated each year in the health area of the Foundation

Operating from

1993

in agreement with the North Metropolitan Health Service

Implemented frameworks

3 + 2

CIS, NIST and ISO 27001, cross-referenced with laws 21.719 and 21.663

Coverage figures published by Fundación Cristo Vive. These figures correspond to the provider's operations, not to BRAINLOF users.

Certified consultants

The platform doesn't arrive on its own. It arrives with those who know how to implement it.

Your implementation is handled by a consultant with accredited certification in your relevant field: information security, data protection, quality, workplace safety, or industry regulations. This is what transforms a license into a fully functional management system—something no international suite offers in Chile.

Certification and quality seal on a digital work surface

Verifiable credentials

You know who enters your organization

The assigned consultant provides proof of their subject matter expertise and is certified on the platform. You can request both before signing.

Coverage by specialty

The specialist that your standard requires

The profile of someone implementing an ISMS is not the same as the one preparing a health accreditation or a mining DS 132. You are assigned based on your subject matter, not your availability.

Independence

We implement; a third party certifies.

The network provides consulting and implementation services, not certification auditing. This separation is what makes the evidence you provide valid for both the certification body and the Agency.

Why this matters more than integration

Chile has an estimated shortage of 28,000 cybersecurity specialists. The bottleneck isn't the software; it's finding people to run it. Hiring that kind of professional today takes months and is competitive across the entire industry; here, it's included in the project.

Structure

An organization, at all levels

Model your institution, its subsidiaries or branches, its departments, units, and teams. Each level only has access to its own data, and assessments run through the entire structure or are consolidated upwards.

  • Access control by role and organization, with separation of duties by design
  • Customized branding by subsidiary: unique logo and color palette on each portal
  • Evaluations by subsidiary, by department, or consolidated for the group
  • Documents with envelope encryption and a unique key per organization
Team from an organization in a meeting, different roles collaborating

Sectors

Designed for Chile's most regulated industries

Healthcare , Banking, Insurance and Fintech, Public Sector and Municipalities, Vital Operations, Mining, Higher Education , Insurance , Human Resources
View each vertical in detail

Frequently Asked Questions

The most frequently asked questions about compliance in Chile

When does Law 21.719 come into effect and what are the risks if I don't comply?

It was published in December 2024 and is fully enforceable from December 1, 2026, after a 24-month adaptation period. Penalties reach up to 20,000 UTM for very serious violations and up to 4% of annual income in case of repeat offenses. The Agency may also order the suspension of treatment and publish a national register of sanctions.

What is the Record of Processing Activities and why do I need it?

It's an inventory of how your organization processes personal data: purpose, legal basis, data categories, retention periods, and recipients. The law requires it to be kept up-to-date. At BRAINLOF, it's generated and maintained based on your data map and daily operations, without needing to be recreated each time.

What does Law 21.663 require and who enforces it?

It specifically requires essential services and Vital Importance Operators to implement an ISMS, appoint a cybersecurity officer, manage risks, and report incidents to the ANCI within a maximum of three hours. It is already in effect and has no grace period.

I'm a small business owner, do I have time?

Less than it seems. During the first twelve months of the program, smaller companies receive a written warning instead of a fine for their first violations. This ends in December 2027, and the warning does not exempt them from correcting the violations nor does it protect them against a claim from the license holder.

How does it differ from a traditional consultancy?

A consultancy delivers documents; an auditor reviews operations. BRAINLOF leaves traceable operational evidence, compliant with legal requirements and continuously monitored, instead of a report that becomes outdated. And it builds capacity within your team instead of taking the knowledge away at project completion.

Does it apply to all regulations or only to Chilean laws?

The engine is agnostic: ISO 27001, 27005, 9001 and 14001, NIST CSF, CIS, Chilean Standards and its own frameworks, in addition to Chilean laws 21.719, 21.663 and 20.584. The frameworks cross each other so that an evaluated control responds to all the standards that require it.

How do I know if my organization is a Vital Importance Operator?

ANCI classifies IBOs through a resolution and publishes the list. The first process closed on July 24, 2026. If your institution was classified, you will be notified and will have reinforced obligations that are immediately enforceable: ISMS, cybersecurity officer, risk management, and incident reporting within three hours, with fines of up to 40,000 UTM.

I'm not an OIV member, but my client is. Does this affect me?

