An independent reviewer went through this site cold and wrote down the twelve questions she would ask before recommending us. Here they are, with our answers.
4 no · 5 partly · 3 yes
Which legal entity becomes the counterparty and invoices us?
There is one. Complipath is run as a registered sole trader in Sweden — the imprint names it, and that is who invoices you. A sole trader is not an incorporated company: the business and the person are the same legal person, which is worth knowing if your procurement rules distinguish them.
If your review needs a limited company as the counterparty, say so before you sign anything: that is a change we would have to make, not a form we can fill in.
Until 21 August 2026 this answer read: “The Design Partner cohort is not a paid contract and nothing is invoiced.” The Design Partner cohort was retired that day: the offer asked for work rather than money, and time is what a busy person has least of. Nothing else in this answer moved: there is still no registered company and still nothing to invoice you.
Corrected again on 22 August 2026, and this time the answer changed rather than its wording. Until that day this answer read: “There is not one yet. Complipath is not a registered company. Nothing is invoiced today: no plan is being billed and there is no entity to bill you.” That was false. There is a counterparty and there was one before this page said so — a registered sole trader in Sweden. The paragraph above is kept exactly as it was written on 21 August 2026, including its closing clause, because it is the record of what we told buyers and not a description of today.
Do we get a data processing agreement?
Not today, and there is no draft. A data processing agreement belongs to the entity in question one, so it follows the registration rather than the other way round.
What we can tell you now is what the privacy page tells you: which suppliers touch data, and which questions about them we have not answered. That is question three.
Which sub-processors do you use — hosting, email, models?
Named, and on the privacy page with what each one does: Vercel for hosting and the application, Supabase for the database, Resend for transactional email, Anthropic for the check's optional reading step, Calendly for booking a call.
Six things about them are written down as unread, in a register that carries the date. Where database backups are stored and for how long. Where application and platform logs are stored and for how long. From which region transactional email is sent. Where the analytics rows are kept. How long Anthropic retains what the reading step sends. How Calendly stores what you type when you book a call.
Nothing on this site says anything about those six, and the reason it says nothing is that nobody has read them yet.
Is data stored outside the EU?
Two regions are measured and both are Frankfurt: the database (eu-central-1) and the application (fra1). Measured, not taken on trust — the register says who read what, and when.
This marketing site is a different thing and stores nothing. It is static files on a content network. It runs no server code and has no database, and the one form on it posts to the application rather than to us. What it does collect is page views through Vercel Web Analytics, and where those rows are kept is one of the six unread items in question three.
Two regions prove two regions. They do not prove a sentence like “your data stays in the EU”, and we are not going to write one until the six are read.
Backups, restore, guaranteed export?
Export: yes, and today it is more than this answer said until 21 August 2026. Two families, three formats each: the whole register, and any single assessment, as CSV, JSON or PDF — plus a PDF of the Annex IV sections from the documentation workspace. Seven artefacts. Question nine lists what is in them and which of them you can actually start today.
Backups: we have not verified them. Managed Postgres takes automatic backups and nobody here has confirmed that the first one exists, checked the retention or attempted a restore. Until somebody has done all three, this page is not going to tell you backups work. It is on the same unread list as question three.
Until 21 August 2026 the first paragraph read: “Export: yes, today. A JSON file per assessment and a CSV of the whole register, in Starter, with no upgrade.” It named two artefacts of seven and presented them as the complete answer to whether export is guaranteed. Nothing in it was false; what was missing was five sixths of the thing. The verdict stays partly, and question nine now says why.
Has there been a penetration test or an external security review?
No. Neither. Nobody outside this company has tested this application.
What we do instead is smaller and worth stating exactly: the classification runs in your browser before you have an account, the application and the database sit in Frankfurt, and every build runs a fixed set of checks over what ships. None of that is a penetration test and none of it is a substitute for one.
Who has reviewed the classification logic?
No lawyer has reviewed the classification logic. Here is what we do instead: the corpus is pinned by hash, every verdict cites the provision it came from, and the engine refuses where the Act requires judgement rather than guessing.
The sources page carries the hashes. The limits page carries what the engine will and will not decide. Both are there so that a lawyer you hire can check the reasoning rather than take it.
What we do instead of being your lawyer, and what we hand yours.
How are amendments and corrections handled?
This is the part we built the company around. Every assessment records which version of the law it answered. When an amending act lands, the register can list exactly which entries cited a provision that moved — and which did not.
It has already happened once. Regulation (EU) 2026/1744 amended the 2024 text, and every guide on this site that cited a changed provision was found by searching the corpus rather than by remembering.
Can each classification be exported with version, date and traceability?
