Operations · Compliance · Artificial Intelligence
Operate while you comply
The consultancy delivers documents; the Agency oversees operations. Manage your assets, projects, people, suppliers, risks, incidents, plans, activities, and AI agents within the platform, and the evidence is automatically generated, traceable back to the article required by law.

The real problem
Nobody breaks the law on purpose. The problem is not being able to prove it.
Your organization already backs up data, controls access, requests consent, and evaluates vendors. What it lacks is a dated, attributable, and traceable record of those operations—which is exactly what's required when an audit comes around.
Today
Compliance exists outside of operations
The organization works on its systems, and, on the other hand, someone transcribes what happened into a document management system, so they have something to respond with. The report is already outdated.
With BRAINLOF
Multiple high-use functions integrated: the operation happens inside and the evidence is issued in the same act. There is no delay in transcription.
Today
Each standard is a separate project
ISO 27001 on one hand, Law 21.719 on the other, quality and occupational safety in separate folders. The same controls are implemented three times.
With BRAINLOF
A single agnostic engine crosses the frames and establishes your baseline. An evaluated control unit meets all the required standards.
Today
There are not enough specialists.
Chile has an estimated shortage of 28,000 cybersecurity professionals. There aren't enough people to do this work manually, at any price.
With BRAINLOF
AI provides the framework with its controls, documents, and activities, and guides you step by step. What previously required a specialist can now be done by your team.
Today
The holder has no way to exercise their rights
RAT, consent, and the ARCO channel are mandatory for any organization that processes personal data, regardless of its size. Almost no one has them operational.
With BRAINLOF
ARCO portal, consent management, and live RAT powered by your own operations. Always included, never tied to a higher plan.
Today
Holdings, networks, and guilds cannot govern their members
A holding company doesn't see the state of its subsidiaries; a trade association recommends but cannot provide tools; a health network repeats the same work in each establishment.
With BRAINLOF
Real multi-organization: each subsidiary with its own brand, data, and encryption key; the parent company consolidates without seeing what doesn't belong to it.
Today
Your industry regulations are not in any software.
Health Superintendency Accreditation, CMF regulations, DS 132, CNA accreditation: no international suite models them, and translating them by hand takes months.
With BRAINLOF
Chilean sectoral frameworks are pre-configured, maintained, and updated when regulations change. No new project required.
This is what it looks like inside
Operational platform, not just documentary
Review some views of the platform operating on a demo institution. The data is fictitious; the structure and behavior are real.
The important reading is not where the risk is, but how much it has shifted. If the two matrices look the same, the controls are ineffective. Each cell reveals the risks it contains, along with their owner and the associated process.
Inherent risk · 23
Impact 1 → 5 · vertical probability
Residual risk · the same 23
After the applied treatment
The clock starts ticking from the recording, not from the meeting. Each incident carries a severity level, phase, responsible leader, and the notification deadline required by the policy—with the deadline in sight.
| Code | Incident | Severity | Phase | Leader | Next deadline |
|---|---|---|---|---|---|
| INC-2026-001 | Ransomware on file server | S1 Critical | Phase 3 | Cybersecurity Officer | Wins in 1 hour 40 minutes |
| INC-2026-002 | Phishing targeting internal accounts | S2 High | Phase 2 | Cybersecurity Officer | Wins in 6 hours |
| INC-2026-003 | Spreadsheet display in shared folder | S1 Critical | Phase 4 | Data Protection Officer | Notified |
| INC-2026-006 | Loss of equipment containing personal data | S2 High | Phase 2 | Data Protection Officer | Under evaluation |
| INC-2026-008 | Malware on laboratory equipment | S4 Low | Phase 1 | IT Support | No deadline |
Fixed and auditable rules based on the data your organization already has uploaded. It's not a model making opinions: it's a deterministic rule that reviews your own information and identifies the specific records that generate each finding. Then the AI makes suggestions; you decide.
Processes marked as critical on the data map for which no one has yet stated what could go wrong.
They store sensitive personal data or confidential information and do not declare encryption at rest.
Each control requires documentation, and each document has a defined frequency and responsible party. The system generates the evidence calendar and shows which regulations each item covers. A document management system stores files; this is a requirement.
| Document | Controls | Class | State | Periodicity | Coverage |
|---|---|---|---|---|---|
| Minutes of the constitution of the security committee | GOV-03 | Minutes or record | Earring | Unique | ISO 27001 · 2 |
| Catalog of personal data | GOV-02 · PRV-01 | Report | In development | Annual | Law 21.719 · 4 |
| Minutes of the review of the risk methodology | RISK-01 | Minutes or record | Earring | Annual | ISO 27005 |
| Matrix of profiles and privileges in systems | IAM-02 · IAM-04 | Matrix | In development | Monthly | ISO 27001 · 3 |
| Minutes of the security committee meetings | GOV-03 | Minutes or record | Earring | Quarterly | Law 21.663 · 5 |
44 documents required by the active framework · the due dates calendar is automatically generated
CRM also leaves evidence. Every opportunity, contact, and campaign is based on legality and traceable consent, so the sales area is no longer the blind spot of RAT (Real-Time Advocacy).
