Platform Features
Continuous scanning,
not manual bookkeeping
Eleven automated scan engines continuously discover Shadow AI, PII, and cloud misconfiguration across your codebases, databases, and infrastructure, feeding evidence straight into your EU AI Act, GDPR, ISO/IEC 42001, NIST AI RMF, DORA, and CRA obligations.
AI & Shadow AI Discovery
AI Framework Discovery (Syft)
Auto-discover AI and ML framework usage across your git repositories, LangChain, OpenAI, PyTorch, scikit-learn and more, via a real software bill of materials (SBOM), and auto-register a draft AI System Card for each one before your compliance team even knows it exists.
Model Artifact Security (ModelScan)
Scan a registered AI system's model file (pickle, H5, SavedModel, PyTorch) for unsafe serialization patterns with Protect AI's ModelScan, directly addressing Article 15's robustness and cybersecurity obligation.
LLM Red-Teaming (Giskard / garak)
Probe your chat models for prompt injection, jailbreaks, and other adversarial vulnerabilities using NVIDIA's garak against a curated set of deterministic probes, no external AI judge required.
AI Act Compliance Benchmarking (COMPL-AI)
Run a curated subset of ETH Zurich / INSAIT's COMPL-AI benchmark suite, cyberattack resilience, fairness, toxicity, AI-disclosure, against your chat models, fully automated within the platform.
Privacy & PII Discovery
Contextual PII Detection (Presidio + GLiNER)
Scan Postgres databases with Microsoft Presidio's local NLP models to auto-discover PII, names, emails, national IDs, and auto-populate your GDPR Record of Processing Activities.
Multi-Source PII & Secrets (Hawk Eye)
Scan object storage, additional databases, and SaaS sources (S3, MySQL, MongoDB, Redis, Google Drive, Slack) for PII and hardcoded secrets in one pass, reusing Hawk Eye's own connector logic.
EU-Specific PII Patterns
Catch country-specific identifiers general-purpose scanners miss, BSN, Codice Fiscale, NIR, IBAN, via a manually code-reviewed, commit-pinned scanner with no telemetry and no hidden network calls.
GDPR Article 9 Special Category Data
Detect health data, religious beliefs, political opinions, trade union membership, sexual orientation, and racial origin via GLiNER zero-shot NLP, run entirely in-cluster, every sample is redacted through Presidio's own Anonymizer before it's ever persisted as evidence.
Infrastructure & Security Posture
Cloud Security Posture (Prowler)
Continuously scan AWS, GCP, and Azure against CIS benchmarks and DORA ICT resilience requirements (Articles 6-15) with Prowler, surfacing misconfigurations and excessive permissions as they happen.
Vulnerability Scanning (Trivy)
Scan git repositories and container registries for unpatched CVEs, misconfigurations, and leaked secrets with Trivy, enforcing DORA Article 9 patching obligations automatically.
MDM Endpoint Audit (Intune / Jamf / Kandji)
Poll Microsoft Intune, Jamf Pro, and Kandji over read-only APIs to verify disk encryption, OS patching, and passcode enforcement, zero agents installed on employee devices.
Identity & Access Audit
Poll Google Workspace, GitHub Organizations, and Microsoft 365 to enforce MFA and flag dormant or orphaned accounts, satisfying ISO 27001 A.5.15-A.5.18 and DORA Article 9 automatically.
GDPR & Data Protection
DSAR Manager
Track data subject access requests from intake to completion with status tracking and deadline management.
Breach Center
Log and manage data breaches. Track the 72-hour supervisory-authority deadline separately from the Art. 34 duty to notify affected data subjects directly when a breach is high-risk to their rights.
DPO Designation (Art. 37)
Designate your organisation's Data Protection Officer once, with their contact details satisfying Art. 37/38 transparency requirements everywhere they're needed, documents, the trust center, and regulator communications.
