This site is in preparation.
The service is still being completed and cannot be booked yet. Sign-up is closed for the time being; existing accounts can still sign in.
Regulation (EU) 2024/1689 · compliance automation
Find every AI in your company, classify it, evidence it.
The AI Act starts with an inventory: which AI is in the house, what it does, which obligations follow. The scanner reads your repositories and finds AI components down to file and line; AI you bought, with no code of its own, you enter beside it. Both come back with a risk tier, a rationale and article references — and with the document drafts that hang off them.
Most of it is no longer preparation: the AI-literacy duty (Art. 4) and the prohibited practices (Art. 5) have applied since 2 February 2025, the transparency obligations for chatbots and generated content (Art. 50) since 2 August 2026. The Annex III high-risk requirements apply from 2 December 2027 — the later part of the work, not the first.
Not bookable yet – the service is in preparation.
See an example reportFree account · no credit card · one public repository
- netcup, data centres in Germany (ISO 27001)
- No model training on your code
- Business customers only (§ 14 BGB) · tenant isolation in the database
AI-generated drafts for expert review — no substitute for legal advice; no liability for content accuracy.
Incremental scan · 12 changed files read
1 new finding compared with the previous scan
src/chat.py:12
import anthropic client = anthropic.Anthropic(api_key=settings.anthropic_key)resp = client.messages.create(model=MODEL)Finding
The chatbot interacts directly with end users, so the transparency obligation of Art. 50(1) applies — users must be able to tell they are interacting with an AI system.
AI-generated · Draft for expert review · no substitute for legal advice
Audit package (HMAC-signed)Example report
A look at the report before you sign up
Four systems as they sit side by side in a real company — three in your own code, one bought in — and what the scanner says about each of them.
Example · excerpt from a scan report
Finding
src/chat.py:12
client = anthropic.Anthropic(api_key=settings.anthropic_key)Classification
A language model answers end-user requests. Anyone talking to an AI system must be able to tell — that is the transparency obligation of Art. 50(1), however harmless the application may be.
AI-generated · Draft for expert review · no substitute for legal advice
Cited passages
What follows from it
- Transparency block for the interface, ready to embed
- Draft of the transparency notice as a PDF
- Checklist item Art. 50(1) with a slot for the evidence
Example data. In the product every cited passage opens the full text of the regulation at exactly the place the classification rests on.
Process
The same work, started differently
The regulation asks for an inventory first: which AI is in the house — the AI you built and the AI you bought — what it does, and which obligations follow. That opening move is what the scanner takes off your desk.
By hand
- Read through every repository, every dependency and every bought tool just to learn where AI is in use — and start over at the next release.
- Locate each finding among 113 articles and 13 annexes, and justify the mapping.
- Draft six document types from nothing, each repeating the same facts about the system.
- Evidence who decided what and when — usually reconstructed from tickets after the fact.
With the scanner
- One scan reads the repository and reports every finding with file and line; bought systems enter the same register without a scan. The first result is there within minutes.
- Every component comes back with a classification, a rationale and article references — each cited passage readable in the full legal text.
- The six drafts are built from the findings and the system profile; open points are marked rather than invented.
- Every change lands in a signature-chained history that exports as an audit package.
We deliberately quote no euro saving here: what a manual audit costs inside your company is not something we know. What the scanner costs is further down.
Three steps
From a connected repository to an evidenced compliance file.
- 1
Register a system
Connect a repository through the GitHub App, GitLab or an access token — or enter a bought system that has no code of its own. Scans start manually or automatically on every push; the automatic kind is enabled per repository.
GitHub · GitLab · bought systems
- 2
Scan & classify
Deterministic detection across all languages, a software inventory from 8 ecosystems, then a classification per component with a rationale and article references.
finding → verdict → passage
- 3
Drafts & evidence
Document drafts as PDF, embeddable transparency blocks, an obligations checklist with attached evidence and one audit package per system.
PDF · blocks · audit package
Regulation
Coverage along the regulation
What the scanner delivers per article — ordered by when the duty binds, and with what deliberately stays with you.
The expert assessment of your system and the legal review of the drafts remain with you and your legal counsel.
From a system to a compliance file
Everything essential in one place: detection, classification, drafts, deadlines, evidence.
Detection in code
Heuristic detection of LLM APIs, embeddings, vector databases and frameworks across all languages; a software inventory from 8 ecosystems. Scans run manually, incrementally or on every push (GitHub & GitLab). Bought AI systems are registered without a repository and carried in the same register from then on.
Languages read
- Python
- TypeScript
- JavaScript
- Java
- C#
- Go
- Rust
- Ruby
- PHP
- Jupyter
- +34 more
Dependency manifests read
- pypi
- npm
- maven
- go
- cargo
- nuget
- rubygems
- composer
Six document types
Transparency notice (Art. 50), AI literacy (Art. 4), risk management (Art. 9), technical documentation (Art. 11), instructions for use (Art. 13), fundamental-rights impact assessment (Art. 27) — as labelled drafts, in your language on request, as PDF.
Art. 50 transparency blocks
Deterministically built, embeddable notice blocks (HTML/Markdown/text/JSON) per obligation and role — ready to copy into your website or app.
Risk classification
Every detected component is mapped along the regulation's risk pyramid — with an AI-generated rationale and article references, grouped per component.
Deadlines & obligations
A deadline calendar along Art. 113 with personal relevance plus an obligations checklist derived from your system profile (role, deployment area, Annex III, Art. 6(3)).
