Maditon Your EU compliance assistant
Built for startups and SMEs without a legal team. Maditon keeps the register your customers and auditors ask for, reads your suppliers' documents and watches them for changes, and drafts the answers to your customers' questionnaires. It does the volume work — the judgement stays yours.
Already have an account? Log in
From a supplier's documents to the answer on your customer's questionnaire
Supplier register
Who you depend on, and what their privacy policies, terms and agreements actually say. Every finding quotes the passage it came from.
Change watching
Documents are re-read on schedule. When terms change you get the difference, and whether it matters, in a morning e-mail.
Questionnaires
Your customer's security or privacy questionnaire answered from your own record. You review, approve and send the file back.
Systems, SLA and contacts
Which systems depend on which suppliers, with SLA levels and support contacts in one view.
PDF packages
One system or the whole register as a PDF, for the day you have no access. Private agreements encrypted, never shared.
EU AI Act module
Inventory, risk classification and audit-ready documentation of your AI systems. GDPR and NIS2 follow as modules.
Maditon is an EU compliance assistant for startups and SMEs.
The register. It keeps the register of suppliers and systems a small company is asked for, fetches copies of suppliers' published legal documents, reads them and reports what they say and what they leave out, each finding quoting the passage it came from.
Over time. It watches those documents for changes and e-mails what changed, compares candidate suppliers before a purchase, keeps SLA levels and support contacts in one view, drafts answers to customers' security and privacy questionnaires from the company's own record, and exports everything as PDF.
The modules. The EU AI Act module adds an inventory of AI systems with draft risk classifications and audit-ready documentation; GDPR and NIS2 modules follow. Everything runs on European infrastructure, and the reading is done by Mistral in France.
The seven kinds of document Maditon reads
- Privacy policy
- Terms of service
- Data processing agreement (DPA)
- Security page
- Sub-processor list
- AI policy
- Service level agreement (SLA)
Plus any document you upload yourself — a signed agreement, a supplier's security questionnaire — read on the same EU-only path, and kept private if you say so.
Built for AI risk assessment, classification, and compliance
AI risk assessment & classification
Classify each AI system under the EU AI Act as prohibited, high-risk, limited-risk or minimal-risk. Get plain-language obligations for every result.
Audit-Ready Documentation
Turn every risk assessment into regulation-compliant documentation. Every conclusion traces back to specific EU AI Act clauses.
Obligation Mapping
Map provider and deployer duties to each AI system, then translate dense regulatory text into actionable controls for your team.
One module today, the stack over time
The EU AI Act module is live. GDPR, NIS2 and more follow — each one the same source-referenced, audit-ready methodology, priced per module so you only pay for what you use.
See all modules →“Providers of high-risk AI systems shall put a quality management system in place that ensures compliance with this Regulation. The quality management system shall be documented in a systematic and orderly manner in the form of written policies, procedures and instructions.”
Dense regulatory text like this is exactly what Maditon translates into clear, actionable steps — with a reference to the exact clause that requires each control.
Every AI system you use assessed, classified, and audit-ready
-
AI-Led Interview
Plain-language questions. No regulatory vocabulary required. Your product manager can run this — reserve your lawyer for the cases that need one.
-
Risk Classification with Honest Gaps
When the AI isn’t sure, it says so. That’s what auditors trust, and what most AI tools quietly hide.
-
Human-Accepted Determinations
Every AI suggestion becomes a draft. A human on your team accepts it, with their name and timestamp. Accountability stays where the law says it must — with you. Maditon cuts the work down to hours.
-
PDF/A-1b Audit Dossier
One click. Archival-quality. Ready for a regulator.
-
Evidence Vault
Stop hunting through Notion, Drive and Slack the day before the audit. Everything in one place.
-
AI Literacy Training
Article 4 says your staff must have AI literacy. Most teams don’t know this exists. Maditon includes the training.
A chatbot here. An AI screening tool there. Now someone asks: “Is any of this high-risk under the AI Act?” Maditon answers that — for every system, with reasoning, in minutes.
Describe your AI system in plain language. Maditon maps it against every risk category in the regulation, flags what applies, and tells you exactly why — citing the specific articles behind each determination. No guesswork, no billable hours, no waiting for a consultant to get back to you.
You shouldn’t have to take our word for it every answer quotes the law it rests on
The frightening part of the AI Act isn’t the regulation. It’s putting your name to an answer you have no way of checking.
A consultant gives you a conclusion. A chatbot gives you a confident paragraph. Neither shows its working — and neither is the one standing there when a regulator asks why.
Maditon shows its working by default. Every classification arrives with the article behind it and the passage quoted word for word from the regulation, so you can read the law that decided your case without leaving the page.
