We move compliance from declarative to executable — provable and replayable
Declarative compliance — the kind that lives in documents nobody recomputes — no longer protects. Our tools, built by NELSE, our technology partner, replace it with compliance computed from your facts, verifiable by a third party, and reconstructible over time.
The declarative model can no longer work
All market compliance rests on the same gesture: declaring. The only recent change is the speed at which declarations are made.
01
Classic declarative
Registers filled by hand, policies written once, spreadsheets. Everything is true the day it is written — then nobody recomputes it. Facing an inspection, every document must be defended from memory.
02
Declarative at machine speed
The market’s recent answer: have generative AI declare for you — “generated” registers, analyses “suggested” by a model that reads doctrine (RAG). Faster, in greater volume — but the same nature: probabilistic, unverifiable, and accompanied by a clause that leaves you the risk.
03
What the times demand
Tighter inspections, the AI Act, health data: compliance must now be demonstrated. Three properties become essential: executable (computed from facts), provable (verifiable by a third party), replayable (reconstructible over time).
What you gain
A file ready to hand over, at any time. Inspection, audit, due diligence: the full file exports in one gesture — and whoever receives it can verify its integrity themselves.
Documents your board understands. Plain-language reports generated from your actual data — what is done, what is missing, who must act.
The certainty that nothing moves behind your back. What is validated cannot be quietly modified; everything is historised, everything can be reconstructed.
The product, results first
Three real deliverables, generated by our tools on the sample dataset — exactly what an engagement produces.


Documents generated on sample data, shown as produced by the tool.

A rules engine, not an AI that guesses
Most compliance software stores what you declare — and, increasingly, has it drafted by a generative AI while disclaiming any responsibility for the output. Our approach is the opposite: the law is encoded as rules, and the computation does the work.
The legal regime, derived — not guessed
You describe the processing through closed facts (sensitive data? vulnerable people? large scale?…). The engine derives the regime — standard, DPIA required, CNIL prior consultation, to be regularised — with the EDPB criteria counted one by one.
Multi-regulatory, in layers
GDPR, CNIL frameworks (health reference methodologies), HDS hosting, AI Act, clinical research (RIPH, MR-001 to 008): rules compose — a health-data processing automatically triggers the layers that apply to it.
Replayable, rule by rule
Every qualification displays the activated rules with their legal ground (article, framework, deliberation): same facts, same result — demonstrable to you, and to an auditor.
A qualification that does not age
Elsewhere, qualification is a stamp applied once, true on paper forever. Here it follows the record's facts: a fact changes, the regime is reviewed — while the preserved history lets you reconstruct the past without ever rewriting it.
Clinical research, qualified too
RIPH categories 1 to 3, reference methodologies MR-001 to MR-008, CPP and ANSM tracks: the engine also qualifies research projects — ground that general-purpose compliance software simply does not cover.
Legal logic lives in the engine — never in the screen
This is the NELSE architecture: the interface displays, the engine computes. No rule is buried in a screen, a form or a spreadsheet — which is what makes the whole testable, versionable, replayable.
What the tool produces for you
Every engagement of the firm relies on these building blocks. They show in your deliverables — and can be demonstrated live in a meeting, on sample data.
Verifiable audit file
Full register (versions included), DPIAs, action plan, breaches, qualifications — delivered in a format designed so a third party can check its integrity without an account and without trusting us.
Reports generated from your data
Periodic progress report with computed vigilance points (DPIAs not opened, records not validated, ongoing breaches) — not a hand-filled template: a document produced from your actual file and reviewed by your DPO.
Public transparency page
“What we do with your data”, in plain language, generated only from records validated by the DPO — never from declarations. Your patients and partners see a compliance that actually exists.
Consolidated multi-site roll-up
CPTS federations, hospital groups, care-home groups: each site keeps its register, governance receives a consolidated view — sums and simple averages of values explainable site by site, never an opaque ranking.
Breaches: the clock is visible
Plain-language declaration by the facility, time-stamped chronology, visible 72-hour countdown (Art. 33), and no closure without a reasoned notification decision.
AI-systems register (AI Act)
Inventory of AI systems, cautious qualification (“to be assessed”, never an automatic classification), staff-training follow-up (Art. 4) — the building block tomorrow's inspections will ask for.
Safeguards that cannot be switched off
In many tools, rigour is an option to configure. Here it is wired in:
- Nothing modified can be presented as validated: an edited record must go back to the DPO.
- A DPIA opinion does not survive an edited analysis: it must be issued again.
- A breach cannot be closed without a reasoned notification decision.
- History can be consulted, nothing is overwritten.
Three deliberate choices
- No generative AI in decisions. No “AI-generated” records, no probabilistic screening: what engages your liability is computed by sourced rules, then decided by your DPO.
- No opaque score. No “% compliant” out of a secret weighting: every displayed indicator breaks down into named points, verifiable one by one.
- No promise of guaranteed compliance. Determinism guarantees the reproducibility of the computation, not legal infallibility: rules are sourced, and the decision remains your DPO’s act.
Every compliance tool rests on choices. Here are the two schools.
Naming no one: these approaches dominate the market, and each has a consequence for you. We systematically made the opposite choice — by design, not by delay.
The market’s choice
A generative AI drafts your register — with a disclaimer waiving any responsibility for the output.
Ours
What engages your liability is not drafted by a probabilistic model: the engine computes from your facts, the rules are displayed, and your DPO decides. The risk is never transferred to you by a clause.
The market’s choice
“Proof”: documents attached inside their platform, viewable if you have an account — and if you trust the tool that produced them.
Ours
Proof that can only be verified at its issuer's is an attachment. Ours leaves the platform: your auditor checks its integrity without an account with us, and without taking our word.
The market’s choice
A language model “grounded in official doctrine”: it reads the texts before answering — and remains probabilistic, even sovereign, even hosted in Europe.
Ours
Citing sources does not make a computation reproducible. Our rules do not invoke the texts: they are derived from them, written, versioned — same facts, same result, on every replay.
The market’s choice
A “compliance score” in percent, from a weighting no one can detail — reassuring as long as nobody asks how it is computed.
Ours
No figure without a breakdown: every indicator reads as named points, verifiable one by one. A documentation progress is not a compliance verdict, and we say so.
The market’s choice
Total flexibility: steps, workflows, fields and rigour rules to configure yourself — the design of compliance is transferred to the client.
Ours
The healthcare-DPO craft is already modelled: nothing to configure, and the safeguards (lapsing validation, reasoned closure) cannot be switched off — not even by us.
The market’s choice
Libraries of hundreds of templates to copy: “80% of your register in minutes” — by imitating a processing that is not yours.
Ours
A copied template describes the facility next door. Here, the regime is computed from your answers, on your situation — a few minutes slower, and it is your register.
See it live
An engine that computes can be demonstrated: in a meeting, on sample data, we qualify a processing activity in front of you — regime, rules, grounds. Ten minutes are enough to understand the difference.
Transformez vos obligations en opportunités.
Un premier échange gratuit et sans engagement pour faire le point sur votre conformité et identifier vos priorités.
Response within 24 business hours · No commitment