Record of Processing Activities
Generate RoPA documents covering lawful basis, data categories, retention periods, and DPO details.
Vendor & Processor Tracking
Maintain a register of data processors with DPA status, contracts, cross-border transfer tracking, and automated risk scoring, critical or high-risk vendors are flagged for review. Vendors can complete their own due-diligence questionnaire through a secure, one-time link, feeding the risk score directly.
DPIA Support
Data Protection Impact Assessment templates aligned with Art. 35 requirements.
Consent Records
Track consent collection, withdrawal, and lawful basis verification across processing activities.
Cross-Border Transfer Tracking
Track data transfers outside EU/EEA and document adequacy decisions, SCCs, or BCRs.
No AI Required
All GDPR tools work standalone. You do not need to register AI systems to use data protection features.
AI System Registry
System Inventory
Auto-populated from Shadow AI discovery, or register systems manually with owner, vendor, purpose, and deployment status.
Tags & Labels
Categorise systems for filtering and reporting.
Risk Owner
Assign responsibility for each AI system.
Version Tracking
Track system and vendor versions.
Bulk Import
Import multiple systems from CSV.
AI Risk Assessment
Guided Questionnaire
15-question assessment based on Article 6 and Annex III with structured risk factor breakdown.
6-Level Classification
Prohibited, High-Risk, Limited, Minimal, Unclassified.
Risk Score & Justification
Quantified risk with detailed explanation of why each factor contributes to the score.
Prohibited Practice Deployment Block
A Prohibited classification (Article 5) automatically raises a critical compliance action and blocks that system's deployment status from being set to production, platform-wide, not just a warning label.
Cross-Framework Compliance
Framework Configuration
Enable EU AI Act, EU GDPR, UK GDPR, CCPA/CPRA, ISO/IEC 42001, NIST AI RMF, DORA, NIS2, ISO/IEC 27001, ISO/IEC 23894, and the Cyber Resilience Act per tenant.
Unified Control Crosswalk
Master tasks map to multiple frameworks so one evidence item can support several obligations.
Framework Badges
Checklist items show the active framework references and rationale behind each mapping.
ISO/IEC 42001 Readiness
All 51 real obligations across the Clause 4-10 management-system requirements and the full Annex A control set (38 controls).
NIST AI RMF Mapping
All 72 real subcategories across Govern, Map, Measure, and Manage, sourced from NIST's own AI RMF Playbook.
DORA Operational Resilience
ICT risk management, incident classification and reporting, third-party risk, and concentration-risk tasks across all 13 real DORA articles.
Cyber Resilience Act
Manufacturer obligations, vulnerability handling (with real software bill of materials data), and technical documentation for products with digital elements.
Public Trust Center
Publish a branded page showing framework completion, published policies, and vendor risk summaries, default off, every disclosure opt-in. Gate sensitive documents and evidence files behind a digital NDA that records each signer to the tamper-evident audit log before they download.
Document Generation
10 AI Act Documents
System Card, Risk Report, Tech Docs, Audit Log, Instructions, Oversight, Governance, QMS, Declaration, CE Marking.
5 GDPR Documents
RoPA, DPIA, DSAR Log, Processor Register, and Breach Report.
HTML & PDF Export
Professional documents ready for submission.
Tamper-Evident Export
Cryptographic server seal and immutable audit log on every exported PDF. Prove exact generation timelines to regulators and automatically invalidate manual edits.
Policy Versioning & Acknowledgment
Every regenerated document keeps its full version history. Mark any policy as requiring staff sign-off and track exactly who has acknowledged the current version, satisfying ISO 27001 A.6.3. Staff acknowledge directly from their own My Compliance page, no admin access needed, no emailed link to chase.
Approved Answer Library
Build a reusable library of approved answers from your generated documents. Paste, or upload a vendor's questionnaire file directly (CSV, Excel, or Word), and matching answers auto-fill instantly, with CAIQ-Lite, SIG-Lite, and VSA starter templates for day one. Unmatched questions can also auto-answer straight from your live scan evidence, verified against your actual scans, not guessed. Index your published policies and anything still unmatched surfaces a cited, extracted suggestion for review, never AI-generated, never auto-submitted.
