557 enterprise domains analyzed DACH Benchmark 2026 0 of 557 DACH companies CERTIFIED — the first verified result is a measurable competitive advantage. View the DACH benchmark →

Our own domain meets the standard.

Verify the evidence yourself.

Am I affected?

Which companies must demonstrate EU AI Act compliance.

The EU AI Act doesn't apply equally to everyone. High-risk obligations apply to AI systems in regulated domains, regardless of company size or location. Find out in under 2 minutes whether your company is affected.

  • Credit scoring & creditworthiness assessment
  • HR software & candidate selection
  • Biometrics & identification
  • Diagnostic AI & healthcare
  • Critical infrastructure
  • B2B SaaS with AI for EU customers
Start the Annex III quick test →

2 minutes · No login · Free

Step 1 — Free

Am I affected by Annex III?

Find out in 2 minutes whether your AI system falls under the EU AI Act's high-risk obligations. The assessment starts immediately, 6 questions.

Go to the Annex III quick test
Step 2 — Instant evidence

Check your domain now

Your technical infrastructure evidence for EU AI Act Art. 50. 90 seconds, cryptographically signed, ready to hand to auditors.

Check your domain — free
The starting point

Regulatory pressure. Missing structure. Clear need for action.

August 2026

The EU AI Act's high-risk obligations took effect. Companies running AI in credit decisions, HR decisions, biometrics, or critical infrastructure are under direct scrutiny. Time is running out. A conformity assessment takes 3 to 6 months.

Liability

Boards and executive management bear personal responsibility for their AI systems' compliance documentation. A documented, cryptographically signed proof is the difference between demonstrated due diligence and an open liability risk.

What CERTavia delivers

GRC tools and consulting deliver process documentation. What Art. 50 additionally requires: a cryptographically signable, machine-readable infrastructure proof of data-source and governance transparency — deterministic, audit-ready, immediately available.

The offering

Infrastructure compliance check for the AI Act, DORA and NIS2

CERTavia scans a domain's AI infrastructure against 80+ deterministic parameters across 6 clusters. The result: SOVP-CERTIFIED or SOVP-FAILED, independently verifiable, immediately audit-ready.

The report includes an Art. 50 relevance rating per cluster, prioritized action items, and a machine-readable verification URL for auditors. Suitable as a technical building block for a conformity assessment dossier.

The Pro report includes:

80+ parameters across 6 clusters
90–120seconds to report
Art. 50relevance rating
Crypto.signed & timestamped

Included in the Pro report

  • 80+ parameter full scan of a domain
  • SOVP-CERTIFIED / SOVP-FAILED verdict with cluster detail
  • Art. 50 relevance rating: critical / relevant / informational
  • Prioritized action items
  • Sovereign Vault with no automatic expiry, machine-readable verification URL
  • Cryptographic signature, reproducible and audit-ready
  • JSON + CSV protocol output

From EUR 490 Basic · EUR 1,490 Pro · Enterprise from EUR 24,900 / year

Regulatory context

What the EU AI Act requires from your company.

Art. 50: transparency of data sources

Art. 50 requires transparency about AI use; the machine-readable labeling of AI-generated content (para. 2) applies only to providers of generative AI systems. CERTavia delivers the infrastructural evidence for it: deterministic, cryptographically signed, immediately verifiable by auditors.

Annex III: high-risk classification

Credit scoring, candidate selection, biometrics, diagnostic AI, critical infrastructure: all fall under the EU AI Act's strictest obligations. Companies starting the conformity assessment today will have audit-ready evidence in place.

DORA + NIS2: regulatory overlap

Financial service providers are subject to DORA, the EU AI Act, and NIS2 simultaneously. CERTavia addresses the shared infrastructure layer of these frameworks as a complementary building block. Risk management, human oversight, and data governance still require complementary internal processes.

EU AI Act Art. 50 Annex III DORA NIS2 Conformity Assessment High-risk AI GRC
The process

Three steps to audit-ready evidence.

Enter your domain

Enter your domain, choose a sector, start the scan. The result is ready in 90 seconds, payment processed via Stripe.

