Advanced Architecture
Automated Scanning: Continuous Telemetry and Scan Pipelines
Compliance should not require manual data entry. EuroCompliant connects to your code, your databases and your cloud accounts, runs twelve specialised engines against them, and writes dated findings back to the right checklist items. Your raw data is scrubbed locally before anything is stored, so nothing personal ever leaves your environment.
Transcript
Compliance should not require manual data entry. EuroCompliant connects to your code, your databases and your cloud accounts, and runs the checks for you on infrastructure we operate in Europe.
In Settings, open Scan Connectors and add a source. Here, a GitHub repository. Databases, cloud accounts and object storage connect the same way. Credentials are held as short lived secrets and used only while a scan runs.
Start a scan by hand, or let the scheduler run one every fifteen minutes. A short lived scan job spins up, fetches a read only copy of the data, runs the engine, then shuts down and leaves nothing behind.
Now open Scans and then Systems. The Syft engine found an AI framework in a repository that was never registered as AI. The platform raises a Shadow AI warning and adds the system to your inventory by itself.
That is one of twelve engines. Syft builds the software bill of materials. Presidio with GLiNER finds personal data and special category data in databases. Prowler checks cloud settings. Trivy lists vulnerable dependencies. The endpoint audit checks device compliance. Each finding is tagged with its framework so it lands on the right checklist.
Personal data never leaves your environment. Presidio replaces names, email addresses and sensitive attributes in memory before anything is stored. Only the finding type, the severity and a salted location hash are kept, so no transfer outside the EEA ever happens.
Filter findings by framework or severity, select a batch, and set a status in one action. That is the dated evidence Articles 10 and 15 ask for, produced without manual data entry.
Why this is required
Article 10(2)(f) and (g) require training, validation and testing datasets to be examined for biases likely to affect health, safety or fundamental rights, with appropriate measures to detect, prevent and mitigate them. Article 15 requires high-risk systems to achieve appropriate accuracy, robustness and cybersecurity, including resilience against data poisoning, model poisoning, adversarial examples and confidentiality attacks, and to declare the metrics in the instructions for use under Article 15(3). You cannot declare a metric you have never measured.
For generative and language-model systems this is not theoretical. Prompt injection can subvert instructions, a model can be induced to disclose training data or system prompts, and outputs can be steered into prohibited content. An undocumented LangChain or Transformers import can turn a supposedly conventional service into an in-scope AI system overnight. Article 15 makes resilience a legal requirement, not a security nice-to-have.
Testing where the data goes is itself a compliance question. Sending prompts, outputs or database rows to a third-party analysis service is a processing operation and, if that service sits outside the EEA, a Chapter V transfer you must then justify. The evidence has to be produced without creating a new transfer problem.
Article 9's risk-management duty is continuous across the entire lifecycle. A scan performed once at launch and filed does not satisfy it. Evidence must be reproduced after any material change, whether a model version, a prompt, a guardrail or a data source, and must be traceable to when it was produced and what it found.
What EuroCompliant does
Scheduled scan jobs. Each scan runs as a short lived job on infrastructure we operate in Europe. It fetches only the data it needs, runs the selected engine, writes the findings, and shuts down. Nothing persists afterwards, and every job is scoped to your organisation and visible in the Scan Jobs table.
Twelve scan engines, each mapped to a framework obligation. Syft builds the software bill of materials and detects AI frameworks such as LangChain, Transformers, Torch and ONNX, which is what powers Shadow AI detection. Presidio with GLiNER finds personal data and GDPR Article 9 special-category data in Postgres, scored per record. Prowler checks cloud posture against CIS benchmarks. Trivy lists vulnerable dependencies and containers. The identity audit checks for dormant accounts and missing multi-factor authentication. The endpoint audit checks Intune and Jamf device compliance. Giskard, Modelscan and Compl-AI test language-model robustness, prompt injection and model artifact integrity. Findings are tagged by framework so they flow to the right checklist automatically.
Local scrubbing before storage. Presidio's Anonymizer replaces names, email addresses, national IDs and Article 9 attributes in memory before any metadata is written. Only the finding type, severity, framework and a salted location hash are kept. No personal data is sent to a US-owned service for analysis, so there is no cross-border transfer to justify under GDPR Chapter V.
