Infrastructure for Secure and Trustworthy AI
Federated data access, enforceable data governance, and trustworthy AI evaluation for organisations building collaborative AI systems.
Secure foundations for collaborative AI
BRAIN++ develops foundational infrastructure that helps organisations discover, govern, share, and use data and AI systems securely.
The infrastructure combines governed access to distributed datasets, technical enforcement of data-use conditions, tamper-evident accountability, and tools for evaluating AI safety, transparency, robustness, and regulatory readiness.
Together, these capabilities allow public institutions, research organisations, healthcare providers, companies, and other partners to collaborate without surrendering control over sensitive data, systems, or strategic assets.
Two connected layers of data and AI trust
From federated, governed data collaboration to trustworthy AI evaluation.
CHAIN++
A federated data infrastructure and permissioned data-governance chain for discovering, connecting, and using distributed public and proprietary datasets while preserving control for data owners.
CHAIN++ combines metadata management, governed access, federated learning, cryptographic smart contracts, local policy enforcement, and tamper-evident audit trails in a single architecture.
Discover CHAIN++COMPL-AI
A trustworthy AI framework for evaluating systems against safety, transparency, bias, robustness, and regulatory expectations.
It supports responsible AI documentation, risk analysis, benchmarking, and EU AI Act readiness.
Explore COMPL-AIBuilding open-source data trust for collaborative AI
CHAIN++ is BRAIN++'s federated data infrastructure and permissioned data-governance chain. It enables organisations to discover, connect, and use distributed datasets for sensitive AI workloads while data remains under the control of its owners and may stay within their own infrastructure.
AI collaborations are frequently delayed by uncertainty around data ownership, residency, permitted processing, compliance, and what happens when information is shared across organisational and infrastructure boundaries.
CHAIN++ combines federated data discovery, metadata management, governed access, and federated learning with technical enforcement and accountability. Contractual conditions can be translated into operational controls, without requiring all participating data to be centralised inside the AI Factory.
Core principle
Data owners should remain in control of their data, even when it is used in collaborative AI workflows across independent organisations and infrastructure environments.
See how CHAIN++ works
Explore the architecture, governance model, security layers, and practical applications of CHAIN++.
How CHAIN++ works
CHAIN++ coordinates data sharing across independent AI infrastructure networks through three complementary layers.
Cryptographic Smart Contracts
Data-use conditions are recorded as cryptographically protected rules on a permissioned, multi-participant chain. These conditions can cover data residency, approved processing, access duration, expiration windows, approved environments, and other contractual restrictions.
The Data Guardian
A local client-side application inspects and classifies outgoing data before transfer. It compares each proposed action against applicable contract and policy rules and can block a non-compliant transfer before data leaves the organisation’s infrastructure.
Tamper-Evident Audit Trails
Kernel-level eBPF monitoring records relevant file execution, data-access, and container activity. Events receive cryptographic fingerprints, supporting technical evidence for compliance review, governance, incident analysis, and multi-party accountability.
From written obligations to technical controls
CHAIN++ connects legal, organisational, and technical data governance.
Instead of treating a data-sharing agreement as a document checked only after an incident, relevant conditions become part of the operational workflow.
- Who may access the data
- Where the data may be stored or processed
- Which infrastructure environment may be used
- Which processing operations are permitted
- How long access remains valid
- When permissions must expire
- Whether onward transfer is permitted
- Which actions must be recorded
- Which violations must block an action
Engineered for high-stakes collaboration
CHAIN++ is intended for sectors where data sharing must be controlled, traceable, and aligned with legal and institutional obligations.
Healthcare & Life Sciences
Secure collaboration around clinical registries, research cohorts, biomedical data, health datasets, and multi-institutional AI research.
Financial Services
Controlled development of fraud detection, risk analysis, anomaly detection, and other models while protecting confidential consumer and transaction data.
Public Sector
Cross-institutional AI projects requiring clear permissions, data-sovereignty safeguards, auditability, and accountable processing.
Research & Industry
Collaboration involving proprietary or sensitive datasets while preserving control over permitted uses, access conditions, and processing environments.
How the two technologies work together
BRAIN++ infrastructure supports the complete path from federated, governed data collaboration to accountable AI development and evaluation.
CHAIN++
Connects distributed datasets and supports discovery, metadata management, governed access, and federated learning. It also defines and enforces how data may be transferred, accessed, processed, retained, and audited.
COMPL-AI
Evaluates resulting AI systems for safety, robustness, transparency, bias, risk, and regulatory readiness.
Together, CHAIN++ and COMPL-AI create an end-to-end trust layer for collaborative AI: federated and governed data access, enforceable conditions for its use, and structured evaluation of the systems developed from it.
Designed for European data and AI governance
CHAIN++ provides technical capabilities that can support an organisation’s wider compliance and governance programme.
Relevant areas may include GDPR obligations, EU AI Act readiness, European Health Data Space requirements, contractual data controls, cybersecurity policies, data residency, access governance, and accountability.
The technology does not replace legal assessment, organisational controls, impact assessments, or regulatory obligations. It provides verifiable technical mechanisms that can help implement and evidence those requirements.
Open by design
CHAIN++ is being developed with the intention of making the underlying technology available as open source at its official production release.
Proof of Concept
The current PoC is an internal technical milestone validating the architecture, enforcement model, and audit mechanisms.
Public code release
The planned GitLab release will allow developers, researchers, security specialists, and compliance teams to inspect and explore the codebase.
Community audit and contribution
Open development can support independent review, integrations, interoperability, sector pilots, and wider community contributions.
Read the CHAIN++ Whitepaper
Explore the architecture, governance model, security mechanisms, implementation approach, and proposed applications.
Explore CHAIN++ on GitLab
Follow development and access the repository when the public open-source release becomes available.
Developed within Bulgaria’s AI Factory ecosystem
CHAIN++ is developed within the BRAIN++ ecosystem at Sofia Tech Park, combining advanced computing, AI expertise, data infrastructure, trustworthy AI, training, business support, and European collaboration.
BRAIN++ is co-funded by the EuroHPC Joint Undertaking and the European Union.
Build trusted AI collaboration with BRAIN++
Contact the BRAIN++ team to discuss secure data sharing, federated infrastructure, trustworthy AI evaluation, research collaboration, or a potential CHAIN++ pilot.