Before
- ×Old spreadsheets
- ×Repeated answers
- ×No source evidence
- ×Unclear owner
- ×Risky stale claims
- ×Slow procurement response
Create or upload CAIQ-Lite, SIG Lite, GDPR Article 28, AI, security, or custom buyer requests. Complair drafts answers from your approved evidence library, flags gaps, assigns owners, and exports review-ready response packets.
EU-hosted workspace for B2B SaaS teams handling AI, security, GDPR, and CRA evidence.
Preparing for CRA? Explore CRA readiness →Enterprise buyers ask for the same proof in different formats: AI usage, subprocessors, GDPR Article 28 answers, security controls, model governance, incident handling, and product documentation. Most SaaS teams answer from old spreadsheets, Slack messages, policies, and half-remembered vendor docs.
Security, AI, privacy, and product answers live across spreadsheets, docs, emails, and individual teammates.
Polished answers aren't enough. Buyers increasingly ask for policies, screenshots, reviews, subprocessors, and source evidence.
Teams repeat the same questionnaire work instead of maintaining a reusable, approved answer library.
Without owners, review dates, and missing-proof flags, teams send answers that may be outdated or unsupported.
Seven steps from "a buyer just sent us a questionnaire" to "approved response packet exported."
Complair's core object is not a questionnaire. It is reusable evidence: approved answers, policies, system records, controls, subprocessors, vendor documents, and review notes mapped to every place they are used.
Built for review, not blind automation.
When evidence changes or expires, Complair shows every answer, document, system, and trust-center claim that needs review.
Approved · Last reviewed 2 May 2026 · Review due 2 Aug 2026
| Question | Status | Evidence | Owner |
|---|---|---|---|
| Do you use AI to make hiring decisions? | Needs review | 2 sources | CTO |
| Do you disclose chatbot use to users? | Approved | 3 sources | CS Lead |
| Do you maintain a vulnerability disclosure process? | Missing proof | 0 sources | Security |
| Do you use subprocessors for AI features? | Drafted | 1 source | Legal |
Generate review-ready outputs from your approved evidence library: buyer questionnaire exports, AI inventory reports, risk classification memos, DPIA drafts, Annex IV technical documentation, CRA vulnerability reports, and trust center pages. Every draft stays source-linked, owner-tracked, and approval-aware.
Approved buyer answers with evidence links, owners, confidence, and missing-proof flags.
View sampleSystems, owners, roles, risk levels, evidence count, and review status.
View sampleRisk tier, rationale, obligations, reviewer, confidence, and source evidence.
View samplePrivacy risk assessment draft with source-linked inputs and human review flags.
View sampleTechnical documentation draft generated from inventory, controls, and evidence.
View sampleIncident clock, affected product, vulnerability status, evidence, and notification readiness.
View sampleBuyer-facing PDF + XLSX + README per product: SBOM coverage, KEV posture, evidence, honest gaps.
View samplePublish approved answers, policies, controls, and evidence summaries for buyers.
View sampleSee which answers, documents, systems, controls, and CRA records rely on each source.
View sampleDaily mint / lemon / coral scores across AI Act, GDPR, NIS2, CRA, and vendors with top-3 gaps.
View sampleBeyond per-questionnaire exports, Complair surfaces a daily readiness score across AI Act, GDPR, NIS2, CRA, and vendors — and bundles a buyer-facing CRA Evidence Pack (PDF + XLSX + README) on demand.
Generate a customer-ready bundle for a product: cover PDF, SBOM table, evidence map, vulnerability posture (incl. KEV), and XLSX data — plus a README explaining gaps. Honest gap detection on stale SBOMs (≥90 days), under-investigation vulnerabilities, and missing classifications.
One tile per active module (AI Act, GDPR, NIS2, CRA, Vendors) with mint / lemon / coral bands and the top three gaps. Universal signals (answered, approved, evidence-mapped, non-stale) plus per-module signals (vendor requirements resolved, SBOM coverage, AI Act training, ROPA + DSR).
For software teams shipping products with digital elements into the EU. Product records, SBOM intake, vulnerability evidence, incident clocks, technical documentation, ENISA-style reporting drafts, and a buyer-facing CRA Evidence Pack.
Complair helps your team keep answers, owners, evidence, and review status ready as AI Act, GDPR, and CRA obligations evolve.
Certain prohibited AI practices and AI literacy obligations started applying.
General-purpose AI model obligations started phasing in.
Transparency duties continue phasing in, subject to final implementation details.
Reporting obligations for actively exploited vulnerabilities and severe incidents begin.
Target date under the AI omnibus political agreement; final adoption/status should be monitored.
Main Cyber Resilience Act obligations apply.
Target date for high-risk AI systems embedded in regulated products.
Create the request, map reusable answers, flag missing proof, and send a review-ready response packet.
Utilizamos cookies esenciales para que funcione el espacio de trabajo y cookies analíticas opcionales para entender el uso del producto. Elija lo que prefiera. Consulte nuestra política de privacidad.