The quote is the proof
Not a reference to look up later. The sentence itself, from Regulation (EU) 2024/1689, on screen beside the conclusion it produced. Open the full source in one click — or flag it, if you think we got it wrong.
It marks its own weak spots
A second pass checks every conclusion back against the retrieved legal text and reports what it could not support — a confidence score you can see, and a plain list of the claims that didn’t hold. Anything shaky is raised for expert review instead of quietly shipped.
Nothing counts until a person accepts it
Every AI determination is a draft. Someone on your team accepts it by name, and the record keeps who and when. That isn’t a formality — it is what the law requires, and it is the trail an auditor asks to see.
And the file is yours to take
Classifications, quoted sources, evidence and the full acceptance trail — exported as an archival PDF/A-1b dossier or machine-readable JSON, whenever you want. Self-serve. No ticket, no notice period, no one to ask.
CV screening for hiring
“AI systems intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates.”
Illustrative. A real determination carries your own system’s facts, its own sources, and the name of whoever accepted it.
European data sovereignty your data stays in Europe, always
Hosted Entirely in Europe
Data sovereignty by design. Everything you put into Maditon is processed and stored within European borders.
GDPR-Native Architecture
Built from the ground up for data minimisation, purpose limitation and data subject rights.
No Vendor Lock-In
Export your entire documentation bank in audit-ready formats at any time.
Multilingual
Available in English and Swedish today. German, French, Spanish and Italian coming soon.
Answers for startups, scaleups, and SMEs
How do I classify an AI system under the EU AI Act?
Start with the system’s purpose, users, data, sector, and effect on people. Maditon turns that into a structured EU AI Act risk assessment, checks the prohibited, high-risk, limited-risk and minimal-risk categories, and explains the classification with article references. The result is a documented classification your team can review and sign off.
Does the EU AI Act apply to startups and SMEs?
Yes. The EU AI Act applies by your role (provider or deployer) and your system’s risk tier — not by company size. A ten-person startup deploying a high-risk AI system carries the same core obligations as a large enterprise. There is no blanket SME exemption, though some duties are lighter and fines are capped for smaller companies. Maditon helps you find out exactly which tier each of your systems falls into.
Do I need a legal team to comply with the EU AI Act?
No. Maditon is built for startups, scaleups, and SMEs that don’t have a dedicated legal or compliance team. It runs a plain-language interview, drafts a risk classification with specific article references, and generates audit-ready documentation. A named person on your team accepts each determination — accountability stays with you, but the heavy lifting does not.
How do I know an EU AI Act classification is correct?
Check it against the law. Maditon names the article behind every classification and quotes the passage from Regulation (EU) 2024/1689 word for word, beside the conclusion it produced, with the full source one click away. A second pass then checks each conclusion back against the retrieved legal text and reports any claim it could not support, together with a confidence score — low-confidence results are raised for expert review rather than presented as settled. Nothing leaves draft until a named person on your team accepts it.
When are the EU AI Act deadlines?
Prohibited practices have applied since February 2025 and general-purpose AI model obligations since August 2025. The Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026) postponed the high-risk obligations (Annex III, including EU database registration) from August 2026 to 2 December 2027, and the rules for AI in regulated products to 2 August 2028. Those dates are now settled law, so classify your systems now to know which obligations will apply to you.
What does Maditon do with my suppliers' documents?
It fetches copies of what each supplier has published — privacy policy, terms, DPA, security page, sub-processor list, AI policy, SLA — reads them with Mistral on an EU endpoint, and returns findings that each quote the passage they came from. A finding is a question to put to the supplier, not a verdict. The documents are then re-read on schedule, and a daily e-mail tells you what changed and whether it matters.
Can Maditon answer my customers' security questionnaires?
Yes. Upload the questionnaire as XLSX, DOCX, CSV or PDF and Maditon drafts an answer to every question it can from your compliance profile, your supplier register and the answers you approved before, naming the source of each. You review and approve; only approved answers go into the file you export back to the customer. Documents you mark private are never used for drafts.
Is my company data kept in the EU?
Yes. Everything you put into Maditon — your systems, suppliers, documents and readings — is processed and stored in Europe by European-headquartered providers, and no US-headquartered cloud service processes it. This is a core architectural decision, not a configuration option. The one exception concerns billing only: Stripe, our payment processor, may transfer billing details (organisation name, billing email, country and VAT number) to its US affiliate. The privacy policy, section 5, describes the safeguards.
Auditors don’t want claims. They want evidence.
Documents, timestamps, and a human signature. That’s what Maditon produces. Go from AI risk assessment to a complete audit package in hours, not months.
Hosted in Europe · GDPR-compliant