[NL] Annex IV[NL] Technical documentation from live systems

[NL] Stop losing enterprise deals to a compliance questionnaire.

[NL] Evidence-based Annex IV documentation generated from your live ML systems — so your security review doesn't stall your sales cycle.

[NL] Reads your stack via REST & AST[NL] No model weights leave your infra[NL] EU-hosted

modeldocs scan · candidate-rankerlive
[NL] The deal blocker

[NL] Your buyer's security team asked for your Annex IV technical file. You have a spreadsheet.

[NL] What you sent

[NL] A self-attested questionnaire and a slide that says "AI Act: in progress." The reviewer can't verify any of it, so it gets escalated.

// status: blocked in security review

[NL] What closes the deal

[NL] A complete Annex IV technical file where every claim points to evidence the reviewer's own engineers would recognise.

// status: passed, contract signed
6–11 weken

[NL] is what a stalled high-risk-AI security review adds to an enterprise sales cycle — usually right before the quarter closes.

[NL] The difference

[NL] Assertion-based vs. evidence-based.

[NL] Everyone else turns a questionnaire into a PDF. We read your live systems and map real artefacts to the exact Annex IV sections that require them.

[NL] Questionnaire tools[NL] Self-attested
Q14[NL] Does the system undergo validation and testing before deployment?
YesNoPartially
Q15[NL] Describe your design specifications and architecture choices.
"[NL] We follow standard ML best practices and review models before release…"
[NL] Generated output: "[NL] The provider asserts that validation and testing are performed."
modeldocs[NL] Evidence-linked
$ modeldocs map --section 2g
 
§2(g) validation and testing
evidence:
eval/holdout_metrics.json
auc=0.834 recall@10=0.71
fairness/ selection_rate by group
source:
mlruns/9f2c1a/metrics
registry://candidate-ranker/3
verified: 2026-05-02 · re-scan on retrain
[NL] Each line resolves to an artefact a reviewer's engineers can open and check.
[NL] How it works

[NL] Connect once. Map automatically. Stay current.

[NL] The scanner reads metadata and source — never weights or training data — and keeps the technical file in sync as your models change.

STAP 01

[NL] Connect

[NL] Point the open-source scanner at your stack. It reads run metadata over REST and your repos via static analysis — read-only, inside your infra.

MLflow RESTModel registryPython AST
STAP 02

[NL] Map

[NL] Every artefact is matched to the Annex IV section that requires it — design specs, data governance, validation, monitoring — with the source reference attached.

§2(b) design§2(g) validation§3 monitoring
STAP 03

[NL] Maintain

[NL] Models retrain and documentation decays. modeldocs re-scans on every change and flags the sections that drifted.

[NL] Free, no signup

[NL] Annex IV Readiness Check

[NL] Nine questions about your ML stack and deployment. Get an instant risk score and the three documentation gaps most likely to stall your next enterprise review.

[NL] Run the readiness check
9 [NL] questions~2 min [NL] to complete0 [NL] data stored
65/100
[NL] sample readiness score
[NL] Do you track experiments in MLflow or similar?
[NL] Are validation metrics versioned with the model?
[NL] Is there a documented post-market monitoring plan?
[NL] Who it's for

[NL] Built for EU AI Providers under Annex III.

// primary user

[NL] Technical founders, CTOs & ML leads at 20–100 person EU SaaS companies.

[NL] Specifically HR-tech and recruitment platforms that are Providers of high-risk AI — automated screening, ranking and matching of candidates.

Annex III · §4(a) [NL] employment & worker management
[NL] You ship AI that screens, ranks or matches candidates.[NL] That puts you squarely in the high-risk category.
[NL] Your enterprise buyers run a vendor security review.[NL] And it now includes your AI Act technical file.
[NL] You'd rather connect a system than fill in a form.[NL] Evidence from your stack beats a 60-page self-assessment.
[NL] EU-hosted[NL] Data stays in the EU
[NL] Open-source scanner[NL] Read and audit the code
[NL] Your code never leaves your infra[NL] Reads metadata via REST & AST only
[NL] Early access

[NL] Get your technical file out of the way.

[NL] Join the waitlist and we'll onboard EU AI Providers in cohorts.

[NL] No spam. One email when your cohort opens. Unsubscribe in one click.

[NL] We store your work email to manage waitlist access. No data is shared with third parties.