Legal · GC and law firm

Records counsel can rely on.

The Act's enforcement teeth bite when the evidence is thin. Veritome produces the artefacts you would hand to a regulator, an auditor or a diligence team — every record timestamped, every dossier hash-sealed, every change attributable to the person who made it.

No card · EU-hosted · 5 minutes to a first classification
Veritome audit log — every change with the user, the timestamp and what changed, hash-chained and anchored daily
Three asks legal teams have on us

The same record, under three different lights.

What we hear

The client says they're 'mostly compliant'. Show me what they actually have.

What the product does

The regulator-view dossier is one PDF per system: classification record, obligation status, evidence per item, hash chain. No screenshots, no slide decks.

What we hear

The M&A target's AI estate is a black box. We need a diligence summary in 48 hours.

What the product does

A public verify URL on every dossier. The diligence team reads the seal directly — no NDA gymnastics on portal access, no redacted screenshots.

What we hear

If a national authority asks us to produce documentation, can we do it inside the deadline?

What the product does

Every change is in the audit log with the user, the timestamp and what changed. Every dossier entry has its own serial number. A break in the chain is surfaced, not hidden.

What changes for counsel

Built for the conversation that starts ‘show me’.

01

Tamper-evident audit trail

Dossier entries form a hash chain, anchored daily. A verification surfaces breaks rather than swallowing them.

02

Regulator-view dossier

A separate rendering with article references in the margin, written to read as authoritative on a regulator's desk.

03

Public verify URL

Anyone can check the seal without an account. Diligence, regulator handoffs and customer due diligence use the same mechanism.

04

Per-action audit log

Every change logged: classification, obligation status, evidence upload, dossier entry. User, timestamp, before and after.

05

Multi-client access for firms

One firm account, many client organisations, permissions enforced at the API. Walls per engagement, not global.

06

Article-anchored everything

Every screen carries the article reference. The record speaks the same language as the Regulation, so review needs no translation step.

In practice

Three legal contexts, one source of truth.

Use case 01

A boutique law firm advising fifty SME clients on EU AI Act readiness.

  • One firm account, fifty client organisations.
  • A standard playbook: free check → classification → obligation map → evidence per client.
  • The regulator-view dossier is the deliverable; clients receive it as a PDF plus a verify URL.
  • If a regulator request lands at one client, the chain reads start to end.
Veritome Annex IV technical-file builder — sections assembled from live system data with a hash-sealed export
Use case 02

A diligence team examining an AI-native target's compliance posture.

  • The target hands over a verify URL; the team reads the seal without portal access.
  • The hash chain confirms integrity — no quiet edits during the diligence window.
  • The per-system dossier exposes classification reasoning, obligation status and evidence completeness.
  • Findings feed straight into the warranty schedule.
Veritome audit log — every change with the user, the timestamp and what changed, hash-chained and anchored daily
Use case 03

An in-house GC fielding an information request from a national authority.

  • The audit log shows every action on the named system across the inspection window.
  • Dossier entries — the Art. 6(3) assessment, the Art. 6(4) notification, the conformity assessment, the IFU handoff — numbered and hashed.
  • Phase-gate attestations record exactly when each phase passed, not 'around April'.
  • The response pack assembles in a working day.
Veritome reports — the organisation compliance report, board summary and audit-preparation pack as sealed PDFs
What counsel leans on

The capabilities that hold up in evidence.

Straight answers

Questions counsel ask

Is the audit trail tamper-evident?

Yes. Every change is logged with the user, the timestamp and what changed; the log is hash-chained and anchored daily. Dossier entries form their own chain, and a break is surfaced rather than hidden. The integrity property is the audit artefact.

Can a third party check a dossier without an account?

Yes. Every sealed dossier carries a public verify URL. A regulator, an auditor or a diligence team reads the seal directly — no portal access, no redacted screenshots.

Can a firm manage several client organisations?

Yes. One firm account, many client organisations, each with its own systems, classifications and obligations, permissions enforced at the API. The regulator-view dossier is the deliverable per client.

Does Veritome replace legal review?

No. Classification under the Act involves judgement no software resolves definitively, and the documents are drafts built from what the client records. Every screen names the article it rests on, which is what makes counsel's review possible rather than guesswork.