Maditon Your EU compliance assistant

Live today: supplier register, change watching, questionnaires, EU AI Act module · GDPR, NIS2 next

Built for startups and SMEs without a legal team. Maditon keeps the register your customers and auditors ask for, reads your suppliers' documents and watches them for changes, and drafts the answers to your customers' questionnaires. It does the volume work — the judgement stays yours.

7
Kinds of supplier document read
Daily
Checks of watched documents
100%
Hosted in Europe
/ What Maditon does for you

From a supplier's documents to the answer on your customer's questionnaire

Supplier register

Who you depend on, and what their privacy policies, terms and agreements actually say. Every finding quotes the passage it came from.

Change watching

Documents are re-read on schedule. When terms change you get the difference, and whether it matters, in a morning e-mail.

Questionnaires

Your customer's security or privacy questionnaire answered from your own record. You review, approve and send the file back.

Systems, SLA and contacts

Which systems depend on which suppliers, with SLA levels and support contacts in one view.

PDF packages

One system or the whole register as a PDF, for the day you have no access. Private agreements encrypted, never shared.

EU AI Act module

Inventory, risk classification and audit-ready documentation of your AI systems. GDPR and NIS2 follow as modules.

Maditon is an EU compliance assistant for startups and SMEs.

The register. It keeps the register of suppliers and systems a small company is asked for, fetches copies of suppliers' published legal documents, reads them and reports what they say and what they leave out, each finding quoting the passage it came from.

Over time. It watches those documents for changes and e-mails what changed, compares candidate suppliers before a purchase, keeps SLA levels and support contacts in one view, drafts answers to customers' security and privacy questionnaires from the company's own record, and exports everything as PDF.

The modules. The EU AI Act module adds an inventory of AI systems with draft risk classifications and audit-ready documentation; GDPR and NIS2 modules follow. Everything runs on European infrastructure, and the reading is done by Mistral in France.

The seven kinds of document Maditon reads

  • Privacy policy
  • Terms of service
  • Data processing agreement (DPA)
  • Security page
  • Sub-processor list
  • AI policy
  • Service level agreement (SLA)

Plus any document you upload yourself — a signed agreement, a supplier's security questionnaire — read on the same EU-only path, and kept private if you say so.

/ The first module: EU AI Act

Built for AI risk assessment, classification, and compliance

AI risk assessment & classification

Classify each AI system under the EU AI Act as prohibited, high-risk, limited-risk or minimal-risk. Get plain-language obligations for every result.

Prohibited
High Risk
Limited
Minimal

Audit-Ready Documentation

Turn every risk assessment into regulation-compliant documentation. Every conclusion traces back to specific EU AI Act clauses.

Obligation Mapping

Map provider and deployer duties to each AI system, then translate dense regulatory text into actionable controls for your team.

One module today, the stack over time

The EU AI Act module is live. GDPR, NIS2 and more follow — each one the same source-referenced, audit-ready methodology, priced per module so you only pay for what you use.

See all modules →
GDPR
2018
NIS2
2024
EU AI Act
2025
CRA
2026
EU AI Act
Article 17(1)
“Providers of high-risk AI systems shall put a quality management system in place that ensures compliance with this Regulation. The quality management system shall be documented in a systematic and orderly manner in the form of written policies, procedures and instructions.”

Dense regulatory text like this is exactly what Maditon translates into clear, actionable steps — with a reference to the exact clause that requires each control.

/ How EU AI Act risk assessment works

Every AI system you use assessed, classified, and audit-ready

  1. AI-Led Interview

    Plain-language questions. No regulatory vocabulary required. Your product manager can run this — reserve your lawyer for the cases that need one.

  2. Risk Classification with Honest Gaps

    When the AI isn’t sure, it says so. That’s what auditors trust, and what most AI tools quietly hide.

  3. Human-Accepted Determinations

    Every AI suggestion becomes a draft. A human on your team accepts it, with their name and timestamp. Accountability stays where the law says it must — with you. Maditon cuts the work down to hours.

  4. PDF/A-1b Audit Dossier

    One click. Archival-quality. Ready for a regulator.

  5. Evidence Vault

    Stop hunting through Notion, Drive and Slack the day before the audit. Everything in one place.

  6. AI Literacy Training

    Article 4 says your staff must have AI literacy. Most teams don’t know this exists. Maditon includes the training.

EU AI Act
Risk Classification

A chatbot here. An AI screening tool there. Now someone asks: “Is any of this high-risk under the AI Act?” Maditon answers that — for every system, with reasoning, in minutes.

Describe your AI system in plain language. Maditon maps it against every risk category in the regulation, flags what applies, and tells you exactly why — citing the specific articles behind each determination. No guesswork, no billable hours, no waiting for a consultant to get back to you.

/ Auditable by design

You shouldn’t have to take our word for it every answer quotes the law it rests on

The frightening part of the AI Act isn’t the regulation. It’s putting your name to an answer you have no way of checking.

A consultant gives you a conclusion. A chatbot gives you a confident paragraph. Neither shows its working — and neither is the one standing there when a regulator asks why.

