What Veritome does
Veritome is one register for the AI a company runs and the governance that attaches to it. A branching intake classifies each system against Article 5, Annex I and Annex III; a rules engine derives the exact obligations for your role and risk tier; smart forms and document generators produce your Annex IV technical file, FRIA, Declaration of Conformity and Annex VIII registration; and every record is timestamped and hash-sealed into a regulator-view dossier with a public verify URL.
Alongside that statutory work, four further regimes run as programmes on the same systems — the GDPR, ISO/IEC 42001, ISO/IEC 27001 and the NIST AI Risk Management Framework — sharing the evidence, the owners and the dates rather than duplicating them. That is 385 catalogue requirements across the five, and 83 programme steps that resolve to 69 distinct records.
You can see the output before you sign up. The sample dossier is a real generated file rather than a screenshot of one, which is the test we think you should apply to every vendor in this category — including us.
How this started
Veritome began as an EU AI Act tool, and would have stayed one, if not for a syllabus.
While the first version was being built, Tomislav took the ISO/IEC 42001 Foundation certificate — the AI management system standard — to settle a narrow question: did it belong in the product at all, or was it scope creep dressed up as ambition?
The answer turned out to be neither. Section after section, the standard was asking questions that had already been asked somewhere else. Risk management across the AI lifecycle. Documented roles and accountability. The effect of a system on the people subject to it. Data quality and provenance. The competence of the staff operating it. Logging, monitoring, incident handling. Those are Articles 9, 10, 12, 14, 15 and 17 of the EU AI Act in a different register — and several of them are questions the GDPR has been asking since 2018.
Different vocabularies. Different auditors. Different certificates. Largely the same underlying work.
That is not an original discovery — anyone who has sat two of these exams knows it. What was striking was how little the software market behaves as though it were true. Frameworks are sold as separate products: an EU AI Act tool, an ISO tool, a privacy tool. So a forty-person company buys three subscriptions, runs three projects, and writes the same access-control policy into three formats for three auditors, none of whom will ever see the other two. The connection between the frameworks was real; nothing in the tooling was holding it.
So the architecture changed, and the product went from one framework to five.
Why the Act is the spine
Widening the scope raised a design question immediately: if five regimes are connected, which one is the trunk?
Of the five, exactly one is not optional. ISO/IEC 42001 and ISO/IEC 27001 are standards you choose to certify against, on your own timetable. NIST AI RMF is voluntary. The GDPR applies wherever personal data flows — real, but conditional on that. The EU AI Act applies because it is law: it does not wait for a board decision, and its dates arrive whether or not the organisation is ready.
So the Act is the spine. Every system is classified against it first, and the obligations that follow are derived from that classification per system rather than picked from a menu. The four voluntary frameworks then run as programmes over the same register: their steps produce records against the same systems, with the same evidence, owners and due dates. The statutory work happens whether or not you ever pursue a certificate — and if you later decide to, you are not starting from an empty project.
Where Veritome is deliberately strict is credit. A record counts toward a second framework only where it has been verified against both clause sets — 14 records today, all of them shared between ISO/IEC 42001 and ISO/IEC 27001. Every other connection, the EU AI Act crosswalks included, appears as a related link: it names the neighbouring clause and ticks nothing. 38 records carry such a link to an EU AI Act article without being credited for it. An unverified tick in a compliance tool is worse than no tick at all, because you find out at the audit. The full crossover matrix shows both, kept apart.
Why this exists
The EU AI Act is the first comprehensive law of its kind anywhere in the world — several hundred pages of dense legal text with real teeth, carrying fines up to €35 million or 7% of global turnover. Large enterprises responded the way they always do: they hired consultancies at six-figure rates, and were sold each framework as its own engagement.
SMEs — the businesses that make up most of the European economy — were left to figure it out alone, and cannot buy the same problem four times. Veritome closes that gap: it gives a forty-person company the same clarity on its obligations as a multinational, without the price tag and without the consultancy theatre. The frameworks and controls register is included from the €199 Govern tier upward rather than priced per framework, which is the commercial half of the same argument.