Audit trail & team
HMAC-chained, tamper-evident event history, team roles, a scoped public API and GDPR tooling (export, deletion, retention) — hosted in the EU.
What the tool does — and what it explicitly does not
This is not a seal of approval. It is the groundwork that otherwise eats weeks before the actual assessment can even begin.
The scanner
Finds what is in the code, maps it onto the regulation, keeps every cited passage readable and pre-writes the drafts. Deterministic where it can be; labelled where a model did the writing.
Your own experts
Know the purpose, the role and the deployment area of each system. No scanner can read those off the code — and half the classification hangs on them.
Your legal counsel
Judges and takes responsibility. The drafts arrive prepared and fully structured instead of as a blank page — they still have to be reviewed.
Checkable
What you can hold us to
Checkable commitments instead of badges — each one also stated in the legal pages.
Servers in the EU
Application, database and backups run at netcup GmbH (Karlsruhe) in data centres in Germany. Every further service involved is listed with its purpose and place of processing in the subprocessor register.
AI can be switched off
Switch AI processing off for your organisation and the deterministic detection stays — classification and drafts fall away, and no code excerpt leaves the system any more.
Every service named
The subprocessor directory names every service in use with its purpose, the data it processes and where — publicly readable, no account needed.
A gapless history
Every action lands in an HMAC signature-chained event history with its author. Editing after the fact shows up when the chain is verified.
You set the retention
Scans are deleted automatically once your retention period passes (default: 365 days). Export and irreversible deletion of the organisation are yours to trigger at any time.
Passwords never touch us
Sign-in runs through a separate identity service; the application never handles credentials. Two-factor sign-in can be switched on.
Plans
Pricing
You pay per monitored system, not per scan: scanning on every push is included and is not billed. Pay yearly and save two months.
Free
Price to be announced
- One monitored system, scans not billed
- Public repositories only, results as a summary, no credit card
Starter
Everything in Free, plus:
- 3 monitored systems
- 300 AI-classified components a month
- 10 AI document drafts a month
- Private + public repositories
- Full findings (file, line, code)
- AI assistant for questions about the regulation
Professional
RecommendedEverything in Starter, plus:
- 15 monitored systems
- 1,000 AI-classified components a month
- 45 AI document drafts a month
- Auditor tools: audit-package export, sign-offs, public statement
Enterprise
Everything in Professional, plus:
- Unlimited systems (fair use)
- 3,000 AI-classified components a month
- 120 AI document drafts a month
Nothing is billed per unit. A component counts only when you have it classified — scanning does not count against these figures. When the month's budget is empty nothing breaks: scans keep running, findings keep appearing, only the AI classification pauses until the first of the month. A run that starts with budget left always finishes, and components that were skipped or failed do not count.
Included in every plan
- Unlimited users and team roles — no per-seat surcharge
- Scans not billed — including on every push
- HMAC-SHA256 hash-chained event history with actor — later edits show up when the chain is verified
- Data processing agreement, subprocessor register and technical-measures annex readable without an account
- Public API and GDPR tools: export and deletion on your own
The plans show the intended scope. Prices will be published at launch; until then this is not an offer.
Frequently asked questions
What teams want to know before the first scan.
Is my source code sent to an AI model?
Detection runs deterministically on our side — no code leaves the system for it. For the classification and the document drafts, excerpts of the affected code go to the language model. That AI processing can be switched off per organisation; detection and inventory then remain.
Does this replace legal advice or an audit?
No, and it is not built to. Everything a model wrote is labelled as a draft and stays labelled in the PDF. The scanner prepares the inventory and the paperwork; the judgement and the responsibility stay with you and your legal counsel.
Where do the servers run, and who can reach the data?
Application, database and backups sit in the EU. Every further service involved is listed with its purpose and location in the subprocessor directory, readable without an account. Inside the application, each organisation is separated from the others at the database level.
Which repositories can be connected?
GitHub through the GitHub App or an access token, GitLab through an access token — self-hosted GitLab instances included. Whole organisations can be imported at once; every repository comes back with a decision and a reason, so nothing is quietly left out.
What about AI we did not build ourselves?
Bought systems are registered without a repository: vendor, purpose, role and area of use come from the system profile rather than from code. From then on they sit in the same register and receive the same classification and the same document drafts as a scanned repository — the regulation's obligations attach to the deployment, not to who wrote the software.
How does the scanner know what the regulation says?
The official full text lives in the system, section by section, in several languages and with a version stamp. Every verdict remembers the sections it rests on — one click on a cited passage opens the original text at exactly that spot. Unaltered official texts carry no AI label, because they are not AI output.
What happens on a push?
If automatic scanning is enabled for a repository, the scanner looks only at what changed and compares the result with its predecessor. Only a deterioration is reported — a first scan is an inventory, not a regression.
Are the generated documents ready to file?
They are fully structured and filled from your system profile, but they are drafts. Facts nobody could know appear as a marked gap in the text rather than as invented wording. Only a person can sign a draft off — with their name and the time recorded.
What does it cost, and what happens if I cancel?
You pay per monitored system, not per scan: scans are not billed. To try it out, the free account with one public repository is enough, no credit card. Plan changes and cancellation happen in the app at any time; afterwards all data can be exported or irreversibly deleted.
Ready for your first scan?
Register, connect a repository and see the first risk map of your code within minutes. Free, no credit card.