Governance & evidence
Automated document generation and cryptographic signing
Most of what a compliance framework actually demands in writing -- a policy, a record of processing, a technical file -- follows a predictable shape once the underlying data exists. Generating it from your own systems and risk assessments removes the blank-page problem, and signing the result gives anyone you hand it to a way to check it hasn't been altered since.
Transcript
Most of what a framework demands in writing follows a predictable shape once the underlying data exists. Generating it from your own systems removes the blank-page problem.
Open Compliance and Docs, then the Documents tab. It lists every generatable document, organisation-wide and per system, and how many are already generated.
Generating a document produces a real preview from your actual data: the system's classification, the frameworks you have enabled, the vendors on your register. Not filler text.
Downloading as a PDF is the same generation call, additionally signed if signing is enabled for your plan. Watch for the banner that appears once it's ready.
That banner's Verify link opens a public page, reachable by anyone with no login required, confirming the content hash and signing key fingerprint independently of the app that generated it.
The result is a document your own data produced, and a signature anyone can check without having to trust your word for it.
Why this is required
GDPR Article 5(2)'s accountability principle requires a controller to be able to demonstrate compliance, not merely assert it. A generated document that cites the real system, the real risk classification, and the real date it was produced is evidence; a hand-written template with the details filled in from memory is not.
AI Act Article 11 requires technical documentation to be drawn up before market placement and kept up to date, containing the Annex IV information. Regenerating it from current data each time is what keeps 'up to date' true rather than aspirational.
A document that changes after it was issued -- deliberately or by accident -- is a real risk when auditors, regulators, or customers rely on it. A cryptographic signature over the exact content at the moment of signing means a later dispute has an independent answer, not just competing claims.
What EuroCompliant does
The Documents tab in Compliance & Docs lists every generatable document, organisation-wide and per-system, and shows how many have already been generated. Generating one produces a real preview from your actual data -- the system's classification, the frameworks you have enabled, the vendors on your register -- not filler text.
Downloading a document as a PDF is the same generation call, additionally signed if signing is enabled for your plan: the response carries a verification link that isn't shown anywhere else, so it's worth keeping alongside the PDF itself.
A signed document embeds a verification ID and shows a 'Document signed' banner with a Verify link. That link opens a public page -- reachable by anyone you send it to, with no login required -- confirming the content hash and signing-key fingerprint independently of the app that generated it.
Walking through it
Open Documents
Compliance & Docs, then the Documents tab, lists what's available to generate for your organisation and for each system.
Open /compliance-docs?tab=documents →Generate and preview
Generate (or Regenerate) produces the document from your current data; the preview shows exactly what would be downloaded.
Open /compliance-docs?tab=documents →Download as PDF and verify
Download PDF triggers signing if it's enabled for your plan. Follow the Verify link on the signed banner to see the independent, public confirmation.
Open /compliance-docs?tab=documents →The law
Frequently asked
Why don't I see a 'Document signed' banner when I download?
Signing is a plan-tier feature. If it isn't enabled for your organisation, downloads still work exactly as before -- you just get the plain PDF without a verification link.
Where do I find a document's verification link later, after I've already downloaded it?
It's only surfaced once, at download time. Keep it alongside the PDF if you plan to hand the document to an auditor or regulator who might want to check it independently.
What does the public verification page actually check?
That the document's content hash matches what was signed, and that the organisation's audit trail is still internally consistent. It confirms authenticity; it does not display or store the document's content itself.
Related guides
Policy versioning and staff acknowledgment
Every regenerated policy keeps its history, and staff sign-off is tracked against the exact version they read.
Documentation & evidence generation
Generating Annex IV technical documentation, declarations of conformity and framework records from data you have already entered.
Records of processing (RoPA)
The Article 30 record: the foundational GDPR document, and usually the first thing requested in an investigation.
Evidence vault & audit trail
Turning completed checklist items into artefacts a regulator can inspect, and the logging duties behind Articles 12 and 26.
Try it on your own systems
Everything in this guide runs in the live product. Start a free trial and follow along with your own data.
Start free trial