Skip to content
AnyAudit

The audit-evidence layer for AI-era software.

AnyAudit turns legacy applications into audit-ready systems — repository analysis, stack-native instrumentation, and a verifiable evidence trail for every decision, data mutation and AI invocation.

Launching September 2026 · CologneAI-assisted, human-verified

The software regulatory clock

Five obligations are converging on the same engineering surface: logging, human oversight and traceable decisions. None of them are met by policy documents alone.

The software regulatory clockA timeline of five regulatory obligations converging on AI-era software between 2025 and 2027: DORA, NIS2, the EU AI Act, GoBD and the Cyber Resilience Act.The software regulatory clock17 Jan 2025DORA applies (financialentities)17 Oct 2024NIS2 transpositiondeadline (adoptionongoing)2 Aug 2026AI Act: high-risklogging & oversightContinuousGoBD: accounting-systemtraceability11 Dec 2027CRA: main obligationsapply
By the time an auditor asks, the evidence chain needs to already exist — not be reconstructed after the fact.

How it works

  1. Repository analysis — map the audit surface: decision points, data mutations, AI invocations.
  2. Stack-native instrumentation — AspectJ/Spring AOP for Java, decorators/middleware for Python and Node, interceptors for .NET, an OpenTelemetry sidecar for deep legacy.
  3. Evidence rail — trace_id carried end-to-end, a tamper-evident hash-chain, confidence gating with mandatory human review of every generated change.
  4. Evidence pack — an arc42 audit annex mapping each mechanism to the regulation it supports: AI Act Art. 12/14, DORA, NIS2, GoBD.
From repository to evidence packA four-step flow: repository analysis maps the audit surface, stack-native instrumentation captures it, an evidence rail carries a tamper-evident record end-to-end, and an evidence pack maps each mechanism to the regulation it supports.From repository to evidence packRepositoryanalysisDecision points ·mutations · AIcallsStack-nativeinstrumentationAOP · decorators ·interceptors ·OTelEvidence railtrace_id ·hash-chain · humanreviewEvidence packarc42 → AI Act ·DORA · NIS2 · GoBD

Principles

Default-deny

Nothing is assumed audit-ready. Every mechanism has to earn its place in the evidence chain.

Human review, always

Every generated change is confidence-scored and reviewed by a human before it merges.

Audit-ready, organisationally owned

We build evidence infrastructure. Legal conformity remains an organisational responsibility.

Open standards first

OpenTelemetry, arc42 and W3C — evidence that outlives any single vendor.

Standards & stewardship

  • Built on OpenTelemetry for distributed tracing and arc42 for architecture documentation.
  • Aligned with the Semantic Trust Framework for evidence composition and confidence gating.
  • This site sets no cookie except the one remembering your own language choice. No trackers, no third-party requests.

Created and stewarded by AnyLAI — the evidence infrastructure company behind AnyDPP. anylai.eu

Early access

Early access for design partners opens September 2026.

contact@anylai.eu