
We handle the paperwork. You keep running your business.
The first SME-focused Compliance-as-a-Service platform for the EU AI Act. Unlike enterprise tools costing $50k+, aissurance automates risk classification, evidence collection, and regulatory reporting — for a monthly subscription from €99.
The Pain
"I don't understand the law. I don't want to risk fines. I don't have time for all the paperwork."
- EU AI Act fines up to 7% of global revenue
- Enterprise GRC tools ignore SMEs
- $50k+ consulting engagements to fill out forms
- No engineering bandwidth to manage compliance
- Aug 2026 deadline is a ticking clock
The Solution
"We handle the paperwork. You keep running your business."
- Compliance-as-a-Service — from €99/month
- Zero-config discovery via Nomyo Router
- Automated risk classification & evidence collection
- Auto-generated regulatory documents
- Crypto-shredding for complete data control
Peace of mind, automated
We are not selling software. We are selling the ability to operate AI without uncertainty.
Zero-Config AI Discovery
Our Nomyo Router plugin gives you instant visibility into your client's AI stack. No engineers needed to fill out forms. Auto-discovers every model endpoint, traffic telemetry, and infrastructure context. Includes deduplication, health monitoring, blacklist controls, and config reporting.
Risk Classification Engine
Per-system automated risk classification against EU AI Act tiers — Prohibited, GPAI/Systemic, High-Risk, Limited-Risk, Minimal-Risk. JSON-driven rules engine updated without code deploys. Rule-match transparency with hover tooltips showing which regulation clauses triggered each classification.
Evidence Locker & QMS
Secure, immutable storage for all compliance evidence. Verification workflow with status tracking (verified/pending/rejected). Text evidence submissions alongside file uploads. Auto-fill from Nomyo Router discovery data for 9 of 14 Annex IV elements. Risk register tracking, version control with audit trails.
Documentation Generator
Convert structured data into formal regulatory documents. Generates EU Declarations of Conformity, Technical Documentation (Annex IV), and Instructions for Use — in PDF and JSON.
Post-Market Monitoring
Incident tracking for serious incidents (Article 73), automated reminders for recurring compliance tasks, and 10-year retention management for withdrawn systems.
Crypto-Shredding
Per-tenant envelope encryption with hierarchical key management. Crypto-shredding for GDPR erasure. A hard requirement for privacy-conscious tech companies.
From uncertainty to compliant in five steps
No consultants. No spreadsheets. Just results.
Take the Compliance Quiz
Answer a few questions about your AI systems. Know instantly where you stand under the EU AI Act.
Connect Your Stack
Install the Nomyo Router plugin for zero-config discovery, or upload your model inventory via CSV.
Classify & Collect
The engine classifies each AI system and guides you through collecting evidence for all 14 Annex IV elements.
Generate & Sign
One-click generation of EU Declarations of Conformity, Technical Documentation, and Instructions for Use.
Ship with Confidence
Post-market monitoring, incident tracking, and automated compliance reminders. We handle the paperwork.
Our advantage
The Nomyo Router plugin gives you instant visibility into a client's AI stack without them needing to hire engineers to fill out forms.
Nomyo Router Plugin
Leverage your existing Nomyo Router deployment as a compliance agent. Periodic POSTs deliver model inventory, endpoint registry, routing config, traffic telemetry, and conversation affinity data. Zero engineering effort required.
- Model inventory with version and quantization details
- Endpoint registry for all inference backends
- Traffic telemetry with latency percentiles
- Semantic cache state and conversation affinity
Manual CSV Import
Upload a model inventory spreadsheet when the Nomyo Router is not yet deployed.
Docker API Scan
Detect running containers with AI-related images via the Docker API for environments using containerized deployments.
compliance:
enabled: true
server_url: "https://app.aissurance.eu/api/discovery"
api_key: "${AISSURANCE_KEY}"
polling_interval: 300
batch_size: 50Crypto-shredding. Per-tenant isolation.