Yes, and it's the way most organizations discover their obligations. Law 21.663 compels International Veterinary Organizations (IVOs) to demand standards from their supply chains, so you'll receive safety questionnaires and contractual clauses that didn't exist before. Responding with evidence, not promises, is now a requirement to continue doing business with them.

Is AI trained using my organization's data?

No. The AI layer is decoupled from business logic and operates with strict organization-wide isolation: neither the user nor the model accesses data outside the tenant and session role. Your data does not feed models or is used to improve service to other customers.

How do they prevent AI from inventing risks or controls?

Separating who finds from who writes. The recognition process works with fixed and auditable rules based on the data your organization already has uploaded, and each finding points to the specific records that generated it. Only then does the AI propose the written risk assessment, and a person accepts, edits, or discards it.

I already have ISO 27001 certification. What's the point?

Certification verifies a moment in time; oversight inquires about ongoing operations. The platform keeps the ISMS active between audits, cross-references your current framework with Laws 21.719 and 21.663 without requiring you to reinstate the same controls, and prepares the file for follow-up audits without having to rebuild it.

Can I upload my own framework or internal rules?

Yes. The engine is agnostic: in addition to the included frameworks, you can define your own frameworks with your controls, your required documents and your frequency, and cross-reference them with external standards so that an evaluated control responds to all of them at once.

How do they protect my organization's data?

Documents with envelope encryption and a unique key per organization in private storage, strict isolation between organizations, role-based access control, short-lived sessions, access logging, and defenses against the OWASP Top 10. The platform operates on hosting infrastructure with SOC 2 type II and ISO 27001 certification.

Do I need technical knowledge and how long does it take to implement?

You don't need to be an expert: AI provides the framework with its controls, documentation, and activities, and guides you step by step. What a traditional consultancy takes months is reduced to weeks. Implementation is handled by a certified consultant within the network, specializing in the area your standard requires.

What exactly do AI-powered service agents do?

They provide 24/7 support to your clients, patients, students, or suppliers via chat, voice, or portal; they execute the service workflow according to your organization's rules; they escalate cases to a human agent when they exceed the threshold defined by your team; and they record the interaction based on legality and consent. They do not make clinical, financial, or disciplinary decisions.

My organization uses AI in admissions or selection. Is that regulated?

Yes. Law 21.719 regulates automated decisions that affect people: it requires a legal basis, notification to the data subject, and the right to object. BRAINLOF allows you to inventory your AI systems, designate a responsible party for each one, record decisions, and specify what the model decides and what a person signs.

Can I take my data with me if I change platforms?

Yes. Your compliance history is yours and can be exported in audit format upon request. Your continued participation should be a choice, not an exit cost.

Do you work with consulting firms, holding companies, and trade associations?

Yes, in two different ways: we certify partners who implement the platform for their clients, and we establish channel agreements with networks that incorporate many organizations simultaneously. These agreements are signed separately because they are distinct relationships.

Am I required to appoint a data protection officer?

Law 21.719 requires the designation of data controllers and, in certain cases, a prevention officer with specific functions. Even if you weren't legally obligated, having someone designated with a written scope of responsibility is the first thing an audit will check. If you don't have anyone to appoint, your network of partners can provide this role externally.

What do I do if I suffer a data breach?

The platform records the incident using its taxonomy, activates the corresponding deadlines, and compiles the notification file. What cannot be improvised is the preparation beforehand: having the data map, the asset inventory, and the communication channel defined before the incident. That is the work the platform does for you.

Does it integrate with my current systems?

Today, the operation takes place within the platform, and the evidence originates there, not imported from outside. Native integrations with identity providers, cloud services, and SIEM, along with single sign-on and a public API, are under development. We mention this because it's the most frequently cited gap compared to international suites.

How does the assistant differ from the agents?

The platform assistant is for your team: it guides the setup and explains what is recorded in each field, and only views the documentation available for that profile—it does not access your data or perform any actions. Service agents are for your customers: they provide 24/7 support, handle entire processes, and leave a record of every interaction.

We are a network, a holding company, or a guild. How does it work?

A parent organization governs its subsidiaries or associates with strict isolation: each operates with its own brand, data, and encryption key, while the parent company consolidates the group's status. It's the same architecture that underpins the channel program, and it's already in place.

Can I try it before deciding?

Yes. The Law 21.719 exposure assessment is free, takes four minutes, and provides your prioritized gaps along with the relevant article that mandates them. If you proceed, this result serves as the starting point for the configuration, and the demo is based on your actual process rather than a product presentation.