Partly, and the partly is about one thing only: everything listed below exists, and the way IN to the single-assessment export was built on 21 August 2026, so nobody outside this company has used it yet. Here is the list rather than the assurance. There are SEVEN export artefacts in two families. The whole register exports as CSV, JSON or PDF, started from the dashboard or the inventory: 15 columns — name, type, domain, status, business owner, technical owner, purpose and use case, whether it affects individuals, the repository, risk level, primary citation, whether the classification is confirmed, engine version, when it was registered and whether it is archived — with the corpus line and the engine version on every row.
A single assessment exports as CSV, JSON or PDF, started from the assessment itself: the outcome and its primary citation, the factors, every obligation with its application date, the review notes and the name of the person who confirmed it.
The documentation workspace exports the Annex IV sections as a PDF, with the derived scope statement that says what those sections cover and what they do not.
What we counted before, and against what: the figures this answer carried until 21 August 2026 — 60 JSON fields, 15 CSV columns — were read off https://app.complipath.io/api/example-run, which is the PUBLIC EXAMPLE this site renders and not a customer export. That is worth saying plainly, because it is why two pages here described two different things in the same words. The 15 columns held; the 60 fields were a count of the example route.
Corrected twice on 21 August 2026 and once on the 22nd. In the morning of the 21st this answer gained a paragraph saying the confirmer's name is now in the export. In the evening the whole answer was rewritten: there are seven export artefacts, not the two this page named, and the field counts it carried were measured against the public example endpoint rather than against an export. On the 22nd the REASON for the partly moved into the first sentence. It had been sitting four paragraphs down, inside this block — so the label said one thing and its reason lived somewhere a reader had to go looking for. A label that cannot be read out of the first two sentences of its own answer is a heading asserting what its value denies, which is the error we had just corrected in the application.
What happens to our data if the company is wound up, or never registers?
Nobody has asked us this before and it is a fair question to ask a company that does not exist yet. There is no written commitment today.
What we would propose to write is that the export in question five stays available for a stated notice period and data is deleted at the end of it. That is a proposal, not a promise, until it is in the terms.
Which features are actually in Starter today?
Twelve, and the pricing section lists every one of them, with everything not built marked as not built.
How that list is kept honest, and how it is not: it is rendered from one file rather than typed into the page, and the number in the heading comes from the render, so no two places on this site can disagree about it. That file is maintained here by hand. Nothing reads the product, so the file can fall behind what actually shipped — which is not a hypothetical, because two answers on this page went stale exactly that way and were corrected on 21 August 2026.
Until 21 August 2026 this answer said the list “is generated from the same file the product ships against, so it cannot drift from the plan it describes.” That was wrong about our own build. The file is in this site's repository and is kept by hand; nothing reads the product. The list itself was accurate and still is — what was false was the reason we gave for trusting it, which is the worse half to get wrong.
Can a lawyer override and annotate a conclusion manually?
Partly, and the two halves of the question have different answers. She can annotate: a lawyer who agrees with a classification can record a signed note against it, and the note leaves the verdict untouched. She cannot override: the conclusion is not editable by hand, and disagreeing with it still means contesting it, which still requires writing why she objects.
What sits beside that: a free-text note on each obligation row, and a mandatory reasoning field on an Article 6(3) claim.
Until 21 August 2026 this answer was no, and it said: “There is no neutral annotation: a lawyer who agrees with the verdict but wants to record a thought has nowhere to put it, because the only route open to her is to disagree.” The neutral note has since been built and deployed; we read the field on the application's own endpoint on 21 August 2026 and moved the answer the same day. The other half of the question has not moved — overriding is still no.
Two of these answers changed when they were measured rather than remembered, and both changed against us being able to say something simpler. Five answers have been corrected since the page went up, and each correction keeps the wording it replaced. If you ask us a thirteenth question we cannot answer, the answer will be that we cannot answer it.
Complipath is EU AI Act compliance software for AI-heavy software companies without a compliance team — an AI system register, deterministic risk classification, the obligations that follow, and the evidence behind every decision.
Complipath is built by Yobel Tzegai in Gothenburg, Sweden.
Complipath provides legal information, not legal advice. Every guide cites its source on EUR-Lex — Regulation (EU) 2024/1689, and Regulation (EU) 2026/1744 where that has amended it; where the law is still settling, the guide says so.
We measure page views with Vercel Web Analytics. It uses no third-party cookies. Visitors are identified by a hash derived from the incoming request, which is discarded after 24 hours, and no identifier is stored that could follow a visitor to another site. What is collected: the time of the visit, the URL, the referring page, filtered query parameters, city-level location, operating system, browser and device type.