AI Governance That Keeps You Compliant
Automate EU AI Act, BaFin MaRisk, and GDPR compliance for your AI systems. From risk classification to incident reporting — one platform built for enterprises, SMEs, and startups.
Built for regulatory compliance
Select any of them to see what it is and who it applies to.
Govern AI models from leading providers
One Platform, Full AI Governance
Purpose-built tools to classify, monitor, and document your AI systems across every regulatory framework.
EU AI Act Readiness
Risk classification wizard, conformity assessments, model cards, and compliance calendars aligned to Articles 9–15.
Learn more →Bias Detection & Explainability
Fairness dashboards, SHAP/LIME explanations, and automated alerts to catch disparate impact before it reaches production.
Learn more →Shadow AI Discovery
Scan repositories, SaaS tools, and procurement records to find every AI system in your organisation and bring it under governance.
Learn more →Evidence Collection That Leaves Your Data Where It Is
Compliance forms are mostly evidence gathering — proving a control exists, is owned, and was reviewed. Alleina’s compliance agent runs inside your own environment and does that work where the data already lives. What comes back is the answer, not the records.
Read-only by construction
The agent connects to your cloud accounts, repositories, identity provider and document stores to read posture — and only to read it. The connector interface has no write method at all, so there is nothing for a misconfiguration to expose.
Findings travel, evidence doesn’t
For each control the agent sends a signed finding: pass or fail, how it was determined, a confidence score, a timestamp, and a SHA-256 reference to the evidence. The evidence artifact itself stays on your infrastructure. The wire format rejects any field outside that list.
Posture facts, not documents
To answer “is there an approved retention policy, and when was it last reviewed?” the agent reads whether the document exists and its review date — never the body. Identifiers such as file paths, URLs and resource IDs are hashed before they leave your network.
Your models, or none at all
Where a judgement call is needed, the agent can run entirely against your own Ollama, vLLM, llama.cpp or LM Studio instance. A fail-closed policy engine refuses to send anything you have classified as confidential or restricted to a hosted model — and treats a backend it cannot identify as hosted rather than assuming the safe case.
The same split applies to fairness and explainability: metrics are computed on your side and only the resulting numbers are transmitted. Our backend does not ship Fairlearn, SHAP or LIME — it could not reconstruct your data from what it receives, because it never had the tools or the inputs.
Regulatory Coverage at a Glance
Everything you need to stay ahead of AI regulation across the EU and beyond.
6+
Regulatory Frameworks
15+
Compliance Checks
72h
Incident SLA Tracking
100%
Audit Trail Coverage
What Applies to You Depends on Your Industry
The Digital Omnibus moved the high-risk dates, not the duties that are already live. Which of the two you are looking at depends on what your systems do.
Gefördert von Deutschland und Europa
Wir sind ein junges Unternehmen und arbeiten transparent — hier steht genau, wo wir stehen.
Bundesgefördert
Ausgezeichnet mit dem EXIST-Gründungsstipendium des Bundesministeriums für Wirtschaft und Energie, kofinanziert aus dem Europäischen Sozialfonds Plus.
Ausgründung der Universität
Inkubiert an der Universität Koblenz, wo unsere Forschung zur angewandten KI-Governance begann.
Recht und Technik, gemeinsam
Gegründet von Juristinnen und Systemingenieuren — den beiden Disziplinen, die dieses Problem wirklich braucht.
Free AI Governance Tools
Start governing AI interactions today — no admin required.
Alleina Shield
Beta FreeBrowser extension for Chrome, Firefox & Edge. Monitor AI interactions, detect PII, and track costs.
Get the extension arrow_forwardAlleina Browser
BetaChromium-based desktop browser with deep network-level interception, DLP blocking, and audit logging.
Download for your OS arrow_forwardAlleina Mobile
BetaAI-governed mobile browser for Android & iOS with Chrome-like UI and built-in interception.
Get the app arrow_forwardLatest from the Blog
EU AI Act Compliance: What German Businesses Need to Know Now
EU AI Act compliance for GPAI is now enforced. See who is in scope, the three most common gaps, and…
The Ethical Lens: Unpacking the Dancing AI Baby Trend Beyond the Cuteness
The viral AI baby trend raises critical questions about data sovereignty, consent, and digital identity. As AI governance experts, we…
Shadow AI: The Hidden Risk in Your Organization
Staff-adopted AI tools create an ungoverned AI estate that no inventory captures. Why shadow AI forms, what it exposes under…
AI Bias in Financial Services: How to Detect It and What the Law Requires
Bias in credit and lending models is both a fairness problem and an Article 10 obligation. How bias enters, which…
How German Banks Are Adopting AI: Market Landscape 2026
German financial institutions are deploying AI faster than they are governing it. Where adoption is concentrated, why the governance gap…
EU AI Act Compliance Checklist for High-Risk AI Systems
A working checklist for Articles 9 to 15, 17, 72 and 73 — what each one demands, what counts as…
German AI Regulation: Navigating BaFin, DORA, NIS2 and the KI-MIG
German AI governance is four overlapping regimes, not one. How the KI-MIG, BaFin's MaRisk and BAIT, DORA and NIS2 interact…
EU AI Act for Financial Institutions: The 2027 Deadline and What to Do Now
The EU AI Act's high-risk deadline moved to 2 December 2027, but credit scoring is still Annex III and the…
Parts of the EU AI Act Are Already Applying
The Act arrives in stages, and several are already live — the remaining ones are less runway than they sound once every system has to be mapped, classified and documented. This is the register the platform works from:
- giltEU AI Act — Verbotene Praktiken und Pflichten zur KI-Kompetenz gelten seitdem
- giltEU AI Act — Pflichten für KI-Modelle mit allgemeinem Verwendungszweck gelten seitdem
- giltEU AI Act — Allgemeine Geltung, einschließlich der Transparenzpflichten nach Artikel 50
- EU AI Act — Kennzeichnung KI-generierter Inhalte nach Artikel 50 Absatz 2, für Systeme, die am 2. August 2026 bereits in Verkehr waren
- EU AI Act — Hochrisiko-Pflichten für eigenständige Systeme nach Anhang III
- EU AI Act — Hochrisiko-Pflichten für Systeme nach Anhang I, die in regulierte Produkte eingebettet sind
Termine aus den je Rechtsakt verlinkten Quellen, nach bestem Wissen gepflegt. Allgemeine Informationen, keine Rechtsberatung und kein Ersatz fĂĽr die eigene rechtliche Beobachtung.
Not ready yet? Get compliance updates instead.