Start by measuring

Stop gathering evidence. Start releasing it.

We'll show you, through a real-world process, how it's recorded when someone runs it within the platform. No obligation.

Request a demo Measure my exposure

Platform

An agnostic engine, all your frames on the same basis

The same system that assesses ISO 27001 also manages Law 21.719, ISO 9001, workplace safety, Chilean Standards, and your internal regulations. Standards and legislation overlap, so an assessed control meets all the standards and laws you want to include, rather than starting from scratch with each certification or sector-specific regulation.

Engine

Control-by-control evaluation

With automatic guidance, real-time scoring, and traceability to the article of law.

  • Included frames and custom frames
  • Intersection between Chilean and foreign laws
  • Single baseline per organization
  • Expiration calendar and alerts

Evidence

Record with evidentiary value

Each transaction is dated, attributed to a person, and linked to the control it satisfies.

  • Audits and findings with follow-up
  • Reports, minutes and RATs automatically generated
  • Exportable documentation for tax audit
  • Historical data that is not lost

Architecture

Multi-organization with levels

Organization, subsidiaries, departments, units, teams and users, each with its scope.

  • Strict isolation between organizations
  • Custom brand per subsidiary
  • Consolidated group evaluation
  • Extranet with its own address per location

Example of structure

Northern Health Network Organization Consolidates All Its Subsidiaries
Central Hospital Branch: Your brand, your data, your encryption key
Admissions Unit Work Team with its scope
User Profile with limited privileges: Sees only what their role enables
Isolated Outpatient Center Branch of the previous subsidiary

Security

Protection that withstands a penetration test

It's not a promise: these are implemented controls. And where we don't have something, we say so.

Information security presentation in a meeting room

Envelope encryption by organization

Each organization stores its files with its own key on private storage. Not even the storage provider has access to the content.

Isolation between organizations

No data crosses from one session to another. Each query is limited to the session tenant, including those made by AI.

Role-based access control

Profile → privilege → resource, with separation of functions by design and traceability of each access.

Sessions and monitoring

Short-lived tokens, access and incident logging, and alerts for anomalous behavior.

OWASP Top 10 Defense

Parameterized queries, strict content policy, and protection against XSS, CSRF, and IDOR.

Provider infrastructure

We operate on hosting with SOC 2 and ISO 27001 certification and inherit their physical and operational controls.

Form for third-party questionnaires

Your OIV and banking clients are required to assess their supply chain. Here's what they need from us, published so you don't have to ask.

Service model Multi-tenant SaaS with strict isolation by organization
Application and data location Hosting provider's data center, with SOC 2 and ISO 27001 certification
Cipher at rest Envelope encryption with a key per organization, in private storage
Encryption in transit TLS on all connections
Access control RBAC by profile, privilege and resource, with separation of duties
Registration and monitoring Access and incident traceability, alerts for anomalous behavior
Safe development Parameterized queries, strict content policy, OWASP Top 10 defenses
Backups and recovery Documented backup and recovery policy, to be completed with committed RPO and RTO
Sub-processors Listing available by agreement, with a current commission contract
Retention and elimination Defined by the client; export of the history in audit format at the end
Incident notification To the client and, where applicable, to ANCI within the legal timeframe

Facing the market

Where we won and where we haven't yet

A table with "yes" in all its own rows isn't information, it's advertising. These are the rows where we lose.

Criterion BRAINLOF GRC International GRC local Consulting firm Forms
It models the letter of the Chilean law Yeah Partial Yeah Yeah No
Sectoral frameworks (health, mining, CMF, CNA) Yeah No Limited Yeah No
Integrated high-use operational functions 24 Few Documentary N/A No
Operational layer (assets, signature, Gantt chart, QR code, CRM) Yeah No No No No
Reach the final headline (portal, ARCO, extranet) Yeah No No No No
Unique biometric identity Yeah No No No No
Multi-organization with branding by subsidiary Yeah Partial No No No
Tools for people to govern AI Yeah Emergent Certification Project No
Native integrations (cloud, IdP, SIEM) In development Extensive Limited N/A No
Single sign-on (SSO) On the roadmap Yeah Variable N/A No
Installed base and references Incipient Miles Dozens Wide N/A
Network of certified partners in Chile Yeah No No Own No
Leave installed capacity Yeah Yeah Yeah No Fragile

This is a comparative analysis by solution category, based on publicly available information as of the date of this report. It does not imply affiliation or sponsorship; trademarks belong to their respective owners.