Open Opportunities Funnel
Pipeline weighted by stage
The regulatory obligation appears on the agenda of the person who has to comply with it. Committees, evidence deadlines, notification periods, and RAT reviews don't just exist in a report: they arrive on the responsible person's calendar, with their origin clearly visible.
Each activity retains the module and control that originated it. If it is rescheduled, the regulatory deadline does not change.
The platform assistant only sees documentation, never your data. It explains what each application does, the best order to configure it, and what is recorded in each field, limited to what the user's profile has available. It does not access your information or perform actions on your behalf.
Administration
Demonstration views with fictitious data. The actual configuration depends on the framework and structure of each institution.
The category difference
Almost everything sold as compliance in Chile is a document manager with workflow
Upload the document, approve it, save it, and let someone remember it in a year. It's useful for organizing paperwork, but the evidence is still the paper—and the audit doesn't ask about the paper, it asks about the transaction behind it.
The usual approach
Document manager and workflow
Policy and procedure repository, with approvals and reminders. The organization continues to operate externally, on its own systems, and someone has to manually transcribe what happened there and transfer it here.
- The document is the end, not the consequence.
- The evidence is transcribed, and that's why it's delayed.
- Nothing forces what is written to coincide with what is done
Our approach
Multiple frequently used functions, integrated together
Daily operations take place within the platform: assets, projects, people, suppliers, firms, campaigns, and customer service. The document is issued as a result of these operations, not the other way around.
- A single piece of data feeds management, risk, and compliance.
- The evidence is dated and attributed, but without a transcription.
- What is written and what is done cannot differ: they are the same record
The difference lies in the crossing
For all work fronts, a single engine that runs through them all
Each module operates independently and delivers its data to the others and to the AI-powered multi-standard engine. This cross-referencing generates evidence—dated, attributed, and traceable back to the specific article required by law—which is something a document management system cannot produce by design.
- You capture a piece of data once and it serves assets, risk, people, and compliance all at once.
- One engine for all frames: ISO 27001, NIST CSF and laws 21.719 and 21.663.
- The AI reasons about that crossing with strict isolation by organization.

The functions that are integrated
Each function operates independently and delivers data to the others and to the compliance engine. This cross-functionality is what a document management system cannot, by design, produce, no matter how many approval workflows it adds.
Where do you enter?
Two ways to work with the platform
Clinics and health networks, banks and fintech, municipalities and state services, mining operations, universities and all Vital Importance Operators qualified by ANCI.
- Your industry framework already loaded, not a generic template
- Evidence ready for audit from the first month
- You start with what you need and add capabilities when the time comes.
Consulting firms that implement, holding companies that govern subsidiaries, trade associations and guilds that need to raise the standard of all their members at the same time.
- Multi-organization with its own brand through subsidiary or associate
- Your methodology within the platform, not ours on top of it
- Recurring income instead of projects that end
The central idea
When you operate, you've already fulfilled your obligations.
This isn't a marketing promise: it's a consequence of where the data resides. Since the asset, the project, the person, and the supplier are all within the platform, the control required by the standard is satisfied by the record already generated by the transaction.

Native data protection
A single safeguarding standard for all your relationships
Law 21.719 does not distinguish between a client and a job applicant: both are considered data subjects. Every person you register enters the system based on legality, consent, and organizational isolation, and contributes to the same Record of Processing Activities.
Business relationship
Contacts and clients
Record with complete history, declared purpose and consent for each authorized contact channel.
Contractual relationship
Suppliers and third parties
Evaluated and monitored, with a treatment agreement and evidence that expires.
Employment relationship
Employees and collaborators
Sensitive employment relationship data is protected, with access limited by role and traceability of each query.
Service link
Patients, students and members
They log in through the extranet with identity verification, exercise their rights, and see what is done with their data.
Artificial intelligence
The AI executes. You're in control.
Within the platform, AI drafts, evaluates each control individually, reads documents, and provides voice support—and your people decide how far it goes, what requires a signature, and what needs to be reversed. Since Law 21.719 regulates automated decision-making, we provide you with the tools to govern all the AI used by your organization.
View the full AI layerBRAINLOF Assistant
Generates the preliminary evaluation of Law 21.719 for the admissions area.
Customer control
We give you the platform. You retain control.
A compliance platform handles an organization's most sensitive assets: its data, its evidence, and the decisions it makes about people. None of that can be left on the vendor's side.
Your data
Your own encryption key
Each organization stores its documents with its own key, in private storage. Neither the storage provider nor we have access to the content.
Your evidence
Exportable whenever you want
Your compliance history is yours and is available in audit format. Your continued participation should be a choice, not an exit cost.
Your AI
You set the thresholds
What can an agent handle alone, what requires a person's signature, and what is automatically reversed? Autonomy is defined by your team, system by system.
Your people
You define who sees what
Profile, privilege and resource: each person only has access to what their role and level in the structure enable, and each access is recorded.
Your reach
Add and subtract what you use
Modules, frameworks, and subsidiaries adapt as your needs change. No user limits and no paying for what you don't need.
Your brand
The portals are yours
Each branch serves its patients, providers, or members using its own logo and colors. The account holder sees your institution, not us.
What makes us different
Four advantages for better service.
