Layout, contracts, and data shapes are real. The data shown is illustrative. Real customer data flows live with our first design partner.
EU AI Act · Art. 43 · Notified Body export
Auditor Portal
A frozen, read-only manifest of vault state — the artifact a Notified Body or external auditor receives when they ask for the current snapshot. Every row is a dated cross-link into the live vault; the JSON bundle below is the same content packaged as a single signed document.
Snapshot metadata
As of
2026-05-04
Sections
5
Total entries
20
Table of contents
Model registry
Every registered model with current Annex IV revision and status.
| id | label | dated | note |
|---|---|---|---|
| mdl-foundation-A | Foundation Model A | 2026-04-22 | active · Annex IV rev 7 |
| mdl-vertical-B | Vertical Model B | 2026-04-29 | active · Annex IV rev 3 |
| mdl-fine-tune-C | Fine-Tune Model C | 2026-05-01 | active · Annex IV rev 2 |
| mdl-personalization-v7 | Personalization Assistant v7 | 2026-04-15 | active · Annex IV rev 11 |
| mdl-recommender-v3 | Recommender v3 | 2026-03-30 | deprecated · pending withdrawal |
| mdl-text-classifier-v1 | Text Classifier v1 | 2026-02-12 | withdrawn |
Annex IV pack revisions
Latest published Annex IV pack per model. Each pack carries the ledger entries used to compute its sections.
| id | label | dated | note |
|---|---|---|---|
| annex-iv-mdl-foundation-A-r7 | Foundation Model A — rev 7 | 2026-04-22 | — |
| annex-iv-mdl-vertical-B-r3 | Vertical Model B — rev 3 | 2026-04-29 | — |
| annex-iv-mdl-fine-tune-C-r2 | Fine-Tune Model C — rev 2 | 2026-05-01 | — |
DSAR chain-of-custody
Every Article-15 trace request resolved against the ledger.
| id | label | dated | note |
|---|---|---|---|
| dsar-4192813 | Subject 4192813 | 2026-04-22 | trace complete · 1 residual flagged |
| dsar-7728034 | Subject 7728034 | 2026-04-26 | trace complete · 0 residuals |
| dsar-9981255 | Subject 9981255 | 2026-04-30 | trace complete · pending re-run |
Erasure-completeness requests
Every Article-17 erasure request and the proof-or-counterexample certificate. Verifier currently stubbed (P7 substrate gap).
| id | label | dated | note |
|---|---|---|---|
| req-2026-001 | req-2026-001 — subject 4192813 · personalization-v7 | 2026-04-23 | verifier stub · awaiting P7 substrate |
| req-2026-002 | req-2026-002 — subject 7728034 · recommender-v3 | 2026-04-27 | verifier stub |
| req-2026-003 | req-2026-003 — subject 9981255 · text-classifier-v1 | 2026-05-01 | verifier stub |
| req-2026-004 | req-2026-004 — subject 4192813 · fine-tune-C | 2026-05-03 | verifier stub |
Incident replay ledger
Public-record incidents replayed against the vault. Each entry names the contract that would have refuted at compile time.
| id | label | dated | note |
|---|---|---|---|
| inc-air-canada | Air Canada chatbot misinformation (TT8) | 2022-11 — at chatbot deploy time, before Mr. Moffatt's first interaction | cross: /ai/incidents/air-canada-chatbot-2024 |
| inc-nyt-openai | New York Times v. OpenAI & Microsoft (TT6+T8) | 2022 — at training-pipeline-compile time, before GPT-4's December 2022 ingestion run | cross: /ai/incidents/nyt-v-openai-2023 |
| inc-italian-dpa-replika | Replika — Italian DPA enforcement (TT6+T7) | 2022-09 — at fine-tune corpus assembly time | cross: /ai/incidents/replika-italian-dpa-2023 |
| inc-samsung-leak | Samsung internal-data leak via ChatGPT (TT6) | 2023-03 — at DLP-rule-deploy time, when ChatGPT use was first permitted | cross: /ai/incidents/samsung-chatgpt-leak-2023 |
Signed by
-----BEGIN COSIGN SIGNATURE (ILLUSTRATIVE)----- issuer: veric.dev / compliance-vault algorithm: fake-sigstore-cosign-stub certificate: MOCK fixture — replace at first DP signing digest: sha256:0000…0000 signed_at: 2026-05-04T00:00:00Z rekor_log_idx: -1 -----END COSIGN SIGNATURE (ILLUSTRATIVE)-----
The signature block above is illustrative — a visual stand-in for the cosign / Sigstore signature a production export will carry. No private key is involved; nothing here is verifiable. Real signing lands when the first design partner signs (BE7 in the implementation plan).
Cross-references
- · /vault/registry — model registry source
- · /vault/incident — incident replay ledger
- · /vault/dsar — DSAR chain-of-custody
- · /vault/erasure — erasure-completeness certificates