For Compliance Managers and GRC Teams

The infrastructure evidence that fits your dossier.

Art. 50 EU AI Act requires transparency about AI use; the machine-readable labeling of AI output (para. 2) applies only to providers who develop or offer a generative AI system under their own brand. CERTavia supplies the infrastructure evidence for your conformity assessment dossier: machine-readable, cryptographically signed, importable into existing GRC systems — ready for external auditors and notified bodies.

The regulatory requirement

What Art. 50 specifically requires from you

Art. 50 EU AI Act obliges providers and deployers of AI systems to disclose AI use, label AI output in a machine-readable way, and document its provenance verifiably. This evidence must be available to external auditors and notified bodies — as part of the conformity assessment dossier under Art. 43.

CERTavia delivers the infrastructure building block for this evidence: a deterministic, cryptographically signed finding on your domain's technical infrastructure. The result complements the legal conformity assessment under Art. 43 as a technical layer-0 record that can be handed directly to auditors.

What compliance teams receive

Four deliverables for the dossier

PDF audit report for the dossier

Structured finding with cluster-based Art. 50 relevance rating (Critical / Relevant / Informational). Includes executive summary, strategic assessment and Sovereign Vault link. Ready for internal filing and direct handover to external auditors and notified bodies.

Machine-readable verification URL

External auditors and notified bodies can query the compliance status automatically — without system access, timestamped, tamper-evident. The stable endpoint follows the Sovereign Vault Protocol (Pro and above: permanently retrievable via token).

JSON + CSV for GRC systems

The structured output imports into ServiceNow, MetricStream, Archer and comparable GRC platforms. All 80+ parameter values with cluster scores, verdict and Art. 50 reference — no manual reformatting.

Sovereign Vault permanently retrievable via token

The audit record is cryptographically secured with no automatic expiry (Pro and above). Remains evidentiary even after an audit period — the state at the time of the check is documented immutably.

The process

Three steps to a dossier building block

Quick Scan — free, 90 seconds

Enter a domain, the scan runs automatically. Initial assessment: CES score, cluster overview, SOVP-CERTIFIED or SOVP-FAILED. No login, no registration.

Order Pro or Annual Subscription

For the full Art. 50 evidence with cryptographic signature, Sovereign Vault permanently retrievable via token, and machine-readable verification URL. PDF report, JSON output and CSV available directly after the scan completes.

Export and filing

PDF into the conformity assessment dossier, JSON/CSV into the GRC system, Sovereign Vault link to external auditors. Annual Subscription customers receive automatic re-scans and change notifications.

Scope and boundaries

What CERTavia delivers — and what it doesn't

What CERTavia delivers

The infrastructure layer-0 evidence under Art. 50: a deterministic finding on technical infrastructure integrity, cryptographically signed, machine-readable, audit-ready. Complementary to GRC processes, ISO certifications and legal counsel — as a technical building block in the conformity assessment dossier.

What CERTavia does not replace

CERTavia is not a legal opinion and not a conformity assessment under Art. 43. For legally binding conformity assessments, contact an accredited notified body (TÜV, DEKRA, BSI-accredited bodies). CERTavia addresses the infrastructure layer — not the legal, organizational or content compliance assessment.

For the dossier: The CERTavia Pro report can be documented in the conformity assessment dossier as "infrastructure evidence under Art. 50 EU AI Act." The Sovereign Vault link enables external auditors to verify independently — timestamped, without system access.

Frequently asked questions

FAQ for compliance managers

Will a notified body / conformity assessment body accept this report?

The EU AI Act does not prescribe a specific evidence format — it requires that Art. 50 requirements (transparency, machine-readable labeling, provenance) are demonstrably met. The CERTavia report is a cryptographically signed, deterministic finding with an Ed25519 signature and DNS-anchored timestamp, independently verifiable of CERTavia. Accredited conformity assessment bodies (TÜV, DEKRA, BSI-accredited bodies) can perform verification via the machine-readable verification URL or the Sovereign Vault link — without system access and without needing to contact CERTavia. The report can be submitted in the conformity assessment dossier as "infrastructure evidence under Art. 50 EU AI Act."

Is a CERTavia report sufficient for the complete conformity assessment dossier?

CERTavia delivers the infrastructure layer (Art. 50), but not the complete CAD. The dossier additionally requires: system description, risk analysis, test protocols, declaration of conformity and, where applicable, notified-body review. CERTavia is a cryptographically verifiable building block within this package — specifically for the technical infrastructure evidence.

How long is a CERTavia report usable in the dossier?

The PDF audit report, the Ed25519 signature and the DNS-anchored timestamp remain permanently valid and document the infrastructure state at the time of the scan. The Sovereign Vault link (Pro and above: permanent; Basic: 90 days) enables external auditors to verify online. For post-market monitoring we recommend re-scans every 90 days or upon infrastructure changes.

How do I get access to the customer portal?

With Annual Starter, Annual Subscription and Enterprise, portal access is unlocked automatically upon purchase — no separate account setup needed, login via email link to your purchase address (no password required). With Basic and Pro, the report is delivered directly by email via the scan access code; portal access here is available on request through our contact form.

The right package for your dossier

Pricing for compliance managers and GRC teams

Basic €490

PDF audit report, cryptographic signature, Sovereign Vault available for 90 days (local archiving required afterward). Suitable for an initial assessment and dossier baseline.

Pro €1,490

Sovereign Vault permanently retrievable via token, machine-readable verification URL, JSON + CSV export. Recommended as a dossier building block and for GRC system integration.

Annual Subscription €9,900 / year

Quarterly re-scans, annual evidence, change notifications, up to 25 domains. Suitable for ongoing audit requirements with continuous dossier maintenance.

Next step

Determine your infrastructure status now.

The free domain scan checks 80+ parameters against SOVP and delivers a CERTIFIED / FAILED result in 90 seconds — ready to attach to your conformity assessment dossier.