This is a difficult combination to replicate, as we integrate seamlessly into complex coverage areas and adapt to your organization's operational needs if required. With consultants who possess extensive experience in the cybersecurity and technology market, we have created unique solutions not only for documentation but also for operational compliance, ensuring order and efficiency while our users provide continuous service.
Advantage 01
Operational layer with underlying compliance
GRC suites manage controls and monitor external systems. BRAINLOF also manages assets, projects, people, firms, campaigns, and identity: evidence originates internally, it's not imported.
Advantage 02
Chilean sectoral depth
Superintendency of Health, Law 20.584, DS 132 and SERNAGEOMIN, CMF regulations, Law 21.521 Fintec, CNA accreditation and DS 44. It is the barrier that an international entrant does not amortize in a market of this size.
Advantage 03
Multi-organization with branding by subsidiary
A parent company governs subsidiaries with strict isolation, and each subsidiary opens its own portals for providers, affiliates, or patients. This is what technically enables the network and channel model.
Advantage 04
Extranet with agents who serve your customers
Customers, students, subscribers, affiliates, or suppliers resolve their procedures 24/7 , supported by AI that verifies identity, executes and closes — and each interaction is based on legality, consent, documented record and strict compliance.
Reference case
Cristo Vive Foundation: primary care in Recoleta, with SGSI operating
Construction of a complete Information Security Management System under a hybrid framework of CIS, NIST and ISO 27001 for the CESFAM Cristo Vive, covering health regulations, telemedicine and electronic medical record, including laws 19.628, 21.719, 21.663, 20.584 and 21.459.
The CESFAM has been operating since 1993 through an agreement with the North Metropolitan Health Service and is part of the public health network. A provider like this handles sensitive data from an entire population, with extended hours and emergency care: there's no window to pause operations while compliance is implemented. Service agents, on the other hand, are available 24/7, regardless of the examination room's hours.
Population served
25,000
people from Recoleta and surrounding areas under the family health model
Annual visits
+20,000
people treated each year in the health area of the Foundation
Operating from
1993
in agreement with the North Metropolitan Health Service
Implemented frameworks
3 + 2
CIS, NIST and ISO 27001, cross-referenced with laws 21.719 and 21.663
Coverage figures published by Fundación Cristo Vive. These figures correspond to the provider's operations, not to BRAINLOF users.
Certified consultants
The platform doesn't arrive on its own. It arrives with those who know how to implement it.
Your implementation is handled by a consultant with accredited certification in your relevant field: information security, data protection, quality, workplace safety, or industry regulations. This is what transforms a license into a fully functional management system—something no international suite offers in Chile.

Verifiable credentials
You know who enters your organization
The assigned consultant provides proof of their subject matter expertise and is certified on the platform. You can request both before signing.
Coverage by specialty
The specialist that your standard requires
The profile of someone implementing an ISMS is not the same as the one preparing a health accreditation or a mining DS 132. You are assigned based on your subject matter, not your availability.
Independence
We implement; a third party certifies.
The network provides consulting and implementation services, not certification auditing. This separation is what makes the evidence you provide valid for both the certification body and the Agency.
Why this matters more than integration
Chile has an estimated shortage of 28,000 cybersecurity specialists. The bottleneck isn't the software; it's finding people to run it. Hiring that kind of professional today takes months and is competitive across the entire industry; here, it's included in the project.
Structure
An organization, at all levels
Model your institution, its subsidiaries or branches, its departments, units, and teams. Each level only has access to its own data, and assessments run through the entire structure or are consolidated upwards.
- Access control by role and organization, with separation of duties by design
- Customized branding by subsidiary: unique logo and color palette on each portal
- Evaluations by subsidiary, by department, or consolidated for the group
- Documents with envelope encryption and a unique key per organization

Sectors
Designed for Chile's most regulated industries
Frequently Asked Questions
The most frequently asked questions about compliance in Chile
When does Law 21.719 come into effect and what are the risks if I don't comply?
It was published in December 2024 and is fully enforceable from December 1, 2026, after a 24-month adaptation period. Penalties reach up to 20,000 UTM for very serious violations and up to 4% of annual income in case of repeat offenses. The Agency may also order the suspension of treatment and publish a national register of sanctions.
What is the Record of Processing Activities and why do I need it?
It's an inventory of how your organization processes personal data: purpose, legal basis, data categories, retention periods, and recipients. The law requires it to be kept up-to-date. At BRAINLOF, it's generated and maintained based on your data map and daily operations, without needing to be recreated each time.
What does Law 21.663 require and who enforces it?
It specifically requires essential services and Vital Importance Operators to implement an ISMS, appoint a cybersecurity officer, manage risks, and report incidents to the ANCI within a maximum of three hours. It is already in effect and has no grace period.
I'm a small business owner, do I have time?
Less than it seems. During the first twelve months of the program, smaller companies receive a written warning instead of a fine for their first violations. This ends in December 2027, and the warning does not exempt them from correcting the violations nor does it protect them against a claim from the license holder.
How does it differ from a traditional consultancy?
A consultancy delivers documents; an auditor reviews operations. BRAINLOF leaves traceable operational evidence, compliant with legal requirements and continuously monitored, instead of a report that becomes outdated. And it builds capacity within your team instead of taking the knowledge away at project completion.
Does it apply to all regulations or only to Chilean laws?