Maditon shows its working by default. Every classification arrives with the article behind it and the passage quoted word for word from the regulation, so you can read the law that decided your case without leaving the page.

The quote is the proof

Not a reference to look up later. The sentence itself, from Regulation (EU) 2024/1689, on screen beside the conclusion it produced. Open the full source in one click — or flag it, if you think we got it wrong.

It marks its own weak spots

A second pass checks every conclusion back against the retrieved legal text and reports what it could not support — a confidence score you can see, and a plain list of the claims that didn’t hold. Anything shaky is raised for expert review instead of quietly shipped.

Nothing counts until a person accepts it

Every AI determination is a draft. Someone on your team accepts it by name, and the record keeps who and when. That isn’t a formality — it is what the law requires, and it is the trail an auditor asks to see.

And the file is yours to take

Classifications, quoted sources, evidence and the full acceptance trail — exported as an archival PDF/A-1b dossier or machine-readable JSON, whenever you want. Self-serve. No ticket, no notice period, no one to ask.

Example determination

CV screening for hiring

High-risk Draft
Annex III(4) · Employment and workers’ management
“AI systems intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates.”
Verified · 0 claims unsupported Awaiting acceptance

Illustrative. A real determination carries your own system’s facts, its own sources, and the name of whoever accepted it.

/ EU data residency

European data sovereignty your data stays in Europe, always

Hosted Entirely in Europe

Data sovereignty by design. Everything you put into Maditon is processed and stored within European borders.

GDPR-Native Architecture

Built from the ground up for data minimisation, purpose limitation and data subject rights.

No Vendor Lock-In

Export your entire documentation bank in audit-ready formats at any time.

Multilingual

Available in English and Swedish today. German, French, Spanish and Italian coming soon.

/ Common questions

Answers for startups, scaleups, and SMEs

How do I classify an AI system under the EU AI Act?

Start with the system’s purpose, users, data, sector, and effect on people. Maditon turns that into a structured EU AI Act risk assessment, checks the prohibited, high-risk, limited-risk and minimal-risk categories, and explains the classification with article references. The result is a documented classification your team can review and sign off.

Does the EU AI Act apply to startups and SMEs?

Yes. The EU AI Act applies by your role (provider or deployer) and your system’s risk tier — not by company size. A ten-person startup deploying a high-risk AI system carries the same core obligations as a large enterprise. There is no blanket SME exemption, though some duties are lighter and fines are capped for smaller companies. Maditon helps you find out exactly which tier each of your systems falls into.

Do I need a legal team to comply with the EU AI Act?

No. Maditon is built for startups, scaleups, and SMEs that don’t have a dedicated legal or compliance team. It runs a plain-language interview, drafts a risk classification with specific article references, and generates audit-ready documentation. A named person on your team accepts each determination — accountability stays with you, but the heavy lifting does not.

How do I know an EU AI Act classification is correct?

Check it against the law. Maditon names the article behind every classification and quotes the passage from Regulation (EU) 2024/1689 word for word, beside the conclusion it produced, with the full source one click away. A second pass then checks each conclusion back against the retrieved legal text and reports any claim it could not support, together with a confidence score — low-confidence results are raised for expert review rather than presented as settled. Nothing leaves draft until a named person on your team accepts it.

When are the EU AI Act deadlines?

Prohibited practices have applied since February 2025 and general-purpose AI model obligations since August 2025. The Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026) postponed the high-risk obligations (Annex III, including EU database registration) from August 2026 to 2 December 2027, and the rules for AI in regulated products to 2 August 2028. Those dates are now settled law, so classify your systems now to know which obligations will apply to you.

What does Maditon do with my suppliers' documents?

It fetches copies of what each supplier has published — privacy policy, terms, DPA, security page, sub-processor list, AI policy, SLA — reads them with Mistral on an EU endpoint, and returns findings that each quote the passage they came from. A finding is a question to put to the supplier, not a verdict. The documents are then re-read on schedule, and a daily e-mail tells you what changed and whether it matters.

Can Maditon answer my customers' security questionnaires?

Yes. Upload the questionnaire as XLSX, DOCX, CSV or PDF and Maditon drafts an answer to every question it can from your compliance profile, your supplier register and the answers you approved before, naming the source of each. You review and approve; only approved answers go into the file you export back to the customer. Documents you mark private are never used for drafts.

Is my company data kept in the EU?

Yes. Everything you put into Maditon — your systems, suppliers, documents and readings — is processed and stored in Europe by European-headquartered providers, and no US-headquartered cloud service processes it. This is a core architectural decision, not a configuration option. The one exception concerns billing only: Stripe, our payment processor, may transfer billing details (organisation name, billing email, country and VAT number) to its US affiliate. The privacy policy, section 5, describes the safeguards.

Auditors don’t want claims. They want evidence.

Documents, timestamps, and a human signature. That’s what Maditon produces. Go from AI risk assessment to a complete audit package in hours, not months.

Hosted in Europe  ·  GDPR-compliant