Custom Policy Authoring
Author your own corporate governance documents (security, privacy, HR, engineering) directly in the platform. Custom policies get full version history and hook straight into staff acknowledgment and the audit matrix.
Bulk User / Group / Role Import
Provision team members, groups, and custom roles in bulk from a CSV export -- each row sets role, department, group membership, and additional grants, with per-row reporting and plan-limit enforcement, so a large organisation can onboard thousands of users without an IdP.
SCIM Provisioning & SSO Lockout
Connect your identity provider (Okta, Microsoft Entra ID, Google, Keycloak) with standard SCIM 2.0 endpoints to keep users and groups in sync automatically. When a user is removed or deactivated in the IdP they are locked out of every login and session immediately -- no manual offboarding, and no stale access.
Assessments & Monitoring
AI Literacy (Art. 4)
Individual staff knowledge assessment with score, self-served from each employee's own compliance page.
Fundamental Rights (Art. 27)
FRIA for public authorities and essential services.
Post-Market Monitoring (Art. 72)
Track system performance and feedback.
Incident Reporting (Art. 73)
Log and track serious incidents.
Compliance Calendar
Never miss a deadline.
Compliance Plans & Gantt
Turn obligations into trackable tasks with deadlines, dependencies, milestones, and an interactive Gantt timeline.
Corrective Actions & Remediation Register
Open scan findings and compliance gaps become tracked corrective actions, prioritized by severity. Resolving an action requires evidence on record, and a cleared scan finding unless you explicitly override with evidence.
Authentication & Security
Email + Password
Standard login with strong password policy.
Google OAuth
Sign in with Google.
SAML & OIDC SSO
Enterprise single sign-on.
TOTP 2FA
Authenticator app verification.
Passkeys
Passwordless hardware key login.
MCP Server (Compliance-as-Code)
Native Model Context Protocol server. Ask Cursor, Claude, or your LLM agents about compliance posture in natural language, right where you code.
Tamper-Evident Audit Log
Every audit log entry is chained to the one before it with a SHA-256 hash, so altering or deleting a historical entry breaks the chain for everything written after it. Verify the full chain on demand from the Audit Trail page, one click confirms nothing has been tampered with.
Team & Collaboration
Granular Custom Roles
Build your own roles from a 70+ permission registry, or start from the built-in admin, department admin, editor, viewer, and auditor presets.
Multi-Role Assignment & Groups
Grant a team member more than one role, or create user groups that carry their own role grants, a group can span one department or several.
Department-Scoped Access
Restrict any role or group grant to a set of departments, with automatic roll-up to sub-departments, a department head sees their team and everyone under it, not just their own department_id. Anyone with broader access gets a global department filter to narrow their own view on demand, with every list still enforced server-side to exactly what they're allowed to see.
Multi-Client Management
Compliance professionals manage client orgs.
Support Tickets
In-app messaging with our support team.
Self-Service Platform
Instant Signup
Start your 14-day free trial in seconds.
Self-Service Billing
Manage your plan, payment method, and invoices.
In-App Support
Create tickets and chat with our team directly.
Data Export
Export all your data at any time.
Account Management
Update team, plan, and settings without contacting us.
Zero-Telemetry, Agentless
Every scan runs inside your own European infrastructure
Your code, data, and models stay on the platform. No scan engine calls an external AI provider, and MDM or identity checks are simple read-only API polls, nothing gets installed on an employee's device.
Coverage
Framework Coverage
The platform starts with EU AI Act and GDPR as the locked baseline, then lets each tenant enable additional frameworks. Checklist tasks are generated from a shared crosswalk so teams can reuse evidence across legal, privacy, certification, and resilience requirements.