Goodbye worries, hello Kodex-Compliance!

A new way
to stay
compliant.

Our all-in-one platform automates and maintains your compliance across GDPR, the EU AI Act, ISO 27001, SOC 2, NIS2, and more. Scanned, remediated, and audit-ready in days, not months.

app.kodex-compliance.com
Kodex-Compliance dashboard

Most tools check that a policy exists. We check that it works.

Two layers, not one: the document, and the practice behind it. A policy on paper is not compliance.

What gets checkedTypical toolsKodex-Compliance

Policy documents read

Your written policies, parsed

Frameworks mapped

Requirements matched to documents

Implementation verified

Whether the control operates in practice

Real-world gap analysis

What is missing, ordered by audit priority

Evidence kept current

Re-checked as your stack and the law change

The last three rows are what an auditor asks about.

How it works

Three questions, in order.

Every company must follow certain rules, from data protection to IT security. Most write a policy. Few actually live it.

01

Which rules apply to you?

Select the frameworks relevant to your business, from GDPR to ISO 27001 to the EU AI Act, and see exactly which requirements land on you.

02

Do your policies cover it?

Upload your documents. They are read and checked against each requirement, so you can see what your written policies actually address.

03

Are they implemented in practice?

The third question is the one most tools skip. Every control is checked against how your organisation really operates, not only against what the document claims.

Coverage

Every framework. One platform.

Map, remediate, and maintain compliance across the full European regulatory landscape.

EU law

GDPR

General Data Protection Regulation

EU law

EU AI Act

AI governance framework

ISO

ISO 27001

Information security management

AICPA

SOC 2

Trust service criteria

EU law

NIS2

Network & information security

EU law

DORA

Digital operational resilience

EU law

CRA

Cyber resilience act

EU law

Product Liability

Product liability evidence

Product

Evidence that holds up in an audit.

Kodex-Compliance organises your compliance evidence, tracks its status, and generates audit-ready reports, all in one place.

Scan result

GDPR Assessment

87%
Privacy PolicyVerified
Data Processing AgreementVerified
Incident Response PlanPartial
DPIA TemplateMissing
Verified by Kodex-Compliance · 1 June 2026

AI-powered gap analysis

Scan your stack and get a prioritised remediation list in minutes.

Auto-generated policies

Production-ready GDPR, SOC 2, and EU AI Act policies tailored to your org.

Continuous evidence tracking

Collect, organise, and maintain evidence with a full audit trail.

Supplier compliance

Send assessments to vendors and track their certification status.

Continuous

The law keeps moving.

A scan is a snapshot. Regulations change, your stack changes, and evidence goes stale. Every change that touches a framework you have selected is mapped to the controls it affects, and you are told what to re-check.

Tracked changes

Last reviewed 31 Aug 2026

2 August 2026

EU AI Act

Article 50 transparency obligations became applicable

Binds providers and deployers of AI systems, not only providers of general-purpose AI models. Generative systems placed on the market before this date have until 2 December 2026 to meet the Article 50(2) machine-readable marking duty.

European Commission

11 September 2026

Cyber Resilience Act

Vulnerability reporting begins under Article 14

Manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents. Early warning within 24 hours, notification within 72 hours, final report within 14 days. The rest of the Regulation applies from 11 December 2027.

European Commission

27 July 2026

EU AI Act

The Digital Omnibus on AI entered into force and moved the high-risk deadlines

Regulation (EU) 2026/1744 amends the AI Act. Annex III high-risk obligations move from 2 August 2026 to 2 December 2027, and Annex I from 2 August 2027 to 2 August 2028. National regulatory sandboxes move to 2 August 2027.

European Commission

Since 17 January 2025

DORA

Applicable to financial entities across the EU

Requires ICT risk management, incident reporting, resilience testing and third-party ICT risk management across twenty categories of financial entity. Under Article 5 the management body holds ultimate responsibility for ICT risk.

EIOPA

Standing obligation since 25 May 2018

GDPR

Records of processing under Article 30

Every controller and processor must keep records of processing. Article 30(5) exempts organisations under 250 employees, but the exemption falls away where the processing is likely to risk rights and freedoms, is not occasional, or involves special category or criminal offence data.

EDPB, SME data protection guide

Every entry is checked against its primary source before publication and carries the link. Your own feed is filtered to the frameworks you have selected. Nothing here is legal advice.

“We built Kodex-Compliance because great teams deserve to spend their time building, not buried in compliance paperwork. Kodex gives you the structure, confidence, and clarity to stay audit-ready without slowing down.”

Jeremiah Matador, CEO & Founder, Kodex-Compliance

FAQ

Common questions

Everything you need to know before getting started.

One scan = running the AI analysis on one compliance framework for one project. The scan reads your connected evidence, maps gaps, and generates your report. Scans take 15 minutes on average.

Ready to automate your compliance?

See where your compliance stands and what to fix next.