Who it is for
Deployers using third-party AI under Article 26, providers placing high-risk systems on the market, GPAI model providers, and the in-house counsel and law firms advising them. Veritome speaks the Act’s language on every screen — each step anchored to its article — so the same record works for your team, your auditor, and a regulator.
It reaches beyond the EU too. A UK or US organisation is in scope when it places an AI system on the EU market or when the output of that system is used in the Union, and the obligations that follow are identical.
And beyond the Act: the security lead who already runs ISO/IEC 27001 and has been handed AI governance on top of it, the organisation whose customers have started asking for ISO/IEC 42001, and the team that wants the NIST AI RMF vocabulary for a US parent. Those are the same systems and the same evidence, which is the whole reason they belong on one register.
How it works
The statutory spine is one guided journey of six phases. Each phase unlocks when the one before it is complete, so you always know the next task, who owns it, and what evidence is still missing — the engine derives all of it from the classification. Switch on any of the other four frameworks and it runs as a programme with its own gated phases over the same systems, producing records that sit beside the Act’s rather than in a separate tool.
Who builds it
Veritome is built by Relay Labs Limited, a small, AI-native software studio in Dublin. It is led by Tomislav, who spent over two decades in operational roles in regulated industries, first banking, and later healthcare. That background is the point: this is software written by someone who has had to make a documentation framework work for busy staff under a real deadline, not theory written from the outside.
In practice that means a product that ships updates in days rather than quarters, prices for SMEs rather than enterprises, and is run by someone you can actually reach. Every feature is shaped by direct conversation with the operators and counsel who use it.
One thing worth separating clearly, because the two are easy to blur: a foundation certificate is a personal qualification held by one person, not an organisational one held by the company. Tomislav holds the ISO/IEC 42001 Foundation certificate; Relay Labs holds no certifications. The table below says so, and will until that changes.
Where we are today
We publish a comparison of twelve tools in this category and assess ourselves against the same criteria as everyone else — corporate disclosure, certifications, weaknesses. These are those facts, unedited. If any of them would disqualify us for you, better that you learn it here than three weeks into an evaluation.
What that buys you: a product that moves fast and a founder who answers the email. What it costs you: no decade of audit history, no Big Four implementation channel, no certification to hand your procurement team. Both halves are true and you should weigh them.
What we believe
Where your data lives
Every byte of customer data and every AI call stays in the EU/EEA. That is a design constraint, not a marketing line — it is why the assistant runs on a French model rather than the obvious American one.
Two US processors handle payments and transactional email under standard contractual clauses; neither receives your compliance records. The full list is at sub-processors, the security posture at the Trust Centre, and the data processing agreement is readable before you sign anything.
Questions we get asked
Is Veritome an EU AI Act tool or an AI governance platform?
Both, in that order. Veritome runs five regimes — the EU AI Act, the GDPR, ISO/IEC 42001, ISO/IEC 27001 and the NIST AI Risk Management Framework — on one register of AI systems. The Act is the spine because it is the only one of the five that is law: it applies whether or not you opt in, and its dates arrive regardless. The other four run as programmes alongside it, so the governance work sits in one place instead of four tools. If you only need the Act today, that is the whole product on its own.
Who is behind Veritome?
Veritome is built by Relay Labs Limited, registered in Dublin, Ireland under company number 807438 and founded on 30.01.2026. It is led by Tomislav, who spent over two decades in operational roles in regulated industries — banking first, then healthcare. It is bootstrapped, with no outside investment, and the team is currently one person.
Why did Veritome expand beyond the EU AI Act?
It came out of taking the ISO/IEC 42001 Foundation certificate while building the first version. The standard kept asking questions the EU AI Act had already asked in different words — risk management, roles and accountability, data quality, human oversight, logging, incident handling — and several the GDPR had been asking since 2018. The frameworks were not four separate bodies of work; they were four vocabularies for largely the same governance. Most software in this category still sells them as separate products, so an organisation buys three tools and answers the same question three times. Veritome instead treats the Act as the spine and hangs the voluntary standards off it.