Methodology

Built on global reference frameworks

ISO 27001 and 27005, NIST CSF, CIS Controls, ISO 9001 and 45001, Chilean Standards and laws 21.719, 21.663 and 20.584. LOF has consultants with individual certifications who support each implementation.

ISO 27001 ISO 27005 NIST CSF CIS Controls ISO 9001 ISO 45001 ISO 42001 NCh
Blocks with the words Compliance, Standards, Laws and Policies

How to hire

Modular, layered.

The scope is defined by frameworks, structure, modules, and verticality — and the proposal is tailored to what you really need.

Compliance Core

Multi-standard engine, RAT, ARCO channel, consent, risks, incidents, critical assets, encrypted documents, and regulatory updates. This is the foundation, not a higher-level plan.

Operating and advanced modules

CRM, planning, people, campaigns, third parties, electronic signatures, biometrics, extranet, and full AI. These features are added and removed depending on your needs.

Sectoral vertical

Your industry framework is fully loaded, with evidence templates and supported implementation.

Consulting and implementation

Gap analysis, system scope, risk analysis, framework loading, evidence migration, implementation, and training — delivered by the network of certified partners in each subject, working within your own platform and not in a separate report.

Request a proposal

Solutions

Each capability solves a specific problem and feeds into the others.

It's not a loose toolbox. Each solution operates independently and, in doing so, provides data to the others and the compliance engine. Open each one to see what it includes and what evidence it leaves behind.

From asset to risk, from risk to evidence

Solutions that share the same data

The equipment you register as assets is the same equipment that appears in the risk assessment, the supplier contract, and the accreditation documentation. Registering it once ensures compliance isn't extra work.

Risk assessment meter showing high level

One piece of data, three uses

The medical equipment you record as assets is the same equipment listed in the risk assessment, the supplier contract, the maintenance plan, and the accreditation documentation. Recording it once ensures compliance isn't extra work.

Artificial intelligence

Three layers: the AI that helps you, the one that attends to you, and the one that your organization controls.

Most compliance platforms added a chat feature on top. Here, the AI is decoupled from the business logic but within the same isolation—neither the user nor the model accesses data outside the tenant and session role—and each action is attributed to the person who authorized it.

Professional with data visualization and overlaid artificial intelligence

Layer 1

AI that helps you achieve

Where a consulting firm charges for weeks, the platform delivers in minutes, with the context of your own organization.

  • Draft policies, procedures, and minutes
  • Evaluate each control individually against the chosen framework
  • Document vision: read, extract, and classify
  • Recognition based on fixed and auditable rules regarding your own data
  • It converts the findings into proposed risks that a person accepts, edits, or discards.
  • Prioritize gaps and develop a remediation plan with those responsible.
  • Conversational and voice assistant, always under the role of the user
  • Platform assistant that guides you through the setup without accessing your data.

Layer 2

Agents who attend

Several specialized agents orchestrated around your data, available 24/7 : one receives, others resolve, one supervises, and another records the evidence.

  • Scheduling, admission, procedures and applications
  • ARCO channel assisted with identity verification
  • First line of incidents with the ANCI clock ticking
  • Supplier evaluation and monitoring
  • 24/7 service, no appointments, no queues, and no business hours
  • Scaling to one person with the full context

Layer 3

Control remains with your company.

Law 21.719 regulates automated decision-making, and ISO 42001 sets the standard. Neither of these requires anything of a model; they require accountability from a person within your organization. Our job is to provide the platform where that accountability can be exercised.

  • Designated person responsible for each AI system, with its scope
  • Inventory of the AI systems used by the organization
  • Impact and bias assessment, approved by the appropriate authority
  • Thresholds of autonomy: what the model decides and what a person signs
  • Record of automated decisions and the data subject's right to object
  • ISO 42001 framework on the same multi-standard engine

Rule the AI

When a model makes a decision about a person, someone has to respond.

AI governance isn't a software function; it's a set of human decisions—who authorizes each system, how far it can go on its own, who reviews its results, and who is accountable to the owner. We don't make those decisions for you; we provide the platform to make, record, and demonstrate them, using the same multi-standard engine that already manages your other obligations.

