Skip to main content

Complyxx.

Compliance

Policy Generator.

A structured, searchable inventory of every AI tool in use across your organization — with owner, purpose, data category, risk tier, and full version history. The single source of truth for AI governance.

What it does

The AI Tool Registry is the operational core of Complyxx. It consolidates all AI tool submissions from across your organization into a single, structured database — replacing scattered spreadsheets, email threads, and informal lists.

Each entry in the registry is a living “AI Usage Card”: it captures not just the tool name, but the specific use case, the data categories involved, the owning department and responsible person, and the current compliance status. The register evolves as your landscape changes.

Feature details

Available from Starter
Tool limit
50 (Starter) / ∞ (Pro)
CSV export
All plans
Version history
All plans
Re-attestation
Pro +
API access
Enterprise

Included in Professional

Unlimited tools, AI-assisted risk scoring, approval workflows, and audit-ready exports — all in one plan.

Key benefits

Surfaces shadow AI automatically

Employee self-reporting is guided and structured, which surfaces tools IT and Compliance didn't know existed — including browser plugins, personal SaaS subscriptions, and AI-enhanced business software.

Every tool has a documented owner

Ownership is assigned at the use-case level, not just the tool level. When an auditor asks "who approved this?", the answer is in the record — not in someone's memory.

Stays current through re-attestation cycles

Owners are prompted to confirm their entries on a configurable schedule. Overdue entries are flagged automatically — the register reflects reality, not a historical snapshot.

Directly exportable as audit evidence

The full registry exports as a structured PDF or CSV on demand. Formatted to match what auditors and data protection authorities actually ask for.

How it works

Invite your team

Complyxx sends structured intake invitations to department leads. The coverage dashboard shows exactly who has responded and who still has open items.

Employees submit their tools

Each person fills in a guided form: tool name (with pre-populated catalog), use case, affected data, and frequency. The form validates inputs and flags incomplete entries.

Submissions consolidate into the register

All entries are deduplicated, normalized, and merged into the central registry. Compliance Officers can review, edit, assign owners, and change status for any entry.

Risk scoring feeds automatically

Each registered tool feeds directly into the Risk Classification workflow — no manual re-entry. The registry and risk register are always in sync.

Regulatory coverage

The AI Tool Registry contributes evidence and documentation for the following frameworks:

Framework Requirement covered Supported
EU AI Act (Art. 26)
Deployer documentation and oversight obligations
Full
GDPR (Art. 30)
Records of processing activities involving AI
Full
ISO 42001
AI system inventory and risk management input
Full
DORA
ICT third-party risk — AI vendor component
Partial
NIS2
Supply chain security — AI system component
Partial

Your AI compliance clock is already ticking.

Start your free 14-day trial today. No credit card. No consultant. No delay.

Baseline inventory in under 30 minutes · Hosted in EU · GDPR-compliant