34 articles covering GDPR, EU AI Act, vendor risk, incidents, and more.
Getting started with Aegis Firma
Set up your organization, add team members, and run your first compliance assessment.
Account setup and organization settings
Configure your organization name, billing, timezone, and notification preferences.
Inviting team members and setting roles
Add colleagues, assign roles (Admin, Editor, Viewer), and restrict access to sensitive data.
What is a DPIA and when is it required?
A Data Protection Impact Assessment is mandatory under GDPR Art.35 when processing poses high risk.
Records of Processing Activities (ROPA)
How to build and maintain your Art.30 register of processing activities.
Handling data subject requests (DSARs)
Respond to Art.15–21 requests within 30 days. This guide covers the workflow from intake to response.
Standard Contractual Clauses (SCCs)
When to use SCCs for international data transfers and how to attach them to DPAs.
Data Processing Agreements (DPAs)
GDPR Art.28 requires a DPA with every processor. Generate and manage DPAs within Aegis Firma.
Understanding the EU AI Act risk tiers
Prohibited, high-risk (Annex III), limited-risk, and minimal-risk — what each tier means for your business.
Is your AI system high-risk? (Annex III)
Walk through the 8 Annex III application areas to determine if your AI system needs a conformity assessment.
Conformity assessment requirements
What documentation, testing, and registration high-risk AI systems need before EU deployment.
Technical documentation (Art.11 + Annex IV)
What goes in your technical documentation file and how Aegis Firma helps you build it.
GPAI model obligations
If you use or develop a general-purpose AI model above 10^25 FLOPs, additional obligations apply.
How to register an AI tool
Add any AI tool your team uses to your registry. Assign a risk level, owner, and approval status.
Shadow AI discovery — how it works
The browser extension monitors which AI tools your team visits. Interpret the monthly discovery report.
Running a bias test
Synthetic demographic analysis to evaluate whether an AI system treats protected groups fairly.
AI tool risk scoring methodology
How Aegis Firma calculates a risk score for each AI tool based on EU AI Act and GDPR criteria.
Vendor risk management overview
Assess and score AI vendors. Send risk questionnaires, track responses, and flag contract renewal alerts.
Sending a vendor risk questionnaire
Choose from 5 questionnaire templates or build a custom one. Track completion status per vendor.
Contract expiry alerts
Set reminders for DPA renewal, data processing review dates, and contract expiry.
Evidence collection and mapping
Upload documents, link to external sources, and map evidence to controls across frameworks.
Compliance frameworks: GDPR, ISO 42001, NIST AI RMF
How the three included frameworks map to each other and to EU AI Act requirements.
Jurisdiction tracking — what does each flag mean?
Each jurisdiction flag shows your compliance status: ✓ Met, ⚠ Partial, ✗ Not started.
Setting up webhook integrations
Send real-time compliance alerts to Slack, Teams, or any endpoint via webhook.
iCal compliance deadline export
Export compliance deadlines to Google Calendar or Outlook via iCal feed.
CSV bulk import for team members
Add team members in bulk from any HR system using a CSV file.
Plans & pricing — full feature comparison
Solo ($79/mo), Team ($199/mo), Business ($499/mo), Federal