Try it directly in your browser
Open the application in your browser with no sign‑up: assess threats, classify the EU AI Act and GDPR, generate a PDF report. You are working with the full application and an example project.
Versatile AI Risk Assessment brings system context, threats, controls, the EU AI Act and GDPR together in one continuous assessment. You receive a clear risk rating, prioritised actions and an audit‑ready evidence package for approvals, internal reviews and customer questions.
Versatile AI Risk Assessment connects risk ratings, prioritised actions and regulatory classification with the evidence your teams need for approvals, reviews and further work.
The live demo is already the full Community Edition. Your working state stays local in your browser and can be preserved and re‑imported as a versioned project file. Use the application freely for personal work, education, research and nonprofit purposes.
Open the application in your browser with no sign‑up: assess threats, classify the EU AI Act and GDPR, generate a PDF report. You are working with the full application and an example project.
Choose the risk model; both editions use the same catalogues and keep their working states separate.
Finely graded risk values from 0 to 11 based on protection level, likelihood and exploitability. For detailed comparison and prioritisation.
The classic matrix of likelihood and impact in three levels each. For working with the established three‑level grid.
The example project shows the methodology in a fully completed assessment and can be removed in the application at any time. PDF reports carry a Community watermark.
Each module of the full application is also available on its own: free of charge, as a single HTML file, entirely local in your browser.
KI‑Risiko‑Check
Threat and risk analysis with 52 curated threats, risk matrices and baseline comparison.
EU‑KI‑VO‑Check
Guided assessment under the EU AI Act down to the EU risk class, with obligation catalogue and deadlines.
DSGVO‑Check
Data protection assessment with DPIA screening: 93 questions in 10 sections and a role‑based obligation status.
For commercial use, the full application and the modules are available as Professional editions. Get in touch
Every AI application needs three clear answers: What is in use? How was it assessed? Why was it approved? When this information is scattered, delays and additional review effort follow.
The purpose, status, owners and criticality of new AI applications are not captured centrally. The actual inventory remains unclear.
Data protection, information security, legal and business teams document their findings separately. There is no aligned risk picture.
Rationale, conditions and evidence are not linked end to end. Decisions can only be evidenced later with additional effort.
If one answer is missing, the basis for the decision remains incomplete.
From system context to GDPR classification: every view comes from the Community Edition and shows how inputs, assessments and evidence work together.
Versatile AI Risk Assessment connects capture, threat analysis, risk assessment, regulatory classification and exports in one continuous workflow. Each step builds traceably on the previous one.
Record purpose, data categories, owners, deployment phase and criticality of the AI system.
Apply the curated catalogue, check relevance and assess inherent risk.
Record existing and planned actions, their rationale and the remaining residual risk.
Document role, risk class, obligations, data protection questions and DPIA needs for professional review.
Prepare reports and machine‑readable formats for approvals, reviews and downstream systems.
Good governance does not start with a feature list, but with the people who carry responsibility. Find the situation that reflects your work – and see immediately which version supports it.
Peter, Katrin, Anna and Thomas are fictional example profiles with illustrative quotes, not customer testimonials.
Data protection · Information security · Research & education
Before starting a project, Peter wants to work through a structured AI risk assessment himself – with no installation, user account or commitment.
“I want to experience the method through a complete example before deciding on productive use.”
The complete application with example data runs directly in the browser. No server, no sign‑up and no transfer of assessment data.
AI risk management · independent review · information security
Katrin manages several assessments and needs complete reports, workbooks, machine‑readable exports and robust evidence packages – often in protected customer environments.
“I need professional results, but no central server and no simultaneous editing.”
The productive single‑user workstation for people who assess AI risks regularly – in clearly delimited projects and environments where data and the application need to stay local.
Consulting · GRC provider · regulated organisation
Anna wants to use Versatile AI Risk Assessment under her own brand, map her own risk and control models and prepare standardised handovers to established enterprise processes.
“The methodology has to fit our catalogues and handover paths – with maximum data sovereignty.”
A tailored offline solution for your own brand, methodology and handover processes – without having to operate a central multi‑user platform.
AI governance · Compliance · Enterprise risk
Business teams, data protection, information security, compliance and audit need the same current state – but different permissions and clearly governed decisions.
“We need more than files being sent around: a binding process, clear responsibilities and a complete history.”
The central multi‑user version in development for self‑hosted operation on your own hardware or in your own cloud. Not vendor‑operated SaaS.
Assessment data stays in the browser. The application works without tracking and discloses its components, vulnerability status and licences. This allows IT, information security and procurement to review it themselves before approval.
All evidence comes from the current Community bundle and ships with every delivery. IT, information security and procurement can verify it independently. The professional catalogues currently comprise 2,546 reviewed content items from 63 named sources (threat analysis, EU AI Act, GDPR/EDPB).
The Community Edition remains free for the long term. Professional and Enterprise are purchased once; the delivered version remains usable indefinitely. Maintenance, updates and support are renewed after twelve months when needed.
Terms for Professional and Enterprise
Work locally and non‑commercially free of charge
for the permitted non‑commercial scope
Assess and manage AI systems in production
per named‑user licence
Integrated into your brand and system landscape
per organisation and agreed delivery scope
A manual AI risk analysis under the EU AI Act and GDPR ties up expert resources or drives consulting costs. Versatile AI Risk Assessment turns it into structured work of hours instead of days. Typical market ranges for orientation:
For independent auditors and data protection consultants: the licence is often recouped with the first billed client engagement.
