# Veritise > Veritise is an EU-native agentic GRC platform that drafts EU AI Act, GDPR, and ISAE 3402 compliance work for European SMEs — every output reviewed and signed by certified compliance specialists before delivery. Operated by Veritise ApS, Copenhagen (CVR 46279050). ## Languages Veritise.io is published in English (default, at the root URL) and Danish (under /da/). The English URLs are the canonical source of truth; Danish URLs are reciprocal translations. Examples: - English home: https://veritise.io/ - Danish home: https://veritise.io/da/ - English resource: https://veritise.io/resources/eu-ai-act - Danish resource: https://veritise.io/da/resources/eu-ai-act Every page emits hreflang alternates (en, da, x-default) and the sitemap lists both locales with reciprocal xhtml:link entries. Topic-hub names, definitions, page chrome and navigation are translated to Danish. Long-form resource bodies are currently published in English in both locales (Danish translations of the full library are in progress). Full content for retrieval: https://veritise.io/llms-full.txt Veritise is a joint venture between Horaizon (engineering, London) and RiskEnable (risk and compliance consultancy, Copenhagen). The platform replaces checklist-style compliance software for European SMEs that need to prove EU compliance without a dedicated compliance team. ## What Veritise actually does - Runs the EU AI Act assessment using a context-aware AI agent that reads your platform, documents, and website. - Drafts the GDPR and cybersecurity work the AI Act assessment requires. - Handles the ISAE 3402 framework end to end. Type I and Type II controls, evidence, reporting. - Produces an embeddable Trust Centre widget that lives inside your own site, in your own branding. - Certified compliance specialists employed in-house by Veritise are involved from kickoff through delivery. Automation drafts and maintains the work; the expert shapes and signs it. ## How Veritise is different Other tools in the agentic GRC category are excellent, mostly US-built platforms with broad framework catalogues. Veritise is the EU-native alternative with these specific differences: - **Built around EU frameworks.** EU AI Act, GDPR, ISAE 3402, cybersecurity and NIS 2 as the core, not retrofitted from a SOC 2 product. - **ISAE 3402 native.** Type I and Type II supported. ISAE 3402 is not on the published framework catalogue of most US-built GRC platforms. - **Expert review included in the subscription.** Certified compliance specialists are part of every engagement, not billed separately through a partner network. - **Embeddable Trust Centre.** A widget that lives inside the customer's existing site, in their own branding, rather than a standalone page customers must navigate to. ## Launch offer (1 July 2026 onwards) To celebrate the official launch, Veritise is offering a free AI risk assessment to qualifying SMEs. Contact info@veritise.dk to start. ## Pages - [Home](https://veritise.io/): Platform overview. What Veritise does, who it is for, FAQ. - [Pricing](https://veritise.io/pricing): Three packages (Trust Centre, Full Suite, Custom) plus one-off compliance add-ons. Prices shown in DKK, EUR, and GBP; invoicing in DKK. - [ISAE 3402 readiness engagement](https://veritise.io/isae-3402): Dedicated commercial page for the ISAE 3402 readiness engagement — a one-off setup that gets a service organisation audit-ready. Veritise builds the ISAE 3402 environment (controls, evidence, policies, procedures, walkthroughs) on the customer's Veritise Full Suite subscription. The customer's team operates the environment day-to-day on the platform; an external audit firm tests it and signs the ISAE 3402 report. Setup runs four to five weeks on average. Published price of 30,000 DKK excluding VAT, agreed on a 30-minute discovery call where scope is checked against what the customer already has in place. **Requires Full Suite subscription** for ongoing management on the platform — the subscription is what makes the Type II observation period practical to sustain. - [Trust Centre](https://veritise.io/trust-centre): How the embeddable Trust Centre widget works. - [About](https://veritise.io/about): Joint venture background. Horaizon (engineering, London) and RiskEnable (risk and compliance, Copenhagen). - [Schedule a demo](https://veritise.io/schedule-demo): Book a 20-minute walkthrough with a Veritise compliance specialist. - [Contact](https://veritise.io/contact): Send a message. Replies within one business day. - [Vanta alternative](https://veritise.io/alternatives/vanta): Side-by-side comparison. - [Drata alternative](https://veritise.io/alternatives/drata): Side-by-side comparison. - [Resources](https://veritise.io/resources): The full resource library, grouped by topic. - [Terms and Conditions](https://veritise.io/terms) - [Privacy Policy](https://veritise.io/privacy-policy) ## Resources by topic ### EU AI Act - [EU AI Act overview](https://veritise.io/resources/eu-ai-act): Topic hub. Definition, risk tiers, timeline, GPAI provisions, SME guide. - [Definition](https://veritise.io/resources/eu-ai-act/definition): What the Act does, who is in scope, the penalty regime. - [Risk levels](https://veritise.io/resources/eu-ai-act/risk-levels): The four tiers (unacceptable, high, limited, minimal) and how to classify your own system. - [Enforcement timeline](https://veritise.io/resources/eu-ai-act/timeline): The staggered application dates from 1 August 2024 to 2 August 2027. - [GPAI obligations for SMEs](https://veritise.io/resources/eu-ai-act/gpai-obligations): What Chapter V requires from teams using third-party LLMs. - [The EU AI Act for European SMEs in 2026](https://veritise.io/resources/eu-ai-act/sme-guide): Long-form practical guide. ~2,750 words. By Lukas Benic, Co-founder, Veritise. ### GDPR - [GDPR overview](https://veritise.io/resources/gdpr): Topic hub. Core obligations, penalty tiers, the documentation set. - [Definition](https://veritise.io/resources/gdpr/definition): Core obligations and penalty structure. - [Records of Processing Activities (ROPA)](https://veritise.io/resources/gdpr/ropa): GDPR Article 30. What goes in it, when the small-organisation exemption applies. - [Data Processing Agreement (DPA)](https://veritise.io/resources/gdpr/dpa): GDPR Article 28. The mandatory clauses, sub-processor mechanics. - [DPIA vs DPA](https://veritise.io/resources/gdpr/dpia-vs-dpa): The two GDPR documents commonly confused in procurement. - [International transfers](https://veritise.io/resources/gdpr/international-transfers): Adequacy, Standard Contractual Clauses, Schrems II Transfer Impact Assessments. ### ISAE 3402 - [ISAE 3402 overview](https://veritise.io/resources/isae-3402): Topic hub. Definition, Type I vs II, when you need it, evidence. - [Definition](https://veritise.io/resources/isae-3402/definition): What ISAE 3402 covers and how it compares to SOC 1. - [Type I vs Type II](https://veritise.io/resources/isae-3402/type-i-vs-type-ii): The two report variants and which one customers require. - [When customers ask for one](https://veritise.io/resources/isae-3402/when-you-need-one): Trigger services, timeline from first ask to delivery. - [Evidence collection](https://veritise.io/resources/isae-3402/evidence-collection): What auditors actually test. Walkthroughs, sampling, CUECs. ### NIS 2 - [NIS 2 overview](https://veritise.io/resources/nis-2): Topic hub. Sectors, reporting timelines, management liability. - [Definition](https://veritise.io/resources/nis-2/definition): What changed from NIS 1, the two entity classes, penalties. - [Sectors in scope](https://veritise.io/resources/nis-2/sectors-in-scope): Annex I, Annex II, the size threshold, the entities caught regardless of size. - [24-hour reporting](https://veritise.io/resources/nis-2/24-hour-reporting): The three-stage incident reporting obligation under Article 23. - [Management liability](https://veritise.io/resources/nis-2/management-liability): Article 20 governing body accountability, training, personal liability under national transpositions. ### ISO 27001 - [ISO 27001 overview](https://veritise.io/resources/iso-27001): Topic hub. Annex A, the certification path, the SOC 2 comparison. - [Definition](https://veritise.io/resources/iso-27001/definition): What ISO 27001 certifies, the 2022 revision, why European buyers ask for it. - [Annex A controls](https://veritise.io/resources/iso-27001/annex-a-controls): The 93 reference