Enterprise

Infrastructure design, at the scale of your organization

Every team gets a senior architect's review on every repository, with the controls your security team expects: single sign-on, IP allowlists, an audit log and your own AI provider.

For every team

One standard for every repository

Platform teams set the rules once; product teams get a reviewed design in minutes instead of weeks.

Teams and roles

Owner, admin, member and viewer. Invitations bound to a GitHub account, shared projects.

Reviews on every PR

Infrastructure, cost and security impact commented on each pull request, before merge.

Deployment in one click

Through your own GitHub Actions, followed live in Brunel, with credentials we never store.

Your AI provider

Run Brunel's architect on your provider and key, billed by your provider.

Security controls

Access, the way your security team wants it

Set by the team's owner and admins, enforced on every request, and recorded in the audit log.

Secrets sealed with AES-256-GCM, bound to their owner

Single sign-on

OIDC with Google Workspace, Microsoft Entra, Okta or any provider, optionally required for every member.

IP allowlist

IPv4 and IPv6 ranges, applied to every request, from the browser and from API keys.

Session length

Force members to sign in again after a set number of hours.

GitHub organization

Only members of your GitHub organization can join or sign in.

Audit log

Invitations, roles, sharing, deployments, security changes: who did what, and when.

Sign everyone out

End every member's sessions and API keys in one click.

Questions

Enterprise FAQ

Can Brunel use our own AI provider?

Yes. Set your provider, model and key (OpenAI, Claude, Mistral or any OpenAI-compatible endpoint) for the whole team. The key is tested, sealed, and never shown again. Prices and files still never come from the model.

Does Brunel get access to our cloud accounts?

No. Deployment runs in your GitHub Actions. With one-click deployment, credentials are sealed in your browser with your repository's public key and stored as GitHub secrets; Brunel never sees them in clear.

How is the Enterprise plan billed?

By contract, with invoicing. Tell us about your team and needs with the form; every request is read by the team and answered by email.

Where is data stored?

The app runs on Vercel. Repositories are deleted right after analysis; only the extracted facts and short excerpts are kept. See the security page for details.

Talk to us

Tell us about your team, your repositories and your constraints. Every request is read and answered by email.

Enterprise · Brunel