Our per-tenant encryption is a hard requirement for privacy-conscious tech companies. Even we cannot read your data.
Per-Tenant Encryption
Every piece of data encrypted with a tenant-specific key. Cryptographic isolation, not just logical. Even we cannot read your data.
Envelope Encryption
Three-tier hierarchy: Master Key → Tenant Key → Data Key. Keys stored in HSM or local encrypted keystore. Data at rest on local POSIX filesystem.
Crypto-Shredding
Permanently delete all tenant data by destroying their encryption key. GDPR Article 17 right to erasure, guaranteed.
Key Rotation
Automated rotation with zero-downtime dual-key period. 90-day grace period for deprecated keys.
HMAC Integrity
SHA-256 signing of all discovery payloads and audit logs to prevent tampering.
RBAC + Least Privilege
Four distinct access levels. Every key access logged and auditable for regulatory proof.
Built for every role in your organization
Four distinct access levels with purpose-built dashboards and permissions.
Compliance Admin
High-level risk posture, deadline tracking, and final sign-off authority for conformity declarations. Peace of mind at a glance.
Full controlTechnical Lead
Upload model metadata, training data schemas, and test results. The primary data entry point for technical documentation.
Data entryAI Deployer
Verify provider compliance before deployment. Restricted view to check the AI systems you depend on.
RestrictedAuditor
Read-only access to view the entire chain of evidence, version history, and risk assessments for regulatory inspection.
Read-onlyPeace of mind from €99/month
SME-focused Compliance-as-a-Service. No $50k consulting engagements. No spreadsheet chaos. Pick a plan and get compliant.
Freemium
Try risk classification before you commit.
- Risk Classification Tool
- "Am I Compliant?" Quiz
- 1 AI System
- Community support
Starter
For AI-first SMEs that need full compliance documentation.
- Full Documentation Generator (14 Annex IV elements)
- Nomyo Router Auto-Discovery
- Up to 10 AI Systems
- Evidence Locker & QMS
- Email support
Pro
For growing teams that need post-market monitoring and multi-user access.
- Unlimited AI Systems
- Post-Market Monitoring
- Incident Response (Article 73)
- Multi-User Access
- Crypto-Shredding
- Priority support
Frequently asked questions
Everything you need to know about aissurance and EU AI Act compliance.
Do I need a lawyer to use aissurance?
Not to get started. aissurance automates risk classification, evidence collection, and document generation based on the EU AI Act text. For final legal sign-off, we recommend consulting qualified counsel — our platform makes that consultation efficient by providing structured evidence.
Can I self-host aissurance?
Currently aissurance is offered as a hosted service. All data is encrypted with per-tenant keys on local POSIX filesystem storage. Self-hosted deployment is planned for Phase 3.
What happens to my data if I cancel?
You can trigger crypto-shredding — we destroy your tenant encryption key, making all stored data permanently unreadable. This satisfies GDPR Article 17 right to erasure.
How does the Nomyo Router plugin work?
If you run Nomyo Router to manage your AI endpoints, a single config addition enables compliance reporting. Nomyo Router periodically sends model inventory, endpoint registry, and telemetry data to aissurance — zero engineering effort.
Is aissurance ready for the Aug 2026 deadline?
The core compliance workflow — classification, evidence collection, documentation generation — is fully implemented. Post-market monitoring and incident tracking are in active development.
What AI Act obligations does aissurance cover?
All Annex III high-risk AI systems (Annex IV technical documentation, Annex V conformity assessment), Article 52 limited-risk transparency, Article 53/54 GPAI obligations, and Article 73 incident reporting.
Start your EU AI Act compliance journey today
The EU AI Act is a ticking clock. Every company using AI is at risk. Start with our free compliance quiz or jump straight into a plan — we handle the rest.
By signing up you agree to our Terms of Service and Privacy Policy.