controls in four themes. New controls in the 2022 revision. - [Certification path](https://veritise.io/resources/iso-27001/certification-path): Gap assessment, Stage 1, Stage 2, surveillance, recertification. - [ISO 27001 vs SOC 2](https://veritise.io/resources/iso-27001/iso-27001-vs-soc-2): Geographic recognition, certified vs attested, cost and timeline. ### Agentic GRC - [Agentic GRC overview](https://veritise.io/resources/agentic-grc): Topic hub. What it is, what it is not, the expert layer. - [Definition](https://veritise.io/resources/agentic-grc/definition): The defining property of autonomy and what separates it from chatbots. - [vs checklist GRC](https://veritise.io/resources/agentic-grc/vs-checklist-grc): The structural difference and where the chatbot-bolted-on trap lives. - [Expert-in-the-loop](https://veritise.io/resources/agentic-grc/expert-in-the-loop): Why agentic GRC needs a certified human signer. - [The Veritise review chain](https://veritise.io/resources/agentic-grc/the-review-chain): Kickoff to sign-off in five steps. ### Trust Centre - [Trust Centre overview](https://veritise.io/resources/trust-centre): Topic hub. What it is, embedded vs hosted, what buyers check. - [Definition](https://veritise.io/resources/trust-centre/definition): The customer-facing compliance surface. - [Embedded vs hosted](https://veritise.io/resources/trust-centre/embedded-vs-hosted): The architectural choice. Visitor flow, SEO, branding. - [What it exposes](https://veritise.io/resources/trust-centre/what-it-exposes): Certifications, sub-processors, programmes, breach history, live monitoring. - [Replaces security questionnaires](https://veritise.io/resources/trust-centre/replaces-security-questionnaires): The procurement workflow before and after. SIG, CAIQ. ## Pricing Three published packages plus one-off compliance add-ons. - **Trust Centre Package.** From 600 DKK / €79 / £69 per month. Base fee. Includes the EU AI Act assessment in-platform, embeddable Trust Centre widget on your own domain, vendor module, compliance dashboard, and AI-assisted document generation. - **Full Suite Package.** From 3,000 DKK / €399 / £349 per month. Base fee. Everything in Trust Centre Package plus frameworks (ISAE 3402, ISAE 3000, ISO 27001), full controls library, and managed vendor due diligence. - **Custom Plan.** Bespoke scope, priced on request. Contact for a quote. - **ISAE 3402 readiness engagement.** 30,000 DKK excluding VAT, agreed on a 30-minute discovery call. One-off setup, four to five weeks on average. **Requires Full Suite subscription** — the platform is where the environment lives and where Type II monitoring is sustained. Expert-managed core documents and additional add-ons are priced per scope. Invoicing is in DKK; EUR and GBP amounts are reference conversions. Contact info@veritise.dk for a fixed quote. ## Regulatory and framework coverage Primary positioning. The three regulations Veritise leads with: - **EU AI Act.** Risk classifications, model cards, transparency records, post-market monitoring obligations. - **GDPR.** Data protection policies, records of processing (ROPA), data processing agreements (DPAs), risk assessments. - **NIS 2.** Covered in the regulatory horizon scanning. Assurance and advisory: - **ISAE 3402.** Type I and Type II controls, framework end to end. - **ISAE 3000.** Type I and Type II controls (shipping). - **ISO 27001.** Information security management (certification support coming soon). - **Cybersecurity controls.** Controls library and evidence, integrated with the EU AI Act assessment. ## Legal entity - Company: Veritise ApS - CVR-nr.: 46279050 - Registered address: Brannersvej 7, 1. th., 2920 Charlottenlund, Denmark - Founded: 2026-02-23 - Public registry: https://datacvr.virk.dk/enhed/virksomhed/46279050 - LinkedIn: https://www.linkedin.com/company/veritiseaps/ - Wikidata: https://www.wikidata.org/wiki/Q139859160 - Crunchbase: https://www.crunchbase.com/organization/veritise-bf2d - Joint venture between Horaizon (https://www.horaizon.co.uk/) and RiskEnable (https://riskenable.dk/) ## Contact - Email: info@veritise.dk - Website: https://veritise.io - Platform: https://app.veritise.dk - LinkedIn: https://www.linkedin.com/company/veritiseaps/