Source register
The source register stores vendor documents with a size limit and a SHA-256 checksum. It creates a new version when the content changes and records it in the ledger under whoever fetched or uploaded it: a person, or the register on its own check. Every retrieval attempt is logged. You can upload non-public documents such as register extracts or signed contracts.
Search vendor documents
Approval answers questions using stored vendor documents and cites the passages it uses. Searches are limited to passages the person’s role permits them to read, and each search is logged. If the documents do not support an answer, Approval leaves the question unanswered.
Inventory import
Import your existing software inventory from CSV or Excel. Columns are matched by name. For unmatched columns, a model suggests mappings using only the headers, without access to cell contents. A person reviews and applies the import as a single proposal, which can be reversed. Imported products start with the status “not requested” and still need approval.
intakeproposalagent-ledger
Vendor identity
Approval compares the company name, register entry and managing directors in the vendor’s imprint with the register extract, citing both sources. The security officer assesses any differences.
Review and signatures
The security and data protection officers each review the draft of their section, edit it and sign it. The signature is recorded in the ledger with a hash of the documents and of the request, so the chain shows that what was signed is what was asked. Agents cannot sign.
proposalagent-uisigningagent-ledger
Model control
Every model call is checked and logged. Public vendor documents can be sent to an approved EU provider. Drafts that name the organisation’s internal systems can only be sent to a self-hosted model.
Evidence for the auditor
Export evidence for an individual request or the whole organisation as JSON and a cover sheet. It includes decisions, edits, citations, model calls and verification of the ledger chain, along with processing times and edit rates.
Self-hosted
Deploy one container image with your own Postgres database. The application uses two database roles and row-level security for each organisation, with retention controls and support for data-subject requests. We do not engage sub-processors to run it.
rlspostgrespiidata-subjectdata-lifecycle