Shadow AI detection. When a scan finds an AI framework in a repository or container that your inventory still lists as a conventional system, the platform promotes it to AI, raises a warning, and flags the risk classification for review. The scan result is attached as dated evidence feeding the Article 10 and 15 checklist items and the Article 72 post-market monitoring record.
Deadlines
Walking through it
Connect a GitHub repository and a Postgres database
In Settings, open Scan Connectors and add each source: a repository, a database with a read-only role, or a cloud account. Credentials are held as short lived secrets and used only while a scan runs.
Open /settings/integrations?tab=scan-connectors →Run a scan, or let the schedule do it
Click Run now, or wait for the scheduler to enqueue due scans. The job fetches a read-only copy of the target, runs the engine, writes findings, and shuts down.
Open /scans →Watch Shadow AI detection in action
Open Scans and then Systems. A finding naming the detected framework appears, the inventory gains the auto-discovered system, and its risk classification is flagged for review.
Open /systems →Triage findings by framework and severity
Filter the register, select a batch, and apply a status in one action. Findings already carry the article reference, so they map straight to the right checklist items.
Open /scans →Re-scan after material change
A model version change, prompt change or new data source invalidates prior results. Article 9's continuous duty applies here too; scans can run nightly or be triggered from your build pipeline.
Open /scans →The law
Data and data governance
Datasets must be examined for possible biases, with appropriate measures to detect, prevent and mitigate them.
Accuracy, robustness and cybersecurity
Resilience against data poisoning, model poisoning, adversarial examples and confidentiality attacks, with declared accuracy metrics.
Risk management system
Testing to identify the most appropriate risk management measures, performed throughout the development process.
Security of processing
Technical measures appropriate to the risk, including a process for regularly testing and evaluating their effectiveness.
Processing of special categories
Processing of health, racial, political, sexual orientation and other special-category data, detected by Presidio with GLiNER before it becomes a breach.
ICT risk management tools
Financial entities must use tools to detect ICT anomalies. Prowler posture checks and Trivy vulnerability scans evidence this directly.
Supply-chain security
Measures to manage supply-chain risk, including provider security. The software bill of materials and vulnerability tracking feed this.
Management of technical vulnerabilities
Endpoint compliance via the MDM audit: encryption, patch level and enrolment evidence.
Vulnerability handling
Manufacturers must identify and document vulnerabilities in products with digital elements. Vulnerability scans and the software bill of materials feed Annex VII technical documentation.
Penalties for non-compliance
Article 99 sets fines up to €15M or 3% of worldwide turnover for breaching Articles 9–15. GDPR Article 83 sets up to €20M or 4% for processing without appropriate technical measures. Undocumented testing is treated as no testing.
Frequently asked
Does scanning make us compliant with Article 15?
It produces the evidence a compliance argument needs, but the obligation is broader: it covers the system's design, its technical resilience measures and its declared accuracy. Scanning tells you where you stand; it does not by itself fix what it finds.
How often should scans run?
After any material change to the model, prompt, data or configuration, and on a recurring schedule set by your post-market monitoring plan. Article 72 expects systematic collection rather than occasional sampling.
Is our data sent to a third-party service for analysis?
No. Presidio's Anonymizer runs inside the scan job itself. It replaces names, email addresses, national IDs and Article 9 attributes in memory before any metadata is written. Only the finding type, severity, framework and a salted location hash are stored, and the scanning infrastructure is in Europe, so no cross-border transfer arises.
What is Shadow AI detection?
If a scan finds an AI framework in a repository or container that your inventory still lists as a conventional system, the platform promotes it to AI, raises a warning, and flags its risk classification for review. The scan result is linked as evidence, so you can see exactly what triggered it.
Related guides
Post-market monitoring
The Article 72 duty to actively watch a high-risk system for its whole life, and why AI systems degrade without anyone changing the code.
Compliance checklists
How Articles 9 to 15 become tracked, owned, evidenced work rather than a document nobody reads.
Evidence vault & audit trail
Turning completed checklist items into artefacts a regulator can inspect, and the logging duties behind Articles 12 and 26.
Cryptographic Assurance: Audit Chains and Document Signing
Sealed documents and a tamper evident audit trail, with a verification link anyone can open in a browser. No login needed.
MCP Server: AI-Native Compliance via Cursor and Claude
Connect Cursor or Claude Desktop to EuroCompliant over SSE and query compliance posture in plain language.
Try it on your own systems
Everything in this guide runs in the live product. Start a free trial and follow along with your own data.
Start free trial