What is in use?
The purpose, status, owners and criticality of new AI applications are not captured centrally. The actual inventory remains unclear.
Versatile AI Risk Assessment brings system context, threats, controls, the EU AI Act and GDPR together in one continuous assessment. You receive a clear risk rating, prioritised actions and an audit‑ready evidence package for approvals, internal reviews and customer questions.
Versatile AI Risk Assessment connects risk ratings, prioritised actions and regulatory classification with the evidence your teams need for approvals, reviews and further work.
Open the Community Edition directly in your browser with no sign‑up. Review threat profiles, risk matrices, the EU AI Act and GDPR, generate a PDF report and preserve the working state as a versioned project file.
Full Community Edition with example data
The demo runs locally in your browser. Please do not enter real or confidential data.
Every AI application needs three clear answers: What is in use? How was it assessed? Why was it approved? When this information is scattered, delays and additional review effort follow.
The purpose, status, owners and criticality of new AI applications are not captured centrally. The actual inventory remains unclear.
Data protection, information security, legal and business teams document their findings separately. There is no aligned risk picture.
Rationale, conditions and evidence are not linked end to end. Decisions can only be evidenced later with additional effort.
If one answer is missing, the basis for the decision remains incomplete.
From system context to GDPR classification: every view comes from the Community Edition and shows how inputs, assessments and evidence work together.
Versatile AI Risk Assessment connects capture, threat analysis, risk assessment, regulatory classification and exports in one continuous workflow. Each step builds traceably on the previous one.
Record purpose, data categories, owners, deployment phase and criticality of the AI system.
Apply the curated catalogue, check relevance and assess inherent risk.
Record existing and planned actions, their rationale and the remaining residual risk.
Document role, risk class, obligations, data protection questions and DPIA needs for professional review.
Prepare reports and machine‑readable formats for approvals, reviews and downstream systems.
Good governance does not start with a feature list, but with the people who carry responsibility. Find the situation that reflects your work – and see immediately which version supports it.
Data protection · Information security · Research & education
Before starting a project, Peter wants to work through a structured AI risk assessment himself – with no installation, user account or commitment.
“I want to experience the method through a complete example before deciding on productive use.”
The complete application with example data runs directly in the browser. No server, no sign‑up and no transfer of assessment data.
Typical: Data protection, compliance and information security for personal orientation, plus students, researchers, educators and nonprofit teams without commercial use.
AI risk management · independent review · information security
Katrin manages several assessments and needs complete reports, workbooks, machine‑readable exports and robust evidence packages – often in protected customer environments.
“I need professional results, but no central server and no simultaneous editing.”
The productive single‑user workstation for people who assess AI risks regularly – in clearly delimited projects and environments where data and the application need to stay local.
Typical: Internal review teams, external specialists, data protection and compliance consultants, and smaller organisations with clearly assigned individual responsibility.
Consulting · GRC provider · regulated organisation
Anna wants to use Versatile AI Risk Assessment under her own brand, map her own risk and control models and prepare standardised handovers to established enterprise processes.
“The methodology has to fit our catalogues and handover paths – with maximum data sovereignty.”
A tailored offline solution for your own brand, methodology and handover processes – without having to operate a central multi‑user platform.
Typical: GRC and consulting firms, audit organisations, public authorities, critical infrastructure operators, and OEM and white‑label partners.
AI governance · Compliance · Enterprise risk
Business teams, data protection, information security, compliance and audit need the same current state – but different permissions and clearly governed decisions.
“We need more than files being sent around: a binding process, clear responsibilities and a complete history.”
The central multi‑user version in development for self‑hosted operation on your own hardware or in your own cloud. Not vendor‑operated SaaS.
Typical: Groups, banks, insurers, public administration, pharma, critical infrastructure and organisations with formalised AI governance.
Assessment data stays in the browser. The application works without tracking and discloses its components, vulnerability status and licences. This allows IT, information security and procurement to review it themselves before approval.
The application processes entries locally. Nothing is saved or exported unless you trigger the action yourself.
The live demo runs with no server in the background, tracking, profiling or newsletter sign‑up.
Components, vulnerability status and the licences used are supplied as verifiable evidence.
IT, information security and procurement can assess operation and build independently using the evidence provided.
The Community Edition remains free for the long term. Professional and Enterprise are purchased once; the delivered version remains usable for the long term. Maintenance, updates and support are renewed after twelve months when needed.
Terms for Professional and Enterprise
Work locally and non‑commercially free of charge
for the permitted non‑commercial scope
Assess and manage AI systems in production
per named‑user licence
Integrated into your brand and system landscape
per organisation and agreed delivery scope
Versatile AI Risk Assessment Connected brings the complete assessment workflow into central multi‑user operation. Teams work on the same state, access follows clear roles, sign‑in runs through your identity provider, and the review workflow and audit trail make decisions traceable. The principle remains the same: your data stays in your environment.