The engine is agnostic: ISO 27001, 27005, 9001 and 14001, NIST CSF, CIS, Chilean Standards and its own frameworks, in addition to Chilean laws 21.719, 21.663 and 20.584. The frameworks cross each other so that an evaluated control responds to all the standards that require it.
How do I know if my organization is a Vital Importance Operator?
ANCI classifies IBOs through a resolution and publishes the list. The first process closed on July 24, 2026. If your institution was classified, you will be notified and will have reinforced obligations that are immediately enforceable: ISMS, cybersecurity officer, risk management, and incident reporting within three hours, with fines of up to 40,000 UTM.
I'm not an OIV member, but my client is. Does this affect me?
Yes, and it's the way most organizations discover their obligations. Law 21.663 compels International Veterinary Organizations (IVOs) to demand standards from their supply chains, so you'll receive safety questionnaires and contractual clauses that didn't exist before. Responding with evidence, not promises, is now a requirement to continue doing business with them.
Is AI trained using my organization's data?
No. The AI layer is decoupled from business logic and operates with strict organization-wide isolation: neither the user nor the model accesses data outside the tenant and session role. Your data does not feed models or is used to improve service to other customers.
How do they prevent AI from inventing risks or controls?
Separating who finds from who writes. The recognition process works with fixed and auditable rules based on the data your organization already has uploaded, and each finding points to the specific records that generated it. Only then does the AI propose the written risk assessment, and a person accepts, edits, or discards it.
I already have ISO 27001 certification. What's the point?
Certification verifies a moment in time; oversight inquires about ongoing operations. The platform keeps the ISMS active between audits, cross-references your current framework with Laws 21.719 and 21.663 without requiring you to reinstate the same controls, and prepares the file for follow-up audits without having to rebuild it.
Can I upload my own framework or internal rules?
Yes. The engine is agnostic: in addition to the included frameworks, you can define your own frameworks with your controls, your required documents and your frequency, and cross-reference them with external standards so that an evaluated control responds to all of them at once.
How do they protect my organization's data?
Documents with envelope encryption and a unique key per organization in private storage, strict isolation between organizations, role-based access control, short-lived sessions, access logging, and defenses against the OWASP Top 10. The platform operates on hosting infrastructure with SOC 2 type II and ISO 27001 certification.
Do I need technical knowledge and how long does it take to implement?
You don't need to be an expert: AI provides the framework with its controls, documentation, and activities, and guides you step by step. What a traditional consultancy takes months is reduced to weeks. Implementation is handled by a certified consultant within the network, specializing in the area your standard requires.
What exactly do AI-powered service agents do?
They provide 24/7 support to your clients, patients, students, or suppliers via chat, voice, or portal; they execute the service workflow according to your organization's rules; they escalate cases to a human agent when they exceed the threshold defined by your team; and they record the interaction based on legality and consent. They do not make clinical, financial, or disciplinary decisions.
My organization uses AI in admissions or selection. Is that regulated?
Yes. Law 21.719 regulates automated decisions that affect people: it requires a legal basis, notification to the data subject, and the right to object. BRAINLOF allows you to inventory your AI systems, designate a responsible party for each one, record decisions, and specify what the model decides and what a person signs.
Can I take my data with me if I change platforms?
Yes. Your compliance history is yours and can be exported in audit format upon request. Your continued participation should be a choice, not an exit cost.
Do you work with consulting firms, holding companies, and trade associations?
Yes, in two different ways: we certify partners who implement the platform for their clients, and we establish channel agreements with networks that incorporate many organizations simultaneously. These agreements are signed separately because they are distinct relationships.
Am I required to appoint a data protection officer?
Law 21.719 requires the designation of data controllers and, in certain cases, a prevention officer with specific functions. Even if you weren't legally obligated, having someone designated with a written scope of responsibility is the first thing an audit will check. If you don't have anyone to appoint, your network of partners can provide this role externally.
What do I do if I suffer a data breach?
The platform records the incident using its taxonomy, activates the corresponding deadlines, and compiles the notification file. What cannot be improvised is the preparation beforehand: having the data map, the asset inventory, and the communication channel defined before the incident. That is the work the platform does for you.
Does it integrate with my current systems?
Today, the operation takes place within the platform, and the evidence originates there, not imported from outside. Native integrations with identity providers, cloud services, and SIEM, along with single sign-on and a public API, are under development. We mention this because it's the most frequently cited gap compared to international suites.
How does the assistant differ from the agents?
The platform assistant is for your team: it guides the setup and explains what is recorded in each field, and only views the documentation available for that profile—it does not access your data or perform any actions. Service agents are for your customers: they provide 24/7 support, handle entire processes, and leave a record of every interaction.
We are a network, a holding company, or a guild. How does it work?
A parent organization governs its subsidiaries or associates with strict isolation: each operates with its own brand, data, and encryption key, while the parent company consolidates the group's status. It's the same architecture that underpins the channel program, and it's already in place.
Can I try it before deciding?
Yes. The Law 21.719 exposure assessment is free, takes four minutes, and provides your prioritized gaps along with the relevant article that mandates them. If you proceed, this result serves as the starting point for the configuration, and the demo is based on your actual process rather than a product presentation.
