Attestly
EU AI Act high-risk obligations apply Aug 2, 2027

Compliance that reads your code, so it never lies about your product.

Automated, engineer-built compliance that syncs directly with your codebase.

No credit card required · 14-day free trial on paid plans · Cancel anytime

Read-only GitHub access EU-hosted option Free for OSS
trust.yourcompany.com
Acme — Trust Center
AI systems
3
2 high-risk
Subprocessors
14
all current
OSS licenses
312
0 risk
Last regen
2h ago
commit a91f0b2
AI inventoryAuto-updated
  • OpenAI · gpt-4oHigh
  • Anthropic · claude-3.5High
  • OpenAI · text-embedding-3Limited
100+
SDK & service detectors
< 90s
Repo scan time
5
Compliance docs generated
9
Lockfile ecosystems
Read-only GitHub access — your code never leaves your infraSet up in under 10 minutesRe-scans on every PR automatically

Built with

VercelNeonClerkStripeResend

Lawyers draft your docs once. Engineers ship code daily.

Within a week your published privacy policy is wrong. Your DPA lists subprocessors you no longer use. Your AI usage isn't disclosed at all. Enterprise procurement sends you a 40-question security questionnaire, and you spend 10+ hours per deal answering it manually.

Stale by design

A PDF written 6 months ago can't reflect what your code did this morning.

Per-jurisdiction rules

EU AI Act, GDPR, CPRA, CO/CT/VA/TX state laws — each demands different disclosures.

No PR-aware tooling

Your scanner stops at SOC 2 controls. Nothing watches the code paths that touch user data.

How it works

From repo to published trust center in 10 minutes.

01

Connect your repo

Read-only GitHub OAuth. Pick the repos that matter. Five-minute interview captures legal-entity facts we can't see in code.

02

Attestly scans

Static analysis finds every AI SDK call, every third-party subprocessor, every personal-data field, every OSS license — with file & line citations.

03

Generate, you approve

Schema-locked LLM produces the five documents. You review the diff. One click publishes to your trust center.

04

Stay live

On every PR, we re-scan and surface drift. New subprocessor? Customers are auto-notified per Art. 28(2) of GDPR.

No credit card required

What it generates

Five living documents. One source of truth: your code.

Every document is regenerated from the same scan that produced the last one, so your trust center never falls behind your release.

EU AI Act

AI Trust Center

Hosted page with AI inventory, data flows, risk class per system, and documentation to instantly satisfy enterprise security reviews.

GDPR · CPRA

Privacy Policy

Accurate to detected data collection. Per-jurisdiction sections appear automatically when a state law applies.

GDPR Art. 28

DPA + Subprocessor list

Up-to-date subprocessor list. New vendor SDK detected? Customers are emailed automatically.

MIT · Apache · BSD

OSS Attributions

Full NOTICE file generated from your dependency graph. Per-release, beautifully formatted, linkable.

AICPA TSC

SOC 2 Readiness

Translate SOC 2 work from months to minutes.

From SOC 2 and OSS attributions to DPIA and AI Act conformity — generated from your code, not a questionnaire.

Forcing function

EU AI Act high-risk obligations apply August 2, 2027.

If you ship a SaaS product to EU customers and any feature uses AI for decisions about people — hiring, credit, biometrics, education, employment, essential services — you owe a conformity assessment, an AI system inventory, and continuous post-market monitoring.

  • AI system inventory mapped to your repo
  • Annex IV conformity draft, ready for legal review
  • AIBOM JSON exportable for enterprise customers
  • Re-runs on every PR — no PDF goes stale
Free to start · no credit card
aibom.jsonschema v1.0
{
  "tenant": "acme",
  "generated_at": "2026-05-06T09:14:22Z",
  "ai_systems": [
    {
      "id": "summarizer",
      "purpose": "summarize customer notes",
      "model": { "provider": "openai", "name": "gpt-4o" },
      "inputs": ["customer.notes", "user.email"],
      "risk_class": "limited",
      "source": "src/agents/summarizer.ts:42"
    },
    {
      "id": "credit-screener",
      "purpose": "pre-qualify loan applicants",
      "model": { "provider": "anthropic", "name": "claude-3.5" },
      "inputs": ["application.income", "application.dob"],
      "risk_class": "high",
      "source": "src/lending/screener.ts:118"
    }
  ]
}

Compliance copilot

An assistant that answers from your code, your docs, and the frameworks that bind you.

Press Cmd/Ctrl+J from any dashboard page. Toggle expert mode for article-by-article reasoning across eleven privacy and AI frameworks. Every turn is grounded in a per-tenant retrieval pass, redacts PII before any LLM call, and lands in the same tamper-evident audit log as the rest of Attestly.

  • PII redaction — emails, phones, SSNs, cards, tokens, keys, IPs — before the LLM ever sees a prompt
  • BYO-LLM end-to-end: copilot, Trust Q&A, and document generation honor your endpoint
  • Mutating actions require a click and respect role gating — you can't accidentally publish
  • Per-tenant monthly budgets + per-user rate limits keep the bill bounded

Cited from your code and your docs

Every claim links back to a scan finding, a published doc section, or a specific framework article. No paraphrasing, no hallucinated citations.

Eleven frameworks in expert mode

GDPR, EU AI Act, SOC 2, CCPA/CPRA, HIPAA, ISO 27001, NIST AI RMF, US state privacy laws, DORA, NIS 2, EU DSA — article-level references, on demand.

Tools, not just talk

Resolve drift, request review, export the audit log — proposed by the assistant, confirmed by you, recorded in the audit chain.

Public Trust Center Q&A

Optional widget on /trust/<you> that answers prospects from your published docs only. The questions you get back are your fastest FAQ feedback loop.

Why not Vanta, Termly, SafeBase, or FOSSA?

Each solves a slice. None reads your code, and none ships all five documents under one roof.

CapabilityAttestlyTermly / iubendaSafeBase / ConveyorFOSSA
Code-aware updatesYes
AI Act moduleYes
Privacy + DPA + OSS + SOC 2All fivePrivacy onlySOC 2 onlyLicenses only
Auto subprocessor notifyYes
Hosted trust centerYesManual fill
Cited compliance copilot + public Trust Q&AYesLight Q&A
PricingFrom $99/moFrom $10/moEnterpriseEnterprise

Built by engineers, for engineers. We got tired of answering security questionnaires, so we automated them.

No credit card required · set up in under 10 minutes

100+ built-in detectors

If your code uses it, Attestly finds it.

OpenAIAnthropicGoogle GeminiAzure OpenAICohereReplicateHugging FaceMistralGroqStripeTwilioSendGridResendPostmarkSegmentMixpanelAmplitudePostHogDatadogSentryLaunchDarklyAuth0ClerkFirebaseSupabaseAWS SDKGoogle CloudCloudflareVercel AIPineconeWeaviateIntercomHubSpotSalesforceSlack+ 65 more

Plus custom detectors via .attestly/detectors.json

Frequently asked questions

Can't find what you're looking for? Reach out and we'll get back to you within a business day.

EU AI Act high-risk obligations apply August 2, 2027. Are you ready?

Connect a repo and watch your AI Trust Center generate in front of you. Most teams are live in under 10 minutes.

  • Free for OSS — no credit card
  • 14-day trial on all paid tiers
  • Cancel anytime — no lock-in