[FR] Annex IV[FR] Technical documentation from live systems

[FR] Stop losing enterprise deals to a compliance questionnaire.

[FR] Evidence-based Annex IV documentation generated from your live ML systems — so your security review doesn't stall your sales cycle.

[FR] Reads your stack via REST & AST[FR] No model weights leave your infra[FR] EU-hosted

modeldocs scan · candidate-rankerlive
[FR] The deal blocker

[FR] Your buyer's security team asked for your Annex IV technical file. You have a spreadsheet.

[FR] What you sent

[FR] A self-attested questionnaire and a slide that says "AI Act: in progress." The reviewer can't verify any of it, so it gets escalated.

// status: blocked in security review

[FR] What closes the deal

[FR] A complete Annex IV technical file where every claim points to evidence the reviewer's own engineers would recognise.

// status: passed, contract signed
6–11 semaines

[FR] is what a stalled high-risk-AI security review adds to an enterprise sales cycle — usually right before the quarter closes.

[FR] The difference

[FR] Assertion-based vs. evidence-based.

[FR] Everyone else turns a questionnaire into a PDF. We read your live systems and map real artefacts to the exact Annex IV sections that require them.

[FR] Questionnaire tools[FR] Self-attested
Q14[FR] Does the system undergo validation and testing before deployment?
YesNoPartially
Q15[FR] Describe your design specifications and architecture choices.
"[FR] We follow standard ML best practices and review models before release…"
[FR] Generated output: "[FR] The provider asserts that validation and testing are performed."
modeldocs[FR] Evidence-linked
$ modeldocs map --section 2g
 
§2(g) validation and testing
evidence:
eval/holdout_metrics.json
auc=0.834 recall@10=0.71
fairness/ selection_rate by group
source:
mlruns/9f2c1a/metrics
registry://candidate-ranker/3
verified: 2026-05-02 · re-scan on retrain
[FR] Each line resolves to an artefact a reviewer's engineers can open and check.
[FR] How it works

[FR] Connect once. Map automatically. Stay current.

[FR] The scanner reads metadata and source — never weights or training data — and keeps the technical file in sync as your models change.

ÉTAPE 01

[FR] Connect

[FR] Point the open-source scanner at your stack. It reads run metadata over REST and your repos via static analysis — read-only, inside your infra.

MLflow RESTModel registryPython AST
ÉTAPE 02

[FR] Map

[FR] Every artefact is matched to the Annex IV section that requires it — design specs, data governance, validation, monitoring — with the source reference attached.

§2(b) design§2(g) validation§3 monitoring
ÉTAPE 03

[FR] Maintain

[FR] Models retrain and documentation decays. modeldocs re-scans on every change and flags the sections that drifted.

[FR] Free, no signup

[FR] Annex IV Readiness Check

[FR] Nine questions about your ML stack and deployment. Get an instant risk score and the three documentation gaps most likely to stall your next enterprise review.

[FR] Run the readiness check
9 [FR] questions~2 min [FR] to complete0 [FR] data stored
65/100
[FR] sample readiness score
[FR] Do you track experiments in MLflow or similar?
[FR] Are validation metrics versioned with the model?
[FR] Is there a documented post-market monitoring plan?
[FR] Who it's for

[FR] Built for EU AI Providers under Annex III.

// primary user

[FR] Technical founders, CTOs & ML leads at 20–100 person EU SaaS companies.

[FR] Specifically HR-tech and recruitment platforms that are Providers of high-risk AI — automated screening, ranking and matching of candidates.

Annex III · §4(a) [FR] employment & worker management
[FR] You ship AI that screens, ranks or matches candidates.[FR] That puts you squarely in the high-risk category.
[FR] Your enterprise buyers run a vendor security review.[FR] And it now includes your AI Act technical file.
[FR] You'd rather connect a system than fill in a form.[FR] Evidence from your stack beats a 60-page self-assessment.
[FR] EU-hosted[FR] Data stays in the EU
[FR] Open-source scanner[FR] Read and audit the code
[FR] Your code never leaves your infra[FR] Reads metadata via REST & AST only
[FR] Early access

[FR] Get your technical file out of the way.

[FR] Join the waitlist and we'll onboard EU AI Providers in cohorts.

[FR] No spam. One email when your cohort opens. Unsubscribe in one click.

[FR] We store your work email to manage waitlist access. No data is shared with third parties.