Our own domain meets the standard.
Verify the evidence yourself.
Which companies must demonstrate EU AI Act compliance.
The EU AI Act doesn't apply equally to everyone. High-risk obligations apply to AI systems in regulated domains, regardless of company size or location. Find out in under 2 minutes whether your company is affected.
- Credit scoring & creditworthiness assessment
- HR software & candidate selection
- Biometrics & identification
- Diagnostic AI & healthcare
- Critical infrastructure
- B2B SaaS with AI for EU customers
2 minutes · No login · Free
Audit-ready evidence for auditors, investors and the supervisory board. Protect your personal liability.
Learn more → IT leaders & CTOsDeterministic Layer-0 check, API-capable, machine-readable, CI/CD-integrable.
Learn more → Compliance managers & GRCArt. 50 evidence for the conformity assessment dossier. GRC system export included.
Learn more → CISOsExternal evidence for risk registers, third-party risk and NIS2 Art. 21 risk management measures.
Learn more → Data protection officersTechnical cross-check between your privacy notice and actual AI governance configuration.
Learn more →Verifiable evidence instead of testimonials
CERTavia launched in June 2026. Instead of testimonials, we show what's cryptographically verifiable: real scan results and the current market situation.
From CERTIFIED (CES 94/100) to FAILED (CES 41/100). The first case is cryptographically signed and independently verifiable via the Sovereign Vault. The other six cases are anonymized — real scan results, not quotes.
View references → DACH Benchmark 2026: the first CERTIFIED spot is open496 enterprise domains analyzed, median CES: 54.5 — not a single company has reached the threshold yet. The window for the first verified CERTIFIED result in DACH is open now.
View the DACH benchmark → Founding Partner ProgramFor auditors, GRC consultancies and MSSPs: early-stage terms, co-branding option and direct roadmap influence. CERTavia is being built now — joining today means reference status in the growing market for AI Act infrastructure evidence.
Become a partner →Regulatory pressure. Missing structure. Clear need for action.
August 2026
The EU AI Act's high-risk obligations took effect. Companies running AI in credit decisions, HR decisions, biometrics, or critical infrastructure are under direct scrutiny. Time is running out. A conformity assessment takes 3 to 6 months.
Liability
Boards and executive management bear personal responsibility for their AI systems' compliance documentation. A documented, cryptographically signed proof is the difference between demonstrated due diligence and an open liability risk.
What CERTavia delivers
GRC tools and consulting deliver process documentation. What Art. 50 additionally requires: a cryptographically signable, machine-readable infrastructure proof of data-source and governance transparency — deterministic, audit-ready, immediately available.
Infrastructure compliance check for the AI Act, DORA and NIS2
CERTavia scans a domain's AI infrastructure against 80+ deterministic parameters across 6 clusters. The result: SOVP-CERTIFIED or SOVP-FAILED, independently verifiable, immediately audit-ready.
The report includes an Art. 50 relevance rating per cluster, prioritized action items, and a machine-readable verification URL for auditors. Suitable as a technical building block for a conformity assessment dossier.
The Pro report includes:
Included in the Pro report
- 80+ parameter full scan of a domain
- SOVP-CERTIFIED / SOVP-FAILED verdict with cluster detail
- Art. 50 relevance rating: critical / relevant / informational
- Prioritized action items
- Sovereign Vault with no automatic expiry, machine-readable verification URL
- Cryptographic signature, reproducible and audit-ready
- JSON + CSV protocol output
From EUR 490 Basic · EUR 1,490 Pro · Enterprise from EUR 24,900 / year
What the EU AI Act requires from your company.
Art. 50: transparency of data sources
Art. 50 requires transparency about AI use; the machine-readable labeling of AI-generated content (para. 2) applies only to providers of generative AI systems. CERTavia delivers the infrastructural evidence for it: deterministic, cryptographically signed, immediately verifiable by auditors.
Annex III: high-risk classification
Credit scoring, candidate selection, biometrics, diagnostic AI, critical infrastructure: all fall under the EU AI Act's strictest obligations. Companies starting the conformity assessment today will have audit-ready evidence in place.