Institutional signage for artificial intelligence government in an office

Why this matters now and not in two years

Any organization that has incorporated AI into admissions, selection, scoring, or customer service is making automated decisions about people. Under Law 21.719, this requires a legal basis, notification to the data subject, and the right to object—and it requires that there be someone capable of explaining the decision, not a provider to be questioned. It is a new obligation for which almost no one has the tools, and the only case where having AI and a compliance engine integrated is equally advantageous.

Orchestration

Four roles, one single conversation for the user

The lead agent speaks once. Behind the scenes, the agents pass the case among themselves as needed, without leaving the isolation of your organization or your assigned role.

Role 01

Reception

It's available anytime, every day. It understands the person's needs, identifies them, and decides which agent is appropriate. Available via chat, voice, or a branded portal for your institution.

Role 02

Specialists

They execute the specific flow: scheduling, admitting, processing, responding to an ARCO request or raising an incident.

Role 03

Supervision

Verify the response against the rules your organization has defined and escalate to a person when the case crosses the threshold. That threshold is set by your team, not the model.

Role 04

Compliance

It records legality, consent, and traceability in the RAT database. It transforms care into evidence without anyone having to document it afterward.

How far does an agent go?

Agents operate within the platform using its own agent management engine and are configured by vertical according to each institution's workflows. An agent does not make clinical, financial, or disciplinary decisions: it executes the workflows defined by your team, respects privacy and consent, and escalates any issues that cross the threshold to a human agent.

Facing a chatbot

Answering is not the same as solving, and solving is not the same as being able to prove it.

Criterion BRAINLOF Agents Chatbot / IVR Agent on generic suite external call center
Complete the entire process Yeah No Partial Yeah
Attends and resolves 7x24 Yeah It answers, it doesn't solve. Partial In shifts
Leave evidence based on legality and consent Yeah No No No
It operates on the organization's data, isolated. Yeah Limited Depends He exports them
Register in the RAT what it deals with Yeah No No No
Scale to a person with full context Yeah No Partial Yeah
Integrations with third-party systems In development Spacious Spacious N/A
Installed base and references Incipient High High High

The last two rows are real disadvantages compared to suppliers with years in the market, and they are declared in the business conversation, not afterwards.

View the agents in your own flow

Vertical

Your industry doesn't need a generic template

Each vertical comes with its own comprehensive regulatory framework, evidence templates, and implementation support. This is a layer that no international suite can fully utilize in a market the size of Chile's.

Vertical Health

Three pieces that are now one

The patient extranet, service agents, and the cybersecurity and data protection framework are integrated, because in health they do not work separately: the holder who exercises an ARCO right is the same patient who requests an appointment, and the data that identifies him is a special category.

The provider operates; the accreditation file is automatically compiled

Electronic medical record, telemedicine, patient consent and health data as a special category: each care leaves the record that accreditation and Law 21.719 require separately.

Healthcare professional consulting clinical data on a tablet

Loaded frame

Accreditation of the Superintendency

Standards for institutional providers, with evidence associated with each evaluated characteristic and responsible for each one.

Loaded frame

Law 20.584 and medical record

Patient rights and duties, confidentiality of electronic health records and traceability of access to health data.

Loaded frame

Telemedicine and healthcare network

Networked providers, remote consent, and safeguarding of the remote clinical session.

Operation

Patient extranet

Portal with provider branding, biometric verification, consent and access via QR code on site.

Operation

24/7 Service Agents

Scheduling and confirmation, admission and documents, assisted ARCO channel and post-care follow-up — at any time, using the provider's workflows. Care is not dependent on the examination room's hours of operation.

Operation

Sensitive data and OIV

SGSI ISO 27001 and 27005, Law 21.663 for qualified providers, and health data as a special category under Law 21.719.

Reference case

Construction of a complete ISMS under a hybrid framework of CIS, NIST and ISO 27001 for the CESFAM Cristo Vive, covering health regulations, telemedicine and electronic medical record, including laws 19.628, 21.719, 21.663, 20.584 and 21.459.

In development · 2027

Higher education: accreditation is no longer a six-year project

A university operates in reverse: it operates for five years and then dedicates a full year to reconstructing the evidence of what it did. This vertical structure reverses that logic—each criterion of the CNA is linked to the operation that feeds it, and the dossier is built month by month.

Accreditation

CNA by dimension and criterion

Institutional and career-based, with associated evidence, responsible party and status for each criterion.

Data

Students and applicants as holders

Tens of thousands of holders with different purposes: admission, welfare, student health and research, each with its own legal basis.

