Annex III conformity · self-service · Enterprise tier €2,499/mo
Sign up. Author your spec.
The substrate produces the handoff.
What used to be a €195k 90-day consultancy engagement is now a €2,499/month Enterprise tier with Stripe checkout. The substrate's outputs — L12 chain, framework-mapped handoff packet, runnable audit bundle — already do what the service was charging humans to produce by hand.
€2,499
Enterprise · flat / month
Stripe · cancel anytime · was €195k/90d as a service
7
Framework templates
GDPR · AI Act · PSD3 · DORA · NIS 2 · MDR · HIPAA
95%
Self-service
even regulated-EU banks · the 5% is partnership only
€5k
Optional DPA-session add-on
if you want one human on your first regulator call
01 · Match a lane
Three live reference chains. Pattern-match yours.
The substrate is sector-agnostic — the architectural primitives are the same for fintech, healthcare, and govtech. The three live reference chains exist so you have a concrete pattern to point at when explaining the substrate to legal / compliance / audit. Pick the closest match; the framework template adapts to your exact feature.
Fintech · Bank · Payments
PSD3 SCA + DORA Article 17. LLM-in-the-loop on credit, fraud, AML, dispute triage.
Canonical spec
Fraud classifier · 5 closed-enum outputs · €0–€50k transactions
Frameworks (Enterprise templates)
- ·PSD3 (SCA + 90/360)
- ·DORA Art. 17 (ICT incident)
- ·EU AI Act Annex III §5(b)
- ·Basel III ICAAP audit trail
DORA mandates third-party ICT audit trail; PSD3 mandates SCA decisioning reproducibility. The substrate's L12 chain delivers what both require — automatically.
Healthcare · Pharma · MedTech
HIPAA / GDPR Art. 9 + MDR + EU AI Act Annex III §5(c). Clinical-note structuring, decision support, triage.
Canonical spec
Clinical-note structurer · 4 typed outputs · safety-class C exclusion
Frameworks (Enterprise templates)
- ·EU AI Act Annex III §5(c) high-risk
- ·MDR Annex VIII rule-11 software-as-MD
- ·HIPAA Security Rule audit-controls
- ·GDPR Art. 9 special-category data
- ·ISO 13485 (CSR)
EU AI Act Annex III §5(c) is enforceable for high-risk medical AI from 2026-08-02. The substrate's signed schema-bounded output + reviewer gate IS the §14 human-oversight requirement.
Govtech · Public sector · Citizen services
eIDAS 2 + GDPR Art. 22 + EU AI Act §5(a). Eligibility, routing, summarisation.
Canonical spec
Eligibility router · 3 outcome enums · mandatory appeal-trail
Frameworks (Enterprise templates)
- ·EU AI Act §5(a) prohibited-practices boundary
- ·GDPR Art. 22 automated-decisioning
- ·eIDAS 2 e-identity binding
- ·EN 301 549 (WCAG 2.1 AA)
- ·Member-state DPA enforcement precedents
GDPR Art. 22 requires a meaningful human-decision route for solely-automated processing. The L12 chain + reviewer gate IS what 'meaningful human decision' looks like operationally.
02 · What Enterprise delivers for Annex III
Six features. All in the €2,499/mo tier.
Everything the old €195k service used to deliver — but running inside the substrate, generated by the substrate, accessible the moment you upgrade to Enterprise. No 90-day engagement gate. No two-engineer retainer. No consultant-week dependency for routine compliance work.
01
Framework handoff templates
Pre-built notified-body-ready packet templates for GDPR, AI Act Annex III/IV, PSD3+PSR, DORA, NIS 2, MDR, and HIPAA. Renderer emits Markdown + JSON for the regulator-facing packet; signed manifest binds it to the chain head. (PDF export is operator-side post-processing — the substrate ships the structured Markdown + JSON.)
02
Article-by-article mandate mapping
Auto-generated cross-reference: every clause of your RuntimeAISpec → the regulatory article it satisfies. The notified body reads it as a table; their checklist becomes mechanical.
03
15-min Bitcoin-anchored OTS
L12 chain head submitted to OpenTimestamps calendars every 15 min (the Vercel cron-tick floor); daily anchor-upgrade cron promotes the pending proofs to Bitcoin-confirmed once the calendar's next batch fires. Regulators see externally-witnessed timestamps verifiable against any Bitcoin full node.
04
HSM key custody hooks (roadmap)
On the roadmap: Ed25519 signing through PKCS#11, YubiHSM 2, AWS CloudHSM, or Thales Luna. Current path is operator-managed env-var key custody (the operator holds the private seed; Promethean never sees it). HSM integration ships with Scale + Enterprise once available.