FocusAcross workspacesFacet filtersAssessment status
FocusRisk matricesThreatsVersioning
FocusRisk indexCoverageOpen items
FocusPrioritisationResidual riskThreats
FocusRisk classesArticle 5GPAI
FocusRoles and permissionsSegregation of dutiesAccess management
FocusDark modePortfolioInterface
Six building blocks turn the single assessment into one shared, traceable working state.
Assessments live centrally per team or client. Every state follows a clear path from draft through review to approval and archive. Approved states are locked; only authorised members can reopen them.
Sign‑in runs via your identity provider; the application itself manages no passwords. Those who manage structure and operation do not see content; those who review content do not change it. This keeps administration, professional assessment and approval clearly separated. Particularly sensitive actions require re‑authentication.
Confidential assessments are visible only to the people named for them. They do not appear in the lists and metrics of any other role.
Every saved state is versioned on the server. Editing locks and visible conflict notices coordinate simultaneous changes. The audit trail makes progress and approvals traceable for authorised teams.
The governance cockpit condenses risk index, coverage and open items into a plain‑language management summary. The AI inventory keeps the estate current, with filters and full‑text search.
Reports and working states as PDF, XLSX, CSV, DOCX and JSON, plus connections to EAM and ITSM systems, straight from the evaluation.
No SaaS component, no external runtime dependencies, no data leaving your environment. The stack runs on your hardware or in your cloud and stays operable down to isolated environments. You keep control of data, operation and updates.
Secure defaults instead of after‑the‑fact configuration: encrypted connections, strict content policies, session and access protection plus confirmations for sensitive actions are active from the start, in every deployment variant.
The application is delivered from a minimal container without a shell or package manager; all services run unprivileged and with no path to privilege escalation. Every release is independently traceable via a bill of materials (SBOM), vulnerability status (VEX) and checksums.
As a partner, you test new capabilities early and help shape catalogues, workflows and connections. Your specific review and approval paths become the basis for priorities and targeted extensions.
Adapt threat and control catalogues to your industry, systems and internal requirements.
Connect steps, fields, responsibilities and exports to your existing processes.
Try development versions in practice and prioritise your requirements directly.
From data flows and deployment to evidence, regulatory classification and procurement: here you will find the answers that matter.
You open the full Community Edition directly in your browser: assess the example AI system, review the system‑type based threat selection, generate PDF reports and preserve the working state as a versioned project file for later re‑import. Completely without sign‑up, without real data and without any data transfer to a server.
No assessment data is transferred automatically. The working state is stored automatically in local browser storage. A file leaves the application only when you explicitly export a PDF report or project file.
A tool that promotes transparency has to be measured by the same standard. On the engineering side, the application ships with a bill of materials (SBOM), the vulnerability status (VEX) and the licences used; this lets Versatile AI Risk Assessment be reviewed independently before approval. The professional content is assured as well: the threat catalogue and the EU AI Act and GDPR content, more than 2,500 reviewed items in total, pass through a documented review and approval process with named sources and automated checks. Professional and Enterprise deliveries include this proof as content assurance documentation: catalogue release, source register, check results and checksum.
No. Versatile AI Risk Assessment creates the transparency and structure for exactly these decisions: it shows, organises and documents. The final legal, professional and regulatory classification is made by the responsible roles in your organisation – Versatile AI Risk Assessment does not guarantee or certify it.
The Community Edition remains free of charge. Professional Offline costs a one‑off €2,490 per named user, including 12 months of updates and email support. From the second year, updates and support can be extended for €490 per year. Enterprise / White‑Label Offline starts at a one‑off €12,900 per organisation and agreed delivery scope; maintenance starts at €1,980 per year from year two. All amounts exclude VAT. The delivered version remains usable without a maintenance renewal; there is no usage‑based billing and no automatic renewal.
The Community Edition and standard operation run as a client‑side single file with no server in the background. Professional adds the capabilities for productive use. Enterprise adds white label, customer‑specific catalogues and connections. Connected is separate from these and is the central multi‑user version in development for operation in your environment.
Depending on the edition you get reports (PDF), workbooks (XLSX) and machine‑readable formats (CSV, JSON) plus connections to EAM and ITSM systems. That gives you an evidence package for approvals, internal reviews, due diligence, procurement and customer questions.
Yes. For your procurement and IT security review we provide a solid basis on request: data flow, operating model, scope of delivery, catalogue status, third‑party software used as well as SBOM/VEX documents. This gives IT, information security, procurement and compliance a well‑founded basis for the adoption decision.
Yes. Versatile AI Risk Assessment Connected brings teams together on one shared, centrally stored state in your environment. Sign‑in runs through your identity provider. The roles and permissions model governs responsibility and access, while the review workflow and audit trail make every change traceable. All views in the Connected section are original screenshots from the running reference stack. As a partner, you use the current state early and help set the priorities.
Whether you want to order Professional, adapt Enterprise or white label, or help shape Connected as a partner: briefly tell us about your plans. We will respond personally with the appropriate next steps. Your details are only transferred to us when you submit the form.
Versatile AI Risk Assessment
For example: demo, editions, transparency, EU AI Act, contact