Dossiers, tech docs and the regulator view
The classification dossier is a hash-linked chain of custody; the regulator view is the 'open the books' surface; the audit bundle is one sealed PDF with a SHA-256 integrity manifest.
Compliance you can't show isn't compliance. The dossier is where Veritome turns all your obligation work into documents a regulator will recognise — a classification record, the Annex IV technical documentation, a regulator-ready view, and a hash-sealed audit bundle.
Every dossier document is a working draft you prepared for your own review — the first time you export one, you acknowledge exactly that. It is not a Veritome attestation or a submission to any authority. Have qualified counsel confirm legal sufficiency before you rely on anything here.
The classification dossier (chain of custody)
The classification dossier is the running record of every decision about a system's risk tier — who decided, what they submitted, who approved it.
- Open the system, then click Dossier in the system header.
- If none exists yet, click Create dossier to open the record and start the audit trail.
- Click New entry, pick an entry type (initial classification, tier change, periodic review, …), fill the guided form and submit.
- A second person reviews each submitted entry: Approve adds it to the chain of custody; Reject returns it with a written reason. (Approving and rejecting cannot be undone.)
Each entry is hash-linked to the one before it: every approved entry stores its own fingerprint plus the previous entry's fingerprint (the first is the genesis entry). Break or alter any entry and the chain no longer verifies. The header meta grid shows Dossier opened, Total entries, Last reviewed, Next review due and Chain integrity; Verify chain → recomputes the fingerprints and either confirms the chain is intact or names the exact entry where it broke. Each entry also carries a public Verify link so a third party can confirm it without access to your account.
Article 11 + Annex IV — technical documentation
Providers of high-risk systems must keep technical documentation proving the system meets the Act's requirements; Annex IV lists what it must contain. You don't retype any of it — Veritome assembles it from the obligation work you've already done on the Technical documentation, Risk management, Data governance and Human oversight tabs. See Annex IV technical documentation, section by section.
Article 47 — Declaration of Conformity
Before a high-risk system is placed on the market, the provider draws up an EU Declaration of Conformity and affixes the CE marking (Art. 48). A DoC must be kept for 10 years. Complete the Conformity tab obligations and Veritome generates the DoC — see Declaration of Conformity, CE marking and Annex VIII registration.
The regulator view
The regulator view is the "open the books" surface — everything an authority would want, in one place. From the system header click Regulator view. It opens with the phase attestations table (each phase with its status, obligation count and completion percentage); below that, every obligation is laid out by tab with its article reference, status, checklist detail, verifier, verification date, and attached evidence. The foot of the page carries the hash-sealed compile timestamp and the public verify mark. Press Cmd/Ctrl + P to print a clean A4 PDF, or use the header link to jump to the Annex VIII export.
The audit-bundle PDF + SHA-256 integrity manifest
The audit bundle is a single merged PDF for one system: a cover sheet, every completed obligation form, the Risk Management Report, and the classification dossier — all in one file. Build it from the Dossier page or the Reports page. The last page is an integrity manifest: a table listing every source document with its position, name, byte size, and the SHA-256 hash of the exact bytes that went into the bundle — the chain-of-custody record for the package, so an auditor can confirm nothing was swapped after assembly.