The scan runs automatically

SOVP scans the domain infrastructure in 90 to 120 seconds against 80+ deterministic parameters. Automatic. No manual effort. No room for interpretation. SOVP-CERTIFIED or SOVP-FAILED.

Use the evidence right away

PDF audit report, cryptographic signature, Sovereign Vault link: ready to forward to the board, compliance team, or external auditors.

example-company.com

CERTIFIED
TLS & encryption
DNSSEC
HTTP security headers
Certificate status

CES 91 · Cryptographically signed · Sovereign Vault active

The technology

Deterministic. Cryptographic. Audit-ready.

CERTavia is built on the Sovereign Validation Protocol (SOVP), an open infrastructure validation protocol with an active IETF draft and a US patent pending.

Deterministic

80+ parameters. 6 clusters. Binary result. No gray area. SOVP delivers an unambiguous SOVP-CERTIFIED or SOVP-FAILED: reproducible, independent, with no room for interpretation.

Cryptographically signed

Every report carries a cryptographic signature, deterministic and timestamped. The Sovereign Vault stores the audit record with no automatic expiry date. Auditors verify the report directly via the verification URL, timestamp-accurate, tamper-evident.

Regulatory grounding

SOVP addresses EU AI Act Art. 50: the machine-readable transparency and provenance evidence for AI systems. US patent pending #64/005,737 · IETF draft draft-litzki-sovp-03.

FAQ

Frequently asked questions.

Is CERTavia software or consulting?

CERTavia is an evidence product with a clear result logic. At its core is an automated, deterministic scan based on SOVP: a structured result that can be forwarded immediately. Additional consulting services are available for enterprise needs.

Which companies is CERTavia relevant for?

For regulated companies running AI in production in areas such as financial services, healthcare, HR software, or critical infrastructure — anywhere Annex III of the EU AI Act applies. Also relevant for SaaS providers offering AI features to EU customers, who carry their own Art. 50 provider obligations.

What does the result document contain?

A SOVP-CERTIFIED or SOVP-FAILED verdict with a full cluster breakdown, an Art. 50 relevance rating per cluster, prioritized action items, a cryptographic signature, a Sovereign Vault link, and a machine-readable verification URL. Suitable as a component of a conformity assessment dossier.

How long is the evidence valid?

The Pro report documents the verified infrastructure state at the time of issuance. The Sovereign Vault is permanently retrievable via token. For the Basic tier, vault availability is 90 days (local archiving required afterward). Re-certification after 90 days is recommended, since domain infrastructure changes continuously. Annual Starter, Annual Subscription and Enterprise products include automatic re-scans.

Does CERTavia replace a full compliance audit?

CERTavia delivers the infrastructural evidence for Art. 50 — the machine-readable Layer-0 proof of data-source and governance transparency. It complements existing GRC processes, ISO certifications and consulting services as a cryptographically verifiable building block of the conformity assessment dossier.

What's technically behind CERTavia?

CERTavia is built on the Sovereign Validation Protocol (SOVP), a deterministic infrastructure validation protocol with a cryptographic signature, DNS anchoring, and a secured audit record. US patent pending #64/005,737 · IETF draft draft-litzki-sovp-03 active.

How do I get access to the customer portal?

For Annual Starter, Annual Subscription and Enterprise, portal access is enabled automatically upon purchase — no separate account setup needed, login via email link tied to your purchase address (no password required). For Basic and Pro, the report is delivered directly by email via the scan access code; customer portal access is available on request via our contact form.

The web doesn't need better crawlers. It needs a foundation agents can stand on and know where they are. We're building that foundation as a protocol.
Thorsten Litzki, Founder & CEO, Litzki Systems LLC
Contact

For companies under real compliance pressure.

AI already in production. Audit pressure is real. CERTavia delivers the result: automated, structured, ready to use immediately.

No discovery call needed. Choose a product, start the scan. The result is ready in 90 seconds.

Financial services Healthcare HR software Critical infrastructure B2B SaaS

Get started now.

Enter your domain, result in 90 seconds.

Check your domain — free