Annex III conformity · self-service · Enterprise tier €2,499/mo

Sign up. Author your spec.
The substrate produces the handoff.

What used to be a €195k 90-day consultancy engagement is now a €2,499/month Enterprise tier with Stripe checkout. The substrate's outputs — L12 chain, framework-mapped handoff packet, runnable audit bundle — already do what the service was charging humans to produce by hand.

€2,499

Enterprise · flat / month

Stripe · cancel anytime · was €195k/90d as a service

7

Framework templates

GDPR · AI Act · PSD3 · DORA · NIS 2 · MDR · HIPAA

95%

Self-service

even regulated-EU banks · the 5% is partnership only

€5k

Optional DPA-session add-on

if you want one human on your first regulator call

01 · Match a lane

Three live reference chains. Pattern-match yours.

The substrate is sector-agnostic — the architectural primitives are the same for fintech, healthcare, and govtech. The three live reference chains exist so you have a concrete pattern to point at when explaining the substrate to legal / compliance / audit. Pick the closest match; the framework template adapts to your exact feature.

Fintech · Bank · Payments

PSD3 SCA + DORA Article 17. LLM-in-the-loop on credit, fraud, AML, dispute triage.

Canonical spec

Fraud classifier · 5 closed-enum outputs · €0–€50k transactions

Frameworks (Enterprise templates)

  • ·PSD3 (SCA + 90/360)
  • ·DORA Art. 17 (ICT incident)
  • ·EU AI Act Annex III §5(b)
  • ·Basel III ICAAP audit trail

DORA mandates third-party ICT audit trail; PSD3 mandates SCA decisioning reproducibility. The substrate's L12 chain delivers what both require — automatically.

Healthcare · Pharma · MedTech

HIPAA / GDPR Art. 9 + MDR + EU AI Act Annex III §5(c). Clinical-note structuring, decision support, triage.

Canonical spec

Clinical-note structurer · 4 typed outputs · safety-class C exclusion

Frameworks (Enterprise templates)

  • ·EU AI Act Annex III §5(c) high-risk
  • ·MDR Annex VIII rule-11 software-as-MD
  • ·HIPAA Security Rule audit-controls
  • ·GDPR Art. 9 special-category data
  • ·ISO 13485 (CSR)

EU AI Act Annex III §5(c) is enforceable for high-risk medical AI from 2026-08-02. The substrate's signed schema-bounded output + reviewer gate IS the §14 human-oversight requirement.

Govtech · Public sector · Citizen services

eIDAS 2 + GDPR Art. 22 + EU AI Act §5(a). Eligibility, routing, summarisation.

Canonical spec

Eligibility router · 3 outcome enums · mandatory appeal-trail

Frameworks (Enterprise templates)

  • ·EU AI Act §5(a) prohibited-practices boundary
  • ·GDPR Art. 22 automated-decisioning
  • ·eIDAS 2 e-identity binding
  • ·EN 301 549 (WCAG 2.1 AA)
  • ·Member-state DPA enforcement precedents

GDPR Art. 22 requires a meaningful human-decision route for solely-automated processing. The L12 chain + reviewer gate IS what 'meaningful human decision' looks like operationally.

02 · What Enterprise delivers for Annex III

Six features. All in the €2,499/mo tier.

Everything the old €195k service used to deliver — but running inside the substrate, generated by the substrate, accessible the moment you upgrade to Enterprise. No 90-day engagement gate. No two-engineer retainer. No consultant-week dependency for routine compliance work.

01

Framework handoff templates

Pre-built notified-body-ready packet templates for GDPR, AI Act Annex III/IV, PSD3+PSR, DORA, NIS 2, MDR, and HIPAA. Renderer emits Markdown + JSON for the regulator-facing packet; signed manifest binds it to the chain head. (PDF export is operator-side post-processing — the substrate ships the structured Markdown + JSON.)

02

Article-by-article mandate mapping

Auto-generated cross-reference: every clause of your RuntimeAISpec → the regulatory article it satisfies. The notified body reads it as a table; their checklist becomes mechanical.

03

15-min Bitcoin-anchored OTS

L12 chain head submitted to OpenTimestamps calendars every 15 min (the Vercel cron-tick floor); daily anchor-upgrade cron promotes the pending proofs to Bitcoin-confirmed once the calendar's next batch fires. Regulators see externally-witnessed timestamps verifiable against any Bitcoin full node.

04

HSM key custody hooks (roadmap)

On the roadmap: Ed25519 signing through PKCS#11, YubiHSM 2, AWS CloudHSM, or Thales Luna. Current path is operator-managed env-var key custody (the operator holds the private seed; Promethean never sees it). HSM integration ships with Scale + Enterprise once available.