Start by measuring
Stop gathering evidence. Start releasing it.
We'll show you, through a real-world process, how it's recorded when someone runs it within the platform. No obligation.
Platform
An agnostic engine, all your frames on the same basis
The same system that assesses ISO 27001 also manages Law 21.719, ISO 9001, workplace safety, Chilean Standards, and your internal regulations. Standards and legislation overlap, so an assessed control meets all the standards and laws you want to include, rather than starting from scratch with each certification or sector-specific regulation.
Engine
Control-by-control evaluation
With automatic guidance, real-time scoring, and traceability to the article of law.
- Included frames and custom frames
- Intersection between Chilean and foreign laws
- Single baseline per organization
- Expiration calendar and alerts
Evidence
Record with evidentiary value
Each transaction is dated, attributed to a person, and linked to the control it satisfies.
- Audits and findings with follow-up
- Reports, minutes and RATs automatically generated
- Exportable documentation for tax audit
- Historical data that is not lost
Architecture
Multi-organization with levels
Organization, subsidiaries, departments, units, teams and users, each with its scope.
- Strict isolation between organizations
- Custom brand per subsidiary
- Consolidated group evaluation
- Extranet with its own address per location
Example of structure
Security
Protection that withstands a penetration test
It's not a promise: these are implemented controls. And where we don't have something, we say so.

Envelope encryption by organization
Each organization stores its files with its own key on private storage. Not even the storage provider has access to the content.
Isolation between organizations
No data crosses from one session to another. Each query is limited to the session tenant, including those made by AI.
Role-based access control
Profile → privilege → resource, with separation of functions by design and traceability of each access.
Sessions and monitoring
Short-lived tokens, access and incident logging, and alerts for anomalous behavior.
OWASP Top 10 Defense
Parameterized queries, strict content policy, and protection against XSS, CSRF, and IDOR.
Provider infrastructure
We operate on hosting with SOC 2 and ISO 27001 certification and inherit their physical and operational controls.
Form for third-party questionnaires
Your OIV and banking clients are required to assess their supply chain. Here's what they need from us, published so you don't have to ask.
| Service model | Multi-tenant SaaS with strict isolation by organization |
| Application and data location | Hosting provider's data center, with SOC 2 and ISO 27001 certification |
| Cipher at rest | Envelope encryption with a key per organization, in private storage |
| Encryption in transit | TLS on all connections |
| Access control | RBAC by profile, privilege and resource, with separation of duties |
| Registration and monitoring | Access and incident traceability, alerts for anomalous behavior |
| Safe development | Parameterized queries, strict content policy, OWASP Top 10 defenses |
| Backups and recovery | Documented backup and recovery policy, to be completed with committed RPO and RTO |
| Sub-processors | Listing available by agreement, with a current commission contract |
| Retention and elimination | Defined by the client; export of the history in audit format at the end |
| Incident notification | To the client and, where applicable, to ANCI within the legal timeframe |
Facing the market
Where we won and where we haven't yet
A table with "yes" in all its own rows isn't information, it's advertising. These are the rows where we lose.
| Criterion | BRAINLOF | GRC International | GRC local | Consulting firm | Forms |
|---|---|---|---|---|---|
| It models the letter of the Chilean law | Yeah | Partial | Yeah | Yeah | No |
| Sectoral frameworks (health, mining, CMF, CNA) | Yeah | No | Limited | Yeah | No |
| Integrated high-use operational functions | 24 | Few | Documentary | N/A | No |
| Operational layer (assets, signature, Gantt chart, QR code, CRM) | Yeah | No | No | No | No |
| Reach the final headline (portal, ARCO, extranet) | Yeah | No | No | No | No |
| Unique biometric identity | Yeah | No | No | No | No |
| Multi-organization with branding by subsidiary | Yeah | Partial | No | No | No |
| Tools for people to govern AI | Yeah | Emergent | Certification | Project | No |
| Native integrations (cloud, IdP, SIEM) | In development | Extensive | Limited | N/A | No |
| Single sign-on (SSO) | On the roadmap | Yeah | Variable | N/A | No |
| Installed base and references | Incipient | Miles | Dozens | Wide | N/A |
| Network of certified partners in Chile | Yeah | No | No | Own | No |
| Leave installed capacity | Yeah | Yeah | Yeah | No | Fragile |
This is a comparative analysis by solution category, based on publicly available information as of the date of this report. It does not imply affiliation or sponsorship; trademarks belong to their respective owners.
Methodology
Built on global reference frameworks
ISO 27001 and 27005, NIST CSF, CIS Controls, ISO 9001 and 45001, Chilean Standards and laws 21.719, 21.663 and 20.584. LOF has consultants with individual certifications who support each implementation.

How to hire
Modular, layered.
The scope is defined by frameworks, structure, modules, and verticality — and the proposal is tailored to what you really need.
Compliance Core
Multi-standard engine, RAT, ARCO channel, consent, risks, incidents, critical assets, encrypted documents, and regulatory updates. This is the foundation, not a higher-level plan.
Operating and advanced modules
CRM, planning, people, campaigns, third parties, electronic signatures, biometrics, extranet, and full AI. These features are added and removed depending on your needs.
Sectoral vertical
Your industry framework is fully loaded, with evidence templates and supported implementation.
