Documentation
Every feature, and the law behind it
How every feature works, the EU articles behind each obligation, and narrated video walkthroughs of the real product.
Start here
Getting started
How EuroCompliant is structured, why the work has to happen in a particular order, and what the dashboard is telling you.
The small business compliance journey
The complete path for a small business, filmed end to end: create the account, onboard, register systems, classify risk, work the checklists, generate documents, and handle the GDPR and AI Act duties that follow.
Registering your systems
Building the system inventory that every other obligation attaches to, covering both AI and conventional systems, and deciding correctly what counts as an AI system.
GDPR & privacy
How data protection obligations run alongside the AI Act, and the parts of the GDPR that carry operational consequences.
Getting started
Set your organisation up, understand the dashboard, and learn the order the work has to happen in.
EU AI Act
Register systems, classify their risk, work the obligation checklists, and produce the technical documentation the Act requires.
Risk classification
The Article 6 assessment that decides which obligations a system carries, and why the reasoning matters as much as the result.
Compliance checklists
How Articles 9 to 15 become tracked, owned, evidenced work rather than a document nobody reads.
Fundamental Rights Impact Assessment
The Article 27 assessment deployers owe before putting certain high-risk systems into use, and how it differs from a DPIA.
GDPR & privacy
Records of processing, data subject rights, processors and the seventy-two hour breach clock.
Data subject requests (DSARs)
Tracking Articles 15 to 22 requests against the one-month statutory clock, including the automated-decision right that bites hardest on AI.
Breach notification
The seventy-two hour clock under Article 33, what the notification must contain, and when you must tell individuals directly.
Records of processing (RoPA)
The Article 30 record: the foundational GDPR document, and usually the first thing requested in an investigation.
Other frameworks
ISO 27001, ISO 42001, NIST AI RMF, DORA, NIS2, CRA, SOC 2, EHDS and CCPA/CPRA: what each one asks for, and honestly, how much of it this platform automates today.
ISO 27001: information security management
The international standard for an information security management system, and how EuroCompliant tracks your Annex A controls.
ISO 42001: AI management systems
The AI-specific counterpart to ISO 27001: how EuroCompliant currently supports it, and what's still coming.
NIST AI RMF: Govern, Map, Measure, Manage
The US voluntary AI risk framework's four functions, and an honest look at what the platform automates today.
DORA: digital operational resilience
What DORA requires of EU financial entities, and the real, working parts of the platform built around it: vendor criticality flags and infrastructure scanning.
NIS2: cybersecurity risk management
The EU's cybersecurity directive for essential and important entities, fully supported in the Obligations page.
CRA: Cyber Resilience Act for products with digital elements
The EU's product-cybersecurity regulation for hardware and software with digital elements: secure-by-default requirements, vulnerability handling, and technical documentation.
SOC 2: AICPA Trust Services Criteria
The AICPA's Trust Services Criteria used in SOC 2 audits: the Common Criteria (security) plus, where in scope, Availability, Confidentiality and Processing Integrity. 43 tracked obligations, 12 platform-managed today, backed by real scan, audit-trail and policy-acknowledgment evidence.
EHDS: European Health Data Space
The EU's regulation for electronic health record (EHR) systems and the primary and secondary use of health data. Entered into force March 2025, but doesn't apply until 26 March 2027 (staggered through 2031). This guide covers how to prepare early, not a present-tense compliance claim.
HIPAA: the U.S. Security Rule for health-tech vendors
The U.S. federal standard for protecting electronic protected health information (ePHI), covering Administrative, Physical, and Technical Safeguards. Essential if you're a European health-tech vendor selling into the U.S. healthcare market.
CCPA/CPRA: California consumer privacy
California's privacy law, and the real strength of the platform's support: a unified request pipeline with a CCPA-specific 45-day clock.
Ongoing operations
The duties that never finish: post-market monitoring, serious incidents, automated testing, vendor risk and the compliance calendar.
Post-market monitoring
The Article 72 duty to actively watch a high-risk system for its whole life, and why AI systems degrade without anyone changing the code.
Serious incident reporting
The Article 73 duty when a high-risk AI system causes serious harm, with deadlines that tighten to two days in the worst cases.