Versatile AI Risk Assessment Connected brings the complete assessment workflow into central multi‑user operation. Teams work on the same state, access follows clear roles, sign‑in runs through your identity provider, and the review workflow and audit trail make decisions traceable. The principle remains the same: your data stays in your environment.
FocusAcross workspacesFacet filtersAssessment status
FocusRisk matricesThreatsVersioning
FocusRisk indexCoverageOpen items
FocusPrioritisationResidual riskThreats
FocusRisk classesArticle 5GPAI
FocusRoles and permissionsSegregation of dutiesAccess management
FocusDark modePortfolioInterface
All views are original screenshots from a running reference stack with demo data; personas and the brand “Musterbank AG” are fictitious. Connected is not yet part of today’s editions; scope and timing are agreed together with pilot partners.
Six building blocks turn the single assessment into one shared, traceable working state.
Assessments live centrally per team or client. Every state follows a clear path from draft through review to approval and archive. Approved states are locked; only authorised members can reopen them.
Sign‑in runs via your identity provider; the application itself manages no passwords. Those who manage structure and operation do not see content; those who review content do not change it. This keeps administration, professional assessment and approval clearly separated. Particularly sensitive actions require re‑authentication.
Confidential assessments are visible only to the people named for them. They do not appear in the lists and metrics of any other role.
Every saved state is versioned on the server. Editing locks and visible conflict notices coordinate simultaneous changes. The audit trail makes progress and approvals traceable for authorised teams.
The governance cockpit condenses risk index, coverage and open items into a plain‑language management summary. The AI inventory keeps the estate current, with filters and full‑text search.
Reports and working states as PDF, XLSX, CSV, DOCX and JSON, plus connections to EAM and ITSM systems, straight from the evaluation.
No SaaS component, no external runtime dependencies, no data leaving your environment. The stack runs on your hardware or in your cloud and stays operable down to isolated environments. You keep control of data, operation and updates.
Secure defaults instead of after‑the‑fact configuration: encrypted connections, strict content policies, session and access protection plus confirmations for sensitive actions are active from the start, in every deployment variant.
The application is delivered from a minimal container without a shell or package manager; all services run unprivileged and with no path to privilege escalation. Every release is independently traceable via a bill of materials (SBOM), vulnerability status (VEX) and checksums.
From data flows and deployment to evidence, regulatory classification and procurement: here you will find the answers that matter.
You open the full Community Edition directly in your browser: assess the example AI system, review the system‑type based threat selection, generate PDF reports and preserve the working state as a versioned project file for later re‑import. Completely without sign‑up, without real data and without any data transfer to a server.
No assessment data is transferred automatically. The working state is stored automatically in local browser storage. A file leaves the application only when you explicitly export a PDF report or project file.
A tool that promotes transparency has to be measured by the same standard. On the engineering side, the application ships with a bill of materials (SBOM), the vulnerability status (VEX) and the licences used; this lets Versatile AI Risk Assessment be reviewed independently before approval. The professional content is assured as well: the threat catalogue and the EU AI Act and GDPR content, more than 2,500 reviewed items in total, pass through a documented review and approval process with named sources and automated checks. Professional and Enterprise deliveries include this proof as content assurance documentation: catalogue release, source register, check results and checksum.
No. Versatile AI Risk Assessment creates the transparency and structure for exactly these decisions: it shows, organises and documents. The final legal, professional and regulatory classification is made by the responsible roles in your organisation – Versatile AI Risk Assessment does not guarantee or certify it.
The Community Edition remains free of charge. Professional Offline costs a one‑off €2,490 per named user, including 12 months of updates and email support. From the second year, updates and support can be extended for €490 per year. Enterprise / White‑Label Offline starts at a one‑off €12,900 per organisation and agreed delivery scope; maintenance starts at €1,980 per year from year two. All amounts exclude VAT. The delivered version remains usable without a maintenance renewal; there is no usage‑based billing and no automatic renewal.
The Community Edition and standard operation run as a client‑side single file with no server in the background. Professional adds the capabilities for productive use. Enterprise adds white label, customer‑specific catalogues and connections. Connected is separate from these and is the central multi‑user version in development for operation in your environment.
Depending on the edition you get reports (PDF), workbooks (XLSX) and machine‑readable formats (CSV, JSON) plus connections to EAM and ITSM systems. That gives you an evidence package for approvals, internal reviews, due diligence, procurement and customer questions.
Yes. For your procurement and IT security review we provide a solid basis on request: data flow, operating model, scope of delivery, catalogue status, third‑party software used as well as SBOM/VEX documents. This gives IT, information security, procurement and compliance a well‑founded basis for the adoption decision.
Yes. Versatile AI Risk Assessment Connected brings teams together on one shared, centrally stored state in your environment. Sign‑in runs through your identity provider. The roles and permissions model governs responsibility and access, while the review workflow and audit trail make every change traceable. All views in the Connected section are original screenshots from the running reference stack. As a partner, you use the current state early and help set the priorities.
Whether you want to order Professional, adapt Enterprise or white label, or help shape Connected as a partner: briefly tell us about your plans. We will respond personally with the appropriate next steps, usually within one business day. Your details are only transferred to us when you submit the form.
Versatile AI Risk Assessment
For example: demo, editions, transparency, EU AI Act, contact