Available from November 2026

Approval helps you review and approve software

AI prepares the assessment for your officers to review and sign.

Approval helps regulated organisations assess and approve software. It collects vendor documents, extracts facts with source references and drafts security and data protection assessments. The responsible officers review, edit and sign the documents. Approval runs in your own datacentre on your Postgres database.

When a department requests software already in the catalogue, its existing approval conditions apply. For new software, Approval collects the vendor’s legal notice, processing agreement, sub-processor list, certificates and security documents. It stores each version with a checksum. Documents that are not public can be uploaded. The filing itself is a ledger entry: who filed the request, and a hash of what it asks.

A model extracts facts with quotes from the stored source documents. Quotes are checked against those documents, and missing information is left open. Drafts use only verified facts. Each officer can review their section alongside its sources before signing.

When a vendor updates a document, Approval checks whether the quoted evidence still exists. If a quote is missing, the corresponding fact is invalidated, affected approvals are marked out of date and both officers are notified. The new version, the facts it invalidated and the approvals it reopened are one ledger entry. An evidence pack for each request contains the filing, decisions, edits, citations and model calls, plus the hash-chained ledger checked against its anchor.

Diese Seite auf Deutsch

The flow

From request to approval

  1. Request

    A department requests software. Existing catalogue entries retain their approval conditions.

  2. Sources

    Vendor documents are collected in the source register, with a checksum for each version.

  3. Facts

    A model extracts facts and quotes the stored source documents. Quotes that cannot be verified are rejected.

  4. Drafts

    The model drafts the security assessment and data-protection documents using only verified facts.

  5. Signatures

    Each officer edits and signs their own part. A model cannot sign.

  6. Watch

    Document updates trigger a check of affected approvals and notify both officers when a review is needed.

Features

Approval features

Source register

The source register stores vendor documents with a size limit and a SHA-256 checksum. It creates a new version when the content changes and records it in the ledger under whoever fetched or uploaded it: a person, or the register on its own check. Every retrieval attempt is logged. You can upload non-public documents such as register extracts or signed contracts.

Search vendor documents

Approval answers questions using stored vendor documents and cites the passages it uses. Searches are limited to passages the person’s role permits them to read, and each search is logged. If the documents do not support an answer, Approval leaves the question unanswered.

Inventory import

Import your existing software inventory from CSV or Excel. Columns are matched by name. For unmatched columns, a model suggests mappings using only the headers, without access to cell contents. A person reviews and applies the import as a single proposal, which can be reversed. Imported products start with the status “not requested” and still need approval.

Vendor identity

Approval compares the company name, register entry and managing directors in the vendor’s imprint with the register extract, citing both sources. The security officer assesses any differences.

Review and signatures

The security and data protection officers each review the draft of their section, edit it and sign it. The signature is recorded in the ledger with a hash of the documents and of the request, so the chain shows that what was signed is what was asked. Agents cannot sign.

Model control

Every model call is checked and logged. Public vendor documents can be sent to an approved EU provider. Drafts that name the organisation’s internal systems can only be sent to a self-hosted model.

Evidence for the auditor

Export evidence for an individual request or the whole organisation as JSON and a cover sheet. It includes decisions, edits, citations, model calls and verification of the ledger chain, along with processing times and edit rates.

Self-hosted

Deploy one container image with your own Postgres database. The application uses two database roles and row-level security for each organisation, with retention controls and support for data-subject requests. We do not engage sub-processors to run it.

Why now

Supply-chain checks are a duty

The duty

Directive (EU) 2022/2555 (NIS2) of 14 December 2022, Article 21(2)(d), lists supply-chain security, including the security of the relationship with each supplier, among the measures an essential or important entity has to take.

Support for the assessment

Software assessments involve reading vendor documents and transferring information into forms. Approval prepares this material with source references. The responsible officers assess it and sign the result.

Runs in your infrastructure

Approval runs in your infrastructure on your Postgres database, without any sub-processor engaged by us. Every model call is checked and logged. Each decision requires a person’s signature.

Our platform

Built with 23 open-source packages

We release these packages, including their tests, under the MIT licence in November 2026. You will be able to inspect how the product works and check the implementation yourself.

  • @octabits-io/proposal
  • @octabits-io/agent-ui
  • @octabits-io/agent-ledger
  • @octabits-io/disclosure
  • @octabits-io/evidence
  • @octabits-io/intake
  • @octabits-io/knowledge
  • octaflow
  • @octabits-io/rls
  • @octabits-io/events
  • @octabits-io/activity
  • @octabits-io/queue
  • @octabits-io/storage
  • @octabits-io/backfill
  • @octabits-io/postgres
  • @octabits-io/pii
  • @octabits-io/data-subject
  • @octabits-io/data-lifecycle
  • @octabits-io/signing
  • @octabits-io/result
  • @octabits-io/server
  • @octabits-io/mail
  • @octabits-io/telemetry

See it for yourself

Approval is available from November 2026. Write to us and we will show you a demo instance with fictional organisations and talk about how your departments review software.