Integrations, scanning and vendor risk
Connecting your infrastructure for automated scanning, wiring up notifications, and tracking third-party risk.
SCIM provisioning and evidence ingestion
Sync your directory automatically with SCIM 2.0 and push evidence or test results from any CI/CD pipeline into the Evidence Vault or findings log.
The compliance calendar and reporting dashboard
The cross-framework view: every deadline in one calendar, and where your overall compliance posture is measured.
Automated access reviews
Connecting an identity provider so access reviews are a dated, automated finding instead of an annual assertion.
Vendor and processor risk scoring
A structured questionnaire turns a vendor register into a dated, explainable risk score per vendor.
Vendor self-service due-diligence questionnaires
Send the same risk questionnaire directly to a vendor's own contact, instead of assessing them on their behalf.
Approved answer library and auto-fill
Approved answers to security questionnaire questions, reused automatically the next time the same question appears.
Compliance plans, milestones, and deadlines
Turn obligations into trackable tasks with deadlines, dependencies, milestones, and a Gantt timeline.
Agent Runtime Telemetry
Stream signed execution decisions from your autonomous-agent runtime firewall straight into tamper-evident audit evidence.
Enterprise Risk Register
A board-level 5x5 risk heatmap with inherent vs. residual scoring, linked straight to your remediation roadmap.
Whistleblower reporting channel
Provide anonymous, safe reporting channels that meet EU Whistleblower Directive requirements.
Deployer Workspace
Your six duties as a deployer of high-risk AI, shown per system so you can see exactly where gaps remain.
ADM Register and Human Override
Log every automated decision that affects people and track contest requests and human overrides.
Scan Findings Become Corrective Actions Automatically
High and critical scan findings automatically become tracked corrective actions that require evidence to close.
Governance & evidence
Audit trails, the evidence vault, AI literacy, and the people-and-access side of compliance.
Documentation & evidence generation
Generating Annex IV technical documentation, declarations of conformity and framework records from data you have already entered.
Evidence vault & audit trail
Turning completed checklist items into artefacts a regulator can inspect, and the logging duties behind Articles 12 and 26.
AI literacy
Article 4 applies to nearly everyone deploying AI, it has been in force since February 2025, and it is the obligation most organisations discover last.
Team, roles and access control
Inviting your team, assigning roles, organising departments, and locking down accounts with 2FA and SSO.
Automated document generation and cryptographic signing
Generate regulator-ready documents from your own data, then download a signed PDF an auditor can verify independently.
Policy versioning and staff acknowledgment
Every regenerated policy keeps its history, and staff sign-off is tracked against the exact version they read.
My Compliance: the employee self-service page
Where any team member, not just admins, signs off on required policies and completes their own AI literacy check.
Publishing a trust center
A public page, at your own address, answering the security questions a prospect would otherwise ask by email.
Certifications and credentialing
Test your team's knowledge with non-accredited online certifications and shareable PDF credentials.
Transparency and Synthetic Content Marking
Disclose AI interaction, mark synthetic content, and document deep-fake provenance.
Conformity Assessment Room
Give a notified body or auditor read-only access to your conformity documents without an admin account.
GPAI Systemic Risk
Track general-purpose AI models and record systemic-risk assessments for high-compute models.
Advanced Architecture
How the platform actually runs: scheduled scan pipelines, hash-chained ledgers and document signing under the hood.
Automated Scanning: Continuous Telemetry and Scan Pipelines
How scheduled scan jobs, 12 scan engines and local PII scrubbing produce dated Article 10/15 evidence without moving data outside the EEA.
Cryptographic Assurance: Audit Chains and Document Signing
Sealed documents and a tamper evident audit trail, with a verification link anyone can open in a browser. No login needed.
Developer Tools
Compliance-as-code: query your posture from Cursor or Claude Desktop via the Model Context Protocol.
Execution Workflows
Turn obligations and scan findings into a Gantt-tracked remediation programme with loop-closed evidence.
See it running on real data
Every walkthrough in this documentation is captured from the live product, not mockups. Start a free trial and follow along.
Start free trial