Approval helps regulated organisations assess and approve software. It collects vendor documents, extracts facts with source references and drafts security and data protection assessments. The responsible officers review, edit and sign the documents. Approval runs in your own datacentre on your Postgres database.
When a department requests software already in the catalogue, its existing approval conditions apply. For new software, Approval collects the vendor’s legal notice, processing agreement, sub-processor list, certificates and security documents. It stores each version with a checksum. Documents that are not public can be uploaded. The filing itself is a ledger entry: who filed the request, and a hash of what it asks.
A model extracts facts with quotes from the stored source documents. Quotes are checked against those documents, and missing information is left open. Drafts use only verified facts. Each officer can review their section alongside its sources before signing.
When a vendor updates a document, Approval checks whether the quoted evidence still exists. If a quote is missing, the corresponding fact is invalidated, affected approvals are marked out of date and both officers are notified. The new version, the facts it invalidated and the approvals it reopened are one ledger entry. An evidence pack for each request contains the filing, decisions, edits, citations and model calls, plus the hash-chained ledger checked against its anchor.
Diese Seite auf Deutsch