If I do the work once, does it count across all five frameworks?
Sometimes, and Veritome is deliberately strict about which. A record is credited in a second framework only where it has been verified against both clause sets — today that is 14 records shared between ISO/IEC 42001 and ISO/IEC 27001, which is why enabling both costs you 14 fewer pieces of work than running them apart. Every other connection, including all of the EU AI Act crosswalks, is shown as a related link: the matrix tells you the two clauses are about the same subject, and it does not tick anything on your behalf. An unverified tick in a compliance tool is worse than no tick, because you only find out at the audit.
Does Veritome hold ISO 27001, ISO 42001 or SOC 2 — and can it certify me?
No to both. Relay Labs holds no certifications today and says so rather than implying otherwise; the founder holds the ISO/IEC 42001 Foundation certificate, but that is a personal qualification and not an organisational certification — the two should not be confused. Veritome is also not a certification body or an auditor: it runs the ISO programmes so your evidence and clause coverage are in order before a real auditor looks at them, but the certificate comes from an accredited body, not from us. What Veritome does have is published sub-processors, documented encryption at rest and in transit, a hash-chained audit trail you can verify yourself, and a Trust Centre that states the current posture rather than a target one. If a vendor certification is a procurement requirement for you, that is a real reason to choose someone else and we will say so.
Where is my data stored?
Entirely in the EU/EEA. The application and its PostgreSQL database run in Nuremberg, object storage in Falkenstein, the cache in Frankfurt, and the customer-facing AI assistant on Mistral in Paris. Error monitoring and product analytics use EU endpoints. The full sub-processor list, including the two US processors used for payments and transactional email under standard contractual clauses, is published at veritome.eu/sub-processors.
Is Veritome legal advice?
No. Classification under the EU AI Act involves judgement that no software tool resolves definitively, and the documents Veritome generates are drafts built from what you tell it. Have a qualified lawyer review your classification and your conformity documentation before you place a high-risk system on the market. Every classification screen names the article it rests on, which is what makes that review possible rather than guesswork.
What does Veritome not do?
It does not monitor models. There is no drift detection, no bias testing and no runtime enforcement — Veritome documents and tracks obligations, it does not sit in front of your inference calls. It does not certify or audit you, it does not file anything with a regulator on your behalf, and it is not a substitute for legal review. Our published comparison of twelve tools names the vendors that do the things we do not.
How many AI systems can I manage, and do the frameworks cost extra?
Classify is free — three systems, classified, with the article each conclusion rests on. Paid plans follow how much of the Act's work you have to do, because that is what decides the price: Starter at €79 per month covers one or two systems and the literacy, transparency and GDPR records every user of AI owes; Govern at €199 covers a governance programme across 25 systems with one high-risk system, GDPR in full and the ISO/IEC 42001 and NIST AI RMF programmes included; Manage at €599 covers the full high-risk provider programme, including the Article 17 quality management system, with three high-risk systems and ISO/IEC 27001 included, and €49 for each additional high-risk system. Annual billing charges ten months for twelve. Enterprise is quoted. Pricing is published in full — you do not need a sales call to find out what it costs.
Beyond Veritome
Relay Labs builds practical software for regulated and operationally complex industries — with a particular focus on healthcare workflows and compliance tooling. Veritome is our flagship, and the bar we hold every other product to.
There is no shortage of ideas for where this goes next — more of them than one person can build in a year, which is a good problem and a real constraint. What governs which ones ship is the same test that produced the five: does it genuinely overlap what is already on the register, and can that overlap be verified clause by clause rather than asserted? Anything we cannot map honestly is something we would rather not sell. We will announce what is coming when it is close enough to be a date rather than an intention.
Something wrong on this page, or a question it does not answer? Tell us — we correct things publicly.