05
On-premise deployment (roadmap)
On the roadmap: Docker + Helm distribution for in-VPC deployment. Today: Promethean runs on Vercel (EU Frankfurt) + Upstash Redis (EU); the substrate's PII-safe hash-only design means the audit-trail layer doesn't see raw operator data either way.
06
SSO + audit log retention
SAML / OIDC for workspace access. 7-year audit log retention satisfies most regulatory record-keeping minimums. Full CSV + JSONL exports for monthly compliance close.
03 · Split of work · honest
What the substrate does. What you do.
The substrate does
- ✓Bound every LLM call to a closed-enum schema (RuntimeAISpec)
- ✓Route ambiguous outputs through a reviewer-queue gate
- ✓Apply your declared fallback when the model fails
- ✓Write a signed L12 receipt per decision
- ✓Anchor the chain into Bitcoin via OpenTimestamps
- ✓Generate the regulator-ready audit bundle (CLI)
- ✓Produce framework-mapped handoff packets (Enterprise)
- ✓Verify offline via 50 KB plain-JS verifier
You do
- ·Sign up for the right tier (Enterprise for Annex III)
- ·Author one RuntimeAISpec per regulated AI feature
- ·Wire the SDK into your existing service (~30 min per spec)
- ·Configure your reviewer queue (operator-supplied UI or use ours)
- ·Run the substrate against staging traffic for a week
- ·Run `node verify.mjs` to confirm chain integrity
- ·Hand the regulator the audit bundle when they ask
- ·(Optional) Buy the €5k DPA-session add-on for your first call
What no one does for you: the legal sign-off, the regulatory strategy, the internal risk-committee presentation, the DPA relationship. Those are your work, same as they'd be with any platform. The substrate just removes the question of "where does the evidence come from?"
04 · Common objections
Six honest answers.
QWe're a regulated bank — surely we need humans on this, not just docs?
You need humans for legal sign-off, regulatory strategy, and your internal risk committee. We don't replace any of those. What we replace is the consultant who'd otherwise generate the L12 chain + audit bundle + framework mapping by hand at €195k per system. The substrate emits that automatically. Your lawyer reads the output, your DPO files it. If you want one human call before your first DPA meeting, the €5k add-on covers that.
QHow is €2,499/mo enough for what was €195k for 90 days?
Because the substrate's own outputs do 90% of what the service was charging for. The €195k paid for two engineers' time over 90 days — €117k of that was their salaries, the rest was margin. We removed the engineers. The substrate writes the same audit bundle, generates the same framework mapping, produces the same notified-body-readable packet. You don't need our engineers between you and the substrate's outputs.
QWhat about our specific regulatory rail — is the framework template good enough?
Seven frameworks shipped: GDPR, AI Act Annex III/IV, PSD3, DORA, NIS 2, MDR, HIPAA. Each template covers the article-by-article mapping the notified body needs. If your jurisdiction's regulator wants a specific format we don't have, you can extend the template yourself (it's TypeScript) or commission a custom one (€15k one-time, becomes part of the substrate for everyone). 99% of regulated-EU buyers fit one of the seven shipped frameworks.
QWhat if my regulator hasn't seen this kind of evidence before?
That's the most common case, and it's where the optional €5k DPA-session add-on earns its keep. We've designed the chain so it maps onto familiar regulatory shapes — GDPR Art. 30 records, DORA Art. 17 audit trails, AI Act Annex IV documentation. Regulators don't need new mental models; they need familiar shapes filled with verifiable evidence. The optional add-on covers the first regulator session if you want a substrate engineer in the room.
QVendor lock-in?
Apache 2.0 substrate (kernel + generators + SDK + verifier). Your spec is yours. Your chain is yours. Your integration code is yours. If you cancel Enterprise, you keep everything. The verifier is 150 lines of plain JS; you can audit it in an afternoon. Self-hosting is supported on the same tier (Enterprise on-prem) — you can run the entire stack inside your VPC.
QWhat's the 5% that's NOT self-service?
Two things, both partnership structures: (1) Frontier-model OEM — if you're Anthropic / OpenAI / Mistral / Cohere wanting to bake the substrate into your API surface, that's a revenue-share or royalty deal that doesn't fit a fixed price. (2) AI-vendor channel — if you're a LangChain / observability / orchestration vendor wanting to resell substrate-emitted audit chains to your enterprise customers, that's a reseller deal at €80k+/yr per integration. Both are rare, both are sales-led, both are the genuine exceptions. For everything else: Stripe checkout.
Annex III conformity is a feature flag. Flip it.
Sign up to Enterprise (€2,499/mo, Stripe checkout, cancel anytime). Author your RuntimeAISpec. Run the SDK against your staging traffic. Generate the audit bundle. Hand it to your DPO. Your compliance team reads the framework-mapped handoff packet and decides whether they need anything more. Most don't.