Consulting and implementation
Gap analysis, system scope, risk analysis, framework loading, evidence migration, implementation, and training — delivered by the network of certified partners in each subject, working within your own platform and not in a separate report.
Solutions
Each capability solves a specific problem and feeds into the others.
It's not a loose toolbox. Each solution operates independently and, in doing so, provides data to the others and the compliance engine. Open each one to see what it includes and what evidence it leaves behind.
From asset to risk, from risk to evidence
Solutions that share the same data
The equipment you register as assets is the same equipment that appears in the risk assessment, the supplier contract, and the accreditation documentation. Registering it once ensures compliance isn't extra work.

One piece of data, three uses
The medical equipment you record as assets is the same equipment listed in the risk assessment, the supplier contract, the maintenance plan, and the accreditation documentation. Recording it once ensures compliance isn't extra work.
Artificial intelligence
Three layers: the AI that helps you, the one that attends to you, and the one that your organization controls.
Most compliance platforms added a chat feature on top. Here, the AI is decoupled from the business logic but within the same isolation—neither the user nor the model accesses data outside the tenant and session role—and each action is attributed to the person who authorized it.

Layer 1
AI that helps you achieve
Where a consulting firm charges for weeks, the platform delivers in minutes, with the context of your own organization.
- Draft policies, procedures, and minutes
- Evaluate each control individually against the chosen framework
- Document vision: read, extract, and classify
- Recognition based on fixed and auditable rules regarding your own data
- It converts the findings into proposed risks that a person accepts, edits, or discards.
- Prioritize gaps and develop a remediation plan with those responsible.
- Conversational and voice assistant, always under the role of the user
- Platform assistant that guides you through the setup without accessing your data.
Layer 2
Agents who attend
Several specialized agents orchestrated around your data, available 24/7 : one receives, others resolve, one supervises, and another records the evidence.
- Scheduling, admission, procedures and applications
- ARCO channel assisted with identity verification
- First line of incidents with the ANCI clock ticking
- Supplier evaluation and monitoring
- 24/7 service, no appointments, no queues, and no business hours
- Scaling to one person with the full context
Layer 3
Control remains with your company.
Law 21.719 regulates automated decision-making, and ISO 42001 sets the standard. Neither of these requires anything of a model; they require accountability from a person within your organization. Our job is to provide the platform where that accountability can be exercised.
- Designated person responsible for each AI system, with its scope
- Inventory of the AI systems used by the organization
- Impact and bias assessment, approved by the appropriate authority
- Thresholds of autonomy: what the model decides and what a person signs
- Record of automated decisions and the data subject's right to object
- ISO 42001 framework on the same multi-standard engine
Rule the AI
When a model makes a decision about a person, someone has to respond.
AI governance isn't a software function; it's a set of human decisions—who authorizes each system, how far it can go on its own, who reviews its results, and who is accountable to the owner. We don't make those decisions for you; we provide the platform to make, record, and demonstrate them, using the same multi-standard engine that already manages your other obligations.

Why this matters now and not in two years
Any organization that has incorporated AI into admissions, selection, scoring, or customer service is making automated decisions about people. Under Law 21.719, this requires a legal basis, notification to the data subject, and the right to object—and it requires that there be someone capable of explaining the decision, not a provider to be questioned. It is a new obligation for which almost no one has the tools, and the only case where having AI and a compliance engine integrated is equally advantageous.
Orchestration
Four roles, one single conversation for the user
The lead agent speaks once. Behind the scenes, the agents pass the case among themselves as needed, without leaving the isolation of your organization or your assigned role.
Role 01
Reception
It's available anytime, every day. It understands the person's needs, identifies them, and decides which agent is appropriate. Available via chat, voice, or a branded portal for your institution.
Role 02
Specialists
They execute the specific flow: scheduling, admitting, processing, responding to an ARCO request or raising an incident.
Role 03
Supervision
Verify the response against the rules your organization has defined and escalate to a person when the case crosses the threshold. That threshold is set by your team, not the model.
Role 04
Compliance
It records legality, consent, and traceability in the RAT database. It transforms care into evidence without anyone having to document it afterward.
How far does an agent go?
Agents operate within the platform using its own agent management engine and are configured by vertical according to each institution's workflows. An agent does not make clinical, financial, or disciplinary decisions: it executes the workflows defined by your team, respects privacy and consent, and escalates any issues that cross the threshold to a human agent.
Facing a chatbot
Answering is not the same as solving, and solving is not the same as being able to prove it.
| Criterion | BRAINLOF Agents | Chatbot / IVR | Agent on generic suite | external call center |
|---|---|---|---|---|
| Complete the entire process | Yeah | No | Partial | Yeah |
| Attends and resolves 7x24 | Yeah | It answers, it doesn't solve. | Partial | In shifts |
| Leave evidence based on legality and consent | Yeah | No | No | No |
| It operates on the organization's data, isolated. | Yeah | Limited | Depends | He exports them |
| Register in the RAT what it deals with | Yeah | No | No | No |
| Scale to a person with full context | Yeah | No | Partial | Yeah |
| Integrations with third-party systems | In development | Spacious | Spacious | N/A |
| Installed base and references | Incipient | High | High | High |
The last two rows are real disadvantages compared to suppliers with years in the market, and they are declared in the business conversation, not afterwards.
