Register ref. PL-2026 / EU AI Act / GDPR / SOC 2
Compliance that keeps
up with your product.
Proofloop maps your AI systems, works out which obligations apply under the EU AI Act, GDPR and SOC 2, writes the documentation, and keeps it current as your product changes.
0 hours
Average annual effort replaced per company
0 days
From kickoff to a complete first documentation set
0+
Controls and obligations tracked across three frameworks
0%
Of evidence collected automatically from connected systems
System integrity
Live Obligations Ledger
Proofloop maps your systems to the applicable obligations and keeps the documentation current as your product changes.
€35M
Maximum EU AI Act penalty, or 7% of global turnover, for prohibited practices
6–9 months
Typical time to a first SOC 2 report when it is run manually
3 weeks
Average time a security questionnaire blocks an enterprise deal
| Ref. | Obligation | Status |
|---|---|---|
| Art. 9 | Risk management system | IN REVIEW |
| Art. 11 | Technical documentation | IN REVIEW |
| Art. 13 | Transparency to deployers | IN REVIEW |
| Art. 14 | Human oversight | IN REVIEW |
| Art. 15 | Accuracy and robustness | IN REVIEW |
| Art. 17 | Quality management system | IN REVIEW |
| Art. 26 | Deployer obligations | IN REVIEW |
| Art. 30 GDPR | Records of processing | IN REVIEW |
| Art. 35 GDPR | Impact assessment (DPIA) | IN REVIEW |
Coverage
Three frameworks, one register.
| Area | EU AI Act | GDPR | SOC 2 Type II |
|---|---|---|---|
| Risk classification | — | ||
| Technical documentation | |||
| Data governance | |||
| Human oversight | — | ||
| Transparency notices | — | ||
| Incident logging | |||
| Vendor and sub-processor management | |||
| Access control evidence | |||
| Change management | — |
Covered Partial— Not applicable
Evidence
Every sentence has a source.
¶1The screening model is hosted exclusively in the eu-west-1 region and training data never leaves the EU.
[1] AWS config snapshot
s3://pl-train-data · region=eu-west-1 · 2026-10-04 06:42
¶2The current production model was released through the standard change process with peer review.
[2] Repo commit
proofloop-app@7c3e9a1 · PR #482 · 2 approvals
¶3Access to training data was reviewed and confirmed for all eleven members of the ML platform group.
[3] Access review record
Okta · group ml-platform · reviewed 2026-09-30
¶4The annotation vendor processes applicant data under a signed data processing agreement.
[4] Vendor DPA
LabelWorks GmbH · signed 2026-03-12 · expires 2028-03-12
Every statement traces to a source. Auditors follow the same line you do.
How it runs
- 01
Connect
Link cloud accounts, repos, ticketing and identity providers.
- AWS · prod-eu-west-1synced 06:42:11
- GitHub · proofloop-appsynced 06:41:58
- Okta · directorysynced 06:40:03
- Jira · SEC projectsynced 06:38:27
- 02
Classify
Proofloop inventories every AI system and assigns an EU AI Act risk tier with the reasoning shown.
System · candidate-screening-v3
High risk — Annex III, 4(a) employment screening
"Ranks inbound applicants and filters CVs before recruiter review."src: github · README.md L14
- 03
Generate
Documentation is drafted against the applicable articles, with every claim linked to the evidence behind it.
Technical file · §2.3 Data
Training data is retained in an EU region with encryption at rest.
Access is limited to the ML platform group.
[1] AWS[2] OKTA - 04
Watch
When the product, vendors or regulations change, affected sections are flagged and rewritten.
- 2026-10-02Model upgraded to v3.2STALE
- 2026-09-28Vendor DPA renewedUPDATED
- 2026-09-15Annex III guidance publishedUPDATED
Integrations
- AWS
- Google Cloud
- Azure
- GitHub
- GitLab
- Jira
- Linear
- Okta
- Google Workspace
- Microsoft Entra
- Snowflake
- Datadog
- Notion
- Confluence
What breaks today
€35M
Maximum EU AI Act penalty, or 7% of global turnover, for prohibited practices
6–9 months
Typical time to a first SOC 2 report when it is run manually
3 weeks
Average time a security questionnaire blocks an enterprise deal
- └ AI_Act_risk_assessment_v7_FINAL.docx2025-08-14 16:0214 mo old
- └ AI_Act_risk_assessment_v7_FINAL_JM-edits.docx2025-09-02 11:4713 mo old
- └ ROPA_2025_updated_Mar.xlsx2025-03-21 09:1518 mo old
- └ DPIA_screening_tool_DRAFT.docx2025-11-30 18:2010 mo old
- └ SOC2_policies_copy.docx2025-10-06 14:3312 mo old
- └ SOC2_policies_copy (2).docx2026-02-11 10:087 mo old
- └ model_card_draft_oldest.md2025-09-19 08:4112 mo old
- └ vendor_list_DO_NOT_EDIT.xlsx2025-12-03 17:5510 mo old
What customers get
SOC 2 Type II in 14 weeks
60-person fintech, previously quoted 9 months by a consultancy
€0 spent on external counsel for AI Act classification
120-person HR software company
Security questionnaires answered in 2 days instead of 3 weeks
40-person AI analytics vendor
Pricing
Baseline
$490/month
- One framework
- Up to 10 systems
- 5 integrations
- Generated documentation
- Quarterly refresh
StandardRecommended
$1,290/month
- All three frameworks
- Up to 50 systems
- Unlimited integrations
- Continuous monitoring
- Questionnaire automation
- Audit export
Enterprise
Custom
- Multi-entity
- Multi-jurisdiction
- Custom frameworks
- Named compliance engineer
- SLA
Annual billing available. Audit firm introductions included at no cost.
FAQ
No. Proofloop does the drafting, evidence collection and monitoring; final legal sign-off stays with your counsel. The output is built to be reviewed quickly rather than rewritten, so counsel spends hours on judgement instead of weeks on first drafts.
Risk management documentation, technical documentation, data governance records, records of processing activities (ROPA), DPIAs, model cards, transparency notices and SOC 2 policies — plus an auditor-ready export package and answers to security questionnaires.
Our compliance team tracks the EU AI Act, its delegated acts and guidance, GDPR decisions and AICPA updates. When something changes, affected obligations are updated in your register and the impacted document sections are flagged and redrafted.
Customer data is stored in the EU by default, encrypted in transit and at rest. Integrations use read-only access wherever the source system allows it.
Yes. Each package links every control to timestamped evidence from the source system, in the formats audit firms already work with. We also introduce you to audit firms familiar with the export.
Most teams connect their systems in the first week and receive a complete first documentation set within 11 days of kickoff.
The Baseline plan covers one framework. Start with SOC 2 and add the EU AI Act and GDPR later — your evidence carries over.
Yes. All documents, evidence records and the system inventory export in open formats (DOCX, PDF, CSV, JSON) at any time.
ProofLoop