DORA + NIS2: regulatory overlap
Financial service providers are subject to DORA, the EU AI Act, and NIS2 simultaneously. CERTavia addresses the shared infrastructure layer of these frameworks as a complementary building block. Risk management, human oversight, and data governance still require complementary internal processes.
Three steps to audit-ready evidence.
Enter your domain
Enter your domain, choose a sector, start the scan. The result is ready in 90 seconds, payment processed via Stripe.
The scan runs automatically
SOVP scans the domain infrastructure in 90 to 120 seconds against 80+ deterministic parameters. Automatic. No manual effort. No room for interpretation. SOVP-CERTIFIED or SOVP-FAILED.
Use the evidence right away
PDF audit report, cryptographic signature, Sovereign Vault link: ready to forward to the board, compliance team, or external auditors.
example-company.com
Deterministic. Cryptographic. Audit-ready.
CERTavia is built on the Sovereign Validation Protocol (SOVP), an open infrastructure validation protocol with an active IETF draft and a US patent pending.
Deterministic
80+ parameters. 6 clusters. Binary result. No gray area. SOVP delivers an unambiguous SOVP-CERTIFIED or SOVP-FAILED: reproducible, independent, with no room for interpretation.
Cryptographically signed
Every report carries a cryptographic signature, deterministic and timestamped. The Sovereign Vault stores the audit record with no automatic expiry date. Auditors verify the report directly via the verification URL, timestamp-accurate, tamper-evident.
Regulatory grounding
SOVP addresses EU AI Act Art. 50: the machine-readable transparency and provenance evidence for AI systems. US patent pending #64/005,737 · IETF draft draft-litzki-sovp-03.
Frequently asked questions.
Is CERTavia software or consulting?
CERTavia is an evidence product with a clear result logic. At its core is an automated, deterministic scan based on SOVP: a structured result that can be forwarded immediately. Additional consulting services are available for enterprise needs.
Which companies is CERTavia relevant for?
For regulated companies running AI in production in areas such as financial services, healthcare, HR software, or critical infrastructure — anywhere Annex III of the EU AI Act applies. Also relevant for SaaS providers offering AI features to EU customers, who carry their own Art. 50 provider obligations.
What does the result document contain?
A SOVP-CERTIFIED or SOVP-FAILED verdict with a full cluster breakdown, an Art. 50 relevance rating per cluster, prioritized action items, a cryptographic signature, a Sovereign Vault link, and a machine-readable verification URL. Suitable as a component of a conformity assessment dossier.
How long is the evidence valid?
The Pro report documents the verified infrastructure state at the time of issuance. The Sovereign Vault is permanently retrievable via token. For the Basic tier, vault availability is 90 days (local archiving required afterward). Re-certification after 90 days is recommended, since domain infrastructure changes continuously. Annual Starter, Annual Subscription and Enterprise products include automatic re-scans.
Does CERTavia replace a full compliance audit?
CERTavia delivers the infrastructural evidence for Art. 50 — the machine-readable Layer-0 proof of data-source and governance transparency. It complements existing GRC processes, ISO certifications and consulting services as a cryptographically verifiable building block of the conformity assessment dossier.
What's technically behind CERTavia?
CERTavia is built on the Sovereign Validation Protocol (SOVP), a deterministic infrastructure validation protocol with a cryptographic signature, DNS anchoring, and a secured audit record. US patent pending #64/005,737 · IETF draft draft-litzki-sovp-03 active.
How do I get access to the customer portal?
For Annual Starter, Annual Subscription and Enterprise, portal access is enabled automatically upon purchase — no separate account setup needed, login via email link tied to your purchase address (no password required). For Basic and Pro, the report is delivered directly by email via the scan access code; customer portal access is available on request via our contact form.
The web doesn't need better crawlers. It needs a foundation agents can stand on and know where they are. We're building that foundation as a protocol.
For companies under real compliance pressure.
AI already in production. Audit pressure is real. CERTavia delivers the result: automated, structured, ready to use immediately.
No discovery call needed. Choose a product, start the scan. The result is ready in 90 seconds.