Vertical
Your industry doesn't need a generic template
Each vertical comes with its own comprehensive regulatory framework, evidence templates, and implementation support. This is a layer that no international suite can fully utilize in a market the size of Chile's.
Vertical Health
Three pieces that are now one
The patient extranet, service agents, and the cybersecurity and data protection framework are integrated, because in health they do not work separately: the holder who exercises an ARCO right is the same patient who requests an appointment, and the data that identifies him is a special category.
The provider operates; the accreditation file is automatically compiled
Electronic medical record, telemedicine, patient consent and health data as a special category: each care leaves the record that accreditation and Law 21.719 require separately.

Loaded frame
Accreditation of the Superintendency
Standards for institutional providers, with evidence associated with each evaluated characteristic and responsible for each one.
Loaded frame
Law 20.584 and medical record
Patient rights and duties, confidentiality of electronic health records and traceability of access to health data.
Loaded frame
Telemedicine and healthcare network
Networked providers, remote consent, and safeguarding of the remote clinical session.
Operation
Patient extranet
Portal with provider branding, biometric verification, consent and access via QR code on site.
Operation
24/7 Service Agents
Scheduling and confirmation, admission and documents, assisted ARCO channel and post-care follow-up — at any time, using the provider's workflows. Care is not dependent on the examination room's hours of operation.
Operation
Sensitive data and OIV
SGSI ISO 27001 and 27005, Law 21.663 for qualified providers, and health data as a special category under Law 21.719.
Reference case
Construction of a complete ISMS under a hybrid framework of CIS, NIST and ISO 27001 for the CESFAM Cristo Vive, covering health regulations, telemedicine and electronic medical record, including laws 19.628, 21.719, 21.663, 20.584 and 21.459.
Higher education: accreditation is no longer a six-year project
A university operates in reverse: it operates for five years and then dedicates a full year to reconstructing the evidence of what it did. This vertical structure reverses that logic—each criterion of the CNA is linked to the operation that feeds it, and the dossier is built month by month.
Accreditation
CNA by dimension and criterion
Institutional and career-based, with associated evidence, responsible party and status for each criterion.
Data
Students and applicants as holders
Tens of thousands of holders with different purposes: admission, welfare, student health and research, each with its own legal basis.
Structure
Headquarters, faculties and units
The same multi-level structure that requires an accreditation file, with upward consolidation.
Actual state of this vertical
The CNA framework is under development, with a planned launch in 2027 alongside the mining sector. An institution can currently operate based on the core framework, Law 21.719, and ISO standards, and incorporate accreditation when it becomes available without migrating or redoing its existing evidence.
Network and channel
Two ways to be on BRAINLOF's side
We certify implementing partners: consultants and firms that put the standard into operation within the client's platform. And we agree on a channel with those who incorporate : networks that bring the platform to many organizations simultaneously. A single partner can be both, but the agreements are signed separately because the terms are different.
We certify you to implant
If you already do consulting in security, data, quality or sector regulations, we train and certify you on the platform so that you can deliver the complete project with it integrated.
- Training and certification credential by subject
- Ideal environment for practicing and demonstrating to your clients
- Account routing based on your specialty and territory
- The project ends with your client up and running, not with a delivered report.
We are adding organizations to the platform
Consulting firms with a portfolio, holding companies that govern subsidiaries, and guilds or associations that want to raise the standard of all their members at the same time.
- Multi-organization with its own brand through subsidiary or associate
- Preferential conditions and recurring commission for active organization
- Partner portal with authorized co-branding
Who brings what to the table
Consulting firms
Your methodology, with a platform behind it
You deliver the diagnosis and implementation as usual, but the client is left with installed capacity and you with recurring revenue instead of a project that ends.
Holdings
Group governance, autonomy by subsidiary
You consolidate compliance across all subsidiaries on one dashboard, and each operates with its own brand, data, and encryption key.
Trade unions and associations
Raise the standard for all your associates
An agreement incorporates dozens of organizations with preferential conditions. The trade association is moving from issuing recommendations to providing a tool.
Agreement and certification
Your team gets certified on the platform and frameworks that it will implement.
Branded portal
We've opened the parent organization and partner portal so you can incorporate the authorized identity and co-branding you need.
Account Addition
Each organization in your network enters in isolation, with its own framework, brand and corporate colors, structure and its own plan.
Optional network support for your channel.
Service 01
Consultancy
The judgment work that no software can replace: understanding the organization, interpreting the standard, and deciding which controls apply and to what extent.
- Diagnosis of gaps against the corresponding framework
- Scope of the management system and statement of applicability
- Risk analysis and definition of the treatment plan
- Data map, purposes and legal bases
- Preparation for accreditation or certification
Service 02
Implantation
Leaving the system running within the platform, with the client's people using it. That's what separates an active license from a renewing client.
- Configuration of the structure, subsidiaries, units and roles
- Loading frameworks, controls, assets, and providers
- Migration of existing evidence and documentation
- Implementation of the RAT, the ARCO channel and the incident registry
- Team training and handover of operations
How we certify our partners
You pass your subject
You present the certifications you already have in security, data, quality, occupational safety, or industry regulations. This defines which verticals you can work with.