Structure

Headquarters, faculties and units

The same multi-level structure that requires an accreditation file, with upward consolidation.

Actual state of this vertical

The CNA framework is under development, with a planned launch in 2027 alongside the mining sector. An institution can currently operate based on the core framework, Law 21.719, and ISO standards, and incorporate accreditation when it becomes available without migrating or redoing its existing evidence.

Network and channel

Two ways to be on BRAINLOF's side

We certify implementing partners: consultants and firms that put the standard into operation within the client's platform. And we agree on a channel with those who incorporate : networks that bring the platform to many organizations simultaneously. A single partner can be both, but the agreements are signed separately because the terms are different.

Certified Ally

We certify you to implant

If you already do consulting in security, data, quality or sector regulations, we train and certify you on the platform so that you can deliver the complete project with it integrated.

  • Training and certification credential by subject
  • Ideal environment for practicing and demonstrating to your clients
  • Account routing based on your specialty and territory
  • The project ends with your client up and running, not with a delivered report.
Apply to the certification program →
Channel

We are adding organizations to the platform

Consulting firms with a portfolio, holding companies that govern subsidiaries, and guilds or associations that want to raise the standard of all their members at the same time.

  • Multi-organization with its own brand through subsidiary or associate
  • Preferential conditions and recurring commission for active organization
  • Partner portal with authorized co-branding
Discuss the program →

Who brings what to the table

Consulting firms

Your methodology, with a platform behind it

You deliver the diagnosis and implementation as usual, but the client is left with installed capacity and you with recurring revenue instead of a project that ends.

Holdings

Group governance, autonomy by subsidiary

You consolidate compliance across all subsidiaries on one dashboard, and each operates with its own brand, data, and encryption key.

Trade unions and associations

Raise the standard for all your associates

An agreement incorporates dozens of organizations with preferential conditions. The trade association is moving from issuing recommendations to providing a tool.

Agreement and certification

Your team gets certified on the platform and frameworks that it will implement.

Branded portal

We've opened the parent organization and partner portal so you can incorporate the authorized identity and co-branding you need.

Account Addition

Each organization in your network enters in isolation, with its own framework, brand and corporate colors, structure and its own plan.

Optional network support for your channel.

Service 01

Consultancy

The judgment work that no software can replace: understanding the organization, interpreting the standard, and deciding which controls apply and to what extent.

  • Diagnosis of gaps against the corresponding framework
  • Scope of the management system and statement of applicability
  • Risk analysis and definition of the treatment plan
  • Data map, purposes and legal bases
  • Preparation for accreditation or certification

Service 02

Implantation

Leaving the system running within the platform, with the client's people using it. That's what separates an active license from a renewing client.

  • Configuration of the structure, subsidiaries, units and roles
  • Loading frameworks, controls, assets, and providers
  • Migration of existing evidence and documentation
  • Implementation of the RAT, the ARCO channel and the incident registry
  • Team training and handover of operations

How we certify our partners

You pass your subject

You present the certifications you already have in security, data, quality, occupational safety, or industry regulations. This defines which verticals you can work with.

We'll train you on the platform

Training on the multi-standard engine, frame loading, RAT, ARCO channel and evidence generation, with a dedicated environment to practice and demonstrate to your clients.

You obtain accreditation

Evaluation and visibility of certified partner by subject, which you can show to your clients and which they can verify on our site.

You take stock and recertify

We assign accounts based on your specialty and territory. Accreditation is renewed when the frameworks change, ensuring your team stays up-to-date.

Directory of certified partners

Public and verifiable: the client checks the credentials before signing, and the partner gains visibility through certification. Complete with the actual network.

Ally Certified materials Vertical Territory Credential
Example Consultant A ISO 27001 · ISO 27005 · Law 21.719 Health RM and Valparaíso Valid until 2027
Example Consultant B NIST CSF · CIS · Law 21.663 OIV and the public sector National Valid until 2027
Example Consultant C ISO 9001 · ISO 45001 · DS 132 Mining Antofagasta In recertification

Subjects in which we certify

Complete with the actual details of the program.

Information Security · ISO 27001 Risk Management · ISO 27005 Cybersecurity · NIST CSF and CIS Data Protection · Law 21.719 IT Governance · COBIT Offensive Security · CISSP and related standards Quality · ISO 9001 Occupational Health and Safety · ISO 45001 Environment · ISO 14001 AI Management · ISO 42001 Health Accreditation CMF and Fintec Regulations

What we measure, and what we don't

A signed agreement is not an incorporated organization. The program is evaluated by active organizations within your network, not by announced agreements—and that's how we report it.

