Register ref. PL-2026 / EU AI Act / GDPR / SOC 2

Compliance that keeps up with your product.

Proofloop maps your AI systems, works out which obligations apply under the EU AI Act, GDPR and SOC 2, writes the documentation, and keeps it current as your product changes.

0 hours

Average annual effort replaced per company

0 days

From kickoff to a complete first documentation set

0+

Controls and obligations tracked across three frameworks

0%

Of evidence collected automatically from connected systems

System integrity

Live Obligations Ledger

Proofloop maps your systems to the applicable obligations and keeps the documentation current as your product changes.

€35M

Maximum EU AI Act penalty, or 7% of global turnover, for prohibited practices

6–9 months

Typical time to a first SOC 2 report when it is run manually

3 weeks

Average time a security questionnaire blocks an enterprise deal

System: candidate-screening-v3Obligations register
Ref.ObligationStatus
Art. 9Risk management systemIN REVIEW
Art. 11Technical documentationIN REVIEW
Art. 13Transparency to deployersIN REVIEW
Art. 14Human oversightIN REVIEW
Art. 15Accuracy and robustnessIN REVIEW
Art. 17Quality management systemIN REVIEW
Art. 26Deployer obligationsIN REVIEW
Art. 30 GDPRRecords of processingIN REVIEW
Art. 35 GDPRImpact assessment (DPIA)IN REVIEW

Coverage

Three frameworks, one register.

AreaEU AI ActGDPRSOC 2 Type II
Risk classification—
Technical documentation
Data governance
Human oversight—
Transparency notices—
Incident logging
Vendor and sub-processor management
Access control evidence
Change management—

Covered Partial— Not applicable

Evidence

Every sentence has a source.

Technical file · Art. 11 · §2.3 Data and access

1The screening model is hosted exclusively in the eu-west-1 region and training data never leaves the EU.

[1] AWS config snapshot

s3://pl-train-data · region=eu-west-1 · 2026-10-04 06:42

2The current production model was released through the standard change process with peer review.

[2] Repo commit

proofloop-app@7c3e9a1 · PR #482 · 2 approvals

3Access to training data was reviewed and confirmed for all eleven members of the ML platform group.

[3] Access review record

Okta · group ml-platform · reviewed 2026-09-30

4The annotation vendor processes applicant data under a signed data processing agreement.

[4] Vendor DPA

LabelWorks GmbH · signed 2026-03-12 · expires 2028-03-12

Every statement traces to a source. Auditors follow the same line you do.

How it runs

  1. 01

    Connect

    Link cloud accounts, repos, ticketing and identity providers.

    • AWS · prod-eu-west-1synced 06:42:11
    • GitHub · proofloop-appsynced 06:41:58
    • Okta · directorysynced 06:40:03
    • Jira · SEC projectsynced 06:38:27
  2. 02

    Classify

    Proofloop inventories every AI system and assigns an EU AI Act risk tier with the reasoning shown.

    System · candidate-screening-v3

    High risk — Annex III, 4(a) employment screening

    "Ranks inbound applicants and filters CVs before recruiter review."src: github · README.md L14
  3. 03

    Generate

    Documentation is drafted against the applicable articles, with every claim linked to the evidence behind it.

    Technical file · §2.3 Data

    Training data is retained in an EU region with encryption at rest.

    Access is limited to the ML platform group.

    [1] AWS[2] OKTA
  4. 04

    Watch

    When the product, vendors or regulations change, affected sections are flagged and rewritten.

    • 2026-10-02Model upgraded to v3.2STALE
    • 2026-09-28Vendor DPA renewedUPDATED
    • 2026-09-15Annex III guidance publishedUPDATED

Integrations

  • AWS
  • Google Cloud
  • Azure
  • GitHub
  • GitLab
  • Jira
  • Linear
  • Okta
  • Google Workspace
  • Microsoft Entra
  • Snowflake
  • Datadog
  • Notion
  • Confluence

What breaks today

€35M

Maximum EU AI Act penalty, or 7% of global turnover, for prohibited practices

6–9 months

Typical time to a first SOC 2 report when it is run manually

3 weeks

Average time a security questionnaire blocks an enterprise deal

What customers get

SOC 2 Type II in 14 weeks

60-person fintech, previously quoted 9 months by a consultancy

€0 spent on external counsel for AI Act classification

120-person HR software company

Security questionnaires answered in 2 days instead of 3 weeks

40-person AI analytics vendor

Pricing

Baseline

$490/month

  • One framework
  • Up to 10 systems
  • 5 integrations
  • Generated documentation
  • Quarterly refresh
Request access

StandardRecommended

$1,290/month

  • All three frameworks
  • Up to 50 systems
  • Unlimited integrations
  • Continuous monitoring
  • Questionnaire automation
  • Audit export
Request access

Enterprise

Custom

  • Multi-entity
  • Multi-jurisdiction
  • Custom frameworks
  • Named compliance engineer
  • SLA
Contact us

Annual billing available. Audit firm introductions included at no cost.

FAQ

No. Proofloop does the drafting, evidence collection and monitoring; final legal sign-off stays with your counsel. The output is built to be reviewed quickly rather than rewritten, so counsel spends hours on judgement instead of weeks on first drafts.

Risk management documentation, technical documentation, data governance records, records of processing activities (ROPA), DPIAs, model cards, transparency notices and SOC 2 policies — plus an auditor-ready export package and answers to security questionnaires.

Our compliance team tracks the EU AI Act, its delegated acts and guidance, GDPR decisions and AICPA updates. When something changes, affected obligations are updated in your register and the impacted document sections are flagged and redrafted.

Customer data is stored in the EU by default, encrypted in transit and at rest. Integrations use read-only access wherever the source system allows it.

Yes. Each package links every control to timestamped evidence from the source system, in the formats audit firms already work with. We also introduce you to audit firms familiar with the export.

Most teams connect their systems in the first week and receive a complete first documentation set within 11 days of kickoff.

The Baseline plan covers one framework. Start with SOC 2 and add the EU AI Act and GDPR later — your evidence carries over.

Yes. All documents, evidence records and the system inventory export in open formats (DOCX, PDF, CSV, JSON) at any time.

Your product changed last week. Your documentation didn't.

Request access