05

On-premise deployment (roadmap)

On the roadmap: Docker + Helm distribution for in-VPC deployment. Today: Promethean runs on Vercel (EU Frankfurt) + Upstash Redis (EU); the substrate's PII-safe hash-only design means the audit-trail layer doesn't see raw operator data either way.

06

SSO + audit log retention

SAML / OIDC for workspace access. 7-year audit log retention satisfies most regulatory record-keeping minimums. Full CSV + JSONL exports for monthly compliance close.

03 · Split of work · honest

What the substrate does. What you do.

The substrate does

  • Bound every LLM call to a closed-enum schema (RuntimeAISpec)
  • Route ambiguous outputs through a reviewer-queue gate
  • Apply your declared fallback when the model fails
  • Write a signed L12 receipt per decision
  • Anchor the chain into Bitcoin via OpenTimestamps
  • Generate the regulator-ready audit bundle (CLI)
  • Produce framework-mapped handoff packets (Enterprise)
  • Verify offline via 50 KB plain-JS verifier

You do

  • ·Sign up for the right tier (Enterprise for Annex III)
  • ·Author one RuntimeAISpec per regulated AI feature
  • ·Wire the SDK into your existing service (~30 min per spec)
  • ·Configure your reviewer queue (operator-supplied UI or use ours)
  • ·Run the substrate against staging traffic for a week
  • ·Run `node verify.mjs` to confirm chain integrity
  • ·Hand the regulator the audit bundle when they ask
  • ·(Optional) Buy the €5k DPA-session add-on for your first call

What no one does for you: the legal sign-off, the regulatory strategy, the internal risk-committee presentation, the DPA relationship. Those are your work, same as they'd be with any platform. The substrate just removes the question of "where does the evidence come from?"

04 · Common objections

Six honest answers.

QWe're a regulated bank — surely we need humans on this, not just docs?
A

You need humans for legal sign-off, regulatory strategy, and your internal risk committee. We don't replace any of those. What we replace is the consultant who'd otherwise generate the L12 chain + audit bundle + framework mapping by hand at €195k per system. The substrate emits that automatically. Your lawyer reads the output, your DPO files it. If you want one human call before your first DPA meeting, the €5k add-on covers that.

QHow is €2,499/mo enough for what was €195k for 90 days?
A

Because the substrate's own outputs do 90% of what the service was charging for. The €195k paid for two engineers' time over 90 days — €117k of that was their salaries, the rest was margin. We removed the engineers. The substrate writes the same audit bundle, generates the same framework mapping, produces the same notified-body-readable packet. You don't need our engineers between you and the substrate's outputs.

QWhat about our specific regulatory rail — is the framework template good enough?
A

Seven frameworks shipped: GDPR, AI Act Annex III/IV, PSD3, DORA, NIS 2, MDR, HIPAA. Each template covers the article-by-article mapping the notified body needs. If your jurisdiction's regulator wants a specific format we don't have, you can extend the template yourself (it's TypeScript) or commission a custom one (€15k one-time, becomes part of the substrate for everyone). 99% of regulated-EU buyers fit one of the seven shipped frameworks.

QWhat if my regulator hasn't seen this kind of evidence before?
A

That's the most common case, and it's where the optional €5k DPA-session add-on earns its keep. We've designed the chain so it maps onto familiar regulatory shapes — GDPR Art. 30 records, DORA Art. 17 audit trails, AI Act Annex IV documentation. Regulators don't need new mental models; they need familiar shapes filled with verifiable evidence. The optional add-on covers the first regulator session if you want a substrate engineer in the room.

QVendor lock-in?
A

Apache 2.0 substrate (kernel + generators + SDK + verifier). Your spec is yours. Your chain is yours. Your integration code is yours. If you cancel Enterprise, you keep everything. The verifier is 150 lines of plain JS; you can audit it in an afternoon. Self-hosting is supported on the same tier (Enterprise on-prem) — you can run the entire stack inside your VPC.

QWhat's the 5% that's NOT self-service?
A

Two things, both partnership structures: (1) Frontier-model OEM — if you're Anthropic / OpenAI / Mistral / Cohere wanting to bake the substrate into your API surface, that's a revenue-share or royalty deal that doesn't fit a fixed price. (2) AI-vendor channel — if you're a LangChain / observability / orchestration vendor wanting to resell substrate-emitted audit chains to your enterprise customers, that's a reseller deal at €80k+/yr per integration. Both are rare, both are sales-led, both are the genuine exceptions. For everything else: Stripe checkout.

Annex III conformity is a feature flag. Flip it.

Sign up to Enterprise (€2,499/mo, Stripe checkout, cancel anytime). Author your RuntimeAISpec. Run the SDK against your staging traffic. Generate the audit bundle. Hand it to your DPO. Your compliance team reads the framework-mapped handoff packet and decides whether they need anything more. Most don't.