Discuss the channel program. Certify me as an ally.

Free diagnosis

How exposed are you to Law 21.719?

Four questions. In the end, you'll see your level of exposure and the gaps that an auditor would check first. No installation required and no commitment.

1. Do you have an up-to-date Record of Processing Activities?

2. How do data subjects exercise their rights today?

3. Can you prove when a control was applied and who applied it?

4. Do you use AI in processes that affect people (admission, selection, scoring)?

What you receive

A gap map, not a brochure

The report lists your gaps prioritized by risk of sanction, with the article that mandates them and what evidence would need to be produced to close them.

What is it for afterwards

This is the agenda for the first meeting

If you decide to talk to us, we don't start with a product presentation: we start with your own gaps on screen.

Access to the platform

How do you want to log in?

There are two different doors, because they are two different worlds: the team that operates the organization from within, and the people that the organization serves.

Internal portal

I am a user of an organization

Internal team entry: administrators and users who operate the modules according to their profile and level in the structure.

  • Your access respects your role: you only see the data that corresponds to you.
  • Each session is recorded as evidence of access control
Enter the portal
Extranet

I am a supplier, affiliate, or subscriber

Services extranet: access the portal with your institution's branding for procedures, documents, identity verification and enabled services.

  • Use the branded link provided by your institution.
  • You can exercise your rights regarding your data from the same portal.
Go to the extranet

Did you lose your institution's link?

Each branch has its own extranet address, with its logo and colors. If you don't have it handy, ask the organization that's helping you: we can't provide it, because the portal and its users belong to them.

Resources

What's coming, when, and what to do beforehand

The Chilean regulatory calendar has fixed dates and different consequences depending on who you are. Here's what you need to have ready, free of charge and without prior registration.

Regulatory calendar

Already in force — Law 21.663 Cybersecurity Framework

Obligations required for essential services and Vital Importance Operators: ISMS, cybersecurity officer, risk management, and incident reporting to ANCI within three hours. Fines of up to 40,000 UTM.

July 2026 — Final OIV list

ANCI has completed its first rating process. The rated institutions now have enhanced obligations, without an adjustment period.

December 1, 2026 — Law 21.719 fully enforceable

The Personal Data Protection Agency becomes operational, with powers to investigate ex officio, impose sanctions of up to 20,000 UTM, order the suspension of processing and publish a national register of sanctions.

December 1, 2027 — The grace period for smaller businesses ends

For the first twelve months, they receive a written warning instead of a fine for their first offenses. After that, the full disciplinary regime applies.

Downloadable guides

Guide

RAT Checklist

What fields does Law 21.719 require, how to set up your processing activities, and the errors that appear in the first review.

Download →

Guide

First 90 days of the data officer

30, 60 and 90 day plan for the person who has just assumed the role: what to collect, what to document and in what order.

Download →

Guide

Minimum evidence before the ANCI

What is required in an incident report, how to run the three-hour deadline, and what backup is needed before it happens.

Download →

Regulatory alerts

We'll notify you when the rule changes.

You'll receive an email when a resolution is published, a deadline changes, or a framework that affects you is updated. There's no fixed frequency: you'll only receive emails when there's something to do. This is exactly what the platform does internally.

Contact

We show you the platform with your own reality.

The demo is not a feature tour: we load one of your real processes and you see what evidence is left when someone runs it.

Healthcare , Banking and Fintech, Public Sector , Mining, Higher Education , OIV , Consulting Firm, Holding Company or Association

Company details

Company name LOF Limited
Brand BRAINLOF · lofconsultoria.com
Home Santiago, Chile
Business mail info@lofconsultoria.com
Rights over your data info@lofconsultoria.com
Business Hours Monday to Friday, 9:00 to 18:00

RUT and telephone number are completed before publishing: they are a requirement in technical evaluations of tenders.

Law 21.719

Rights channel

Exercise your rights regarding the personal data processed by LOF Limitada : access, rectification, cancellation or deletion, objection, portability, and blocking. We respond within the legal timeframe.

We only ask for your RUT (Chilean tax ID number) to verify your identity. If your data is processed by an organization that uses BRAINLOF, exercise your rights with that organization through its own portal: this channel is for LOF Limitada as the data controller.