We'll train you on the platform
Training on the multi-standard engine, frame loading, RAT, ARCO channel and evidence generation, with a dedicated environment to practice and demonstrate to your clients.
You obtain accreditation
Evaluation and visibility of certified partner by subject, which you can show to your clients and which they can verify on our site.
You take stock and recertify
We assign accounts based on your specialty and territory. Accreditation is renewed when the frameworks change, ensuring your team stays up-to-date.
Directory of certified partners
Public and verifiable: the client checks the credentials before signing, and the partner gains visibility through certification. Complete with the actual network.
| Ally | Certified materials | Vertical | Territory | Credential |
|---|---|---|---|---|
| Example Consultant A | ISO 27001 · ISO 27005 · Law 21.719 | Health | RM and Valparaíso | Valid until 2027 |
| Example Consultant B | NIST CSF · CIS · Law 21.663 | OIV and the public sector | National | Valid until 2027 |
| Example Consultant C | ISO 9001 · ISO 45001 · DS 132 | Mining | Antofagasta | In recertification |
Subjects in which we certify
Complete with the actual details of the program.
What we measure, and what we don't
A signed agreement is not an incorporated organization. The program is evaluated by active organizations within your network, not by announced agreements—and that's how we report it.
Free diagnosis
How exposed are you to Law 21.719?
Four questions. In the end, you'll see your level of exposure and the gaps that an auditor would check first. No installation required and no commitment.
1. Do you have an up-to-date Record of Processing Activities?
2. How do data subjects exercise their rights today?
3. Can you prove when a control was applied and who applied it?
4. Do you use AI in processes that affect people (admission, selection, scoring)?
What you receive
A gap map, not a brochure
The report lists your gaps prioritized by risk of sanction, with the article that mandates them and what evidence would need to be produced to close them.
What is it for afterwards
This is the agenda for the first meeting
If you decide to talk to us, we don't start with a product presentation: we start with your own gaps on screen.
Access to the platform
How do you want to log in?
There are two different doors, because they are two different worlds: the team that operates the organization from within, and the people that the organization serves.
I am a user of an organization
Internal team entry: administrators and users who operate the modules according to their profile and level in the structure.
- Your access respects your role: you only see the data that corresponds to you.
- Each session is recorded as evidence of access control
I am a supplier, affiliate, or subscriber
Services extranet: access the portal with your institution's branding for procedures, documents, identity verification and enabled services.
- Use the branded link provided by your institution.
- You can exercise your rights regarding your data from the same portal.
Did you lose your institution's link?
Each branch has its own extranet address, with its logo and colors. If you don't have it handy, ask the organization that's helping you: we can't provide it, because the portal and its users belong to them.
Resources
What's coming, when, and what to do beforehand
The Chilean regulatory calendar has fixed dates and different consequences depending on who you are. Here's what you need to have ready, free of charge and without prior registration.
Regulatory calendar
Already in force — Law 21.663 Cybersecurity Framework
Obligations required for essential services and Vital Importance Operators: ISMS, cybersecurity officer, risk management, and incident reporting to ANCI within three hours. Fines of up to 40,000 UTM.
July 2026 — Final OIV list
ANCI has completed its first rating process. The rated institutions now have enhanced obligations, without an adjustment period.
December 1, 2026 — Law 21.719 fully enforceable
The Personal Data Protection Agency becomes operational, with powers to investigate ex officio, impose sanctions of up to 20,000 UTM, order the suspension of processing and publish a national register of sanctions.
December 1, 2027 — The grace period for smaller businesses ends
For the first twelve months, they receive a written warning instead of a fine for their first offenses. After that, the full disciplinary regime applies.
Downloadable guides
Guide
RAT Checklist
What fields does Law 21.719 require, how to set up your processing activities, and the errors that appear in the first review.
Guide
First 90 days of the data officer
30, 60 and 90 day plan for the person who has just assumed the role: what to collect, what to document and in what order.
Guide
Minimum evidence before the ANCI
What is required in an incident report, how to run the three-hour deadline, and what backup is needed before it happens.
Regulatory alerts
We'll notify you when the rule changes.
You'll receive an email when a resolution is published, a deadline changes, or a framework that affects you is updated. There's no fixed frequency: you'll only receive emails when there's something to do. This is exactly what the platform does internally.
Contact
We show you the platform with your own reality.
The demo is not a feature tour: we load one of your real processes and you see what evidence is left when someone runs it.
Company details
| Company name | LOF Limited |
| Brand | BRAINLOF · lofconsultoria.com |
| Home | Santiago, Chile |
| Business mail | info@lofconsultoria.com |
| Rights over your data | info@lofconsultoria.com |
| Business Hours | Monday to Friday, 9:00 to 18:00 |
RUT and telephone number are completed before publishing: they are a requirement in technical evaluations of tenders.
Law 21.719
Rights channel
Exercise your rights regarding the personal data processed by LOF Limitada : access, rectification, cancellation or deletion, objection, portability, and blocking. We respond within the legal timeframe.
We only ask for your RUT (Chilean tax ID number) to verify your identity. If your data is processed by an organization that uses BRAINLOF, exercise your rights with that organization through its own portal: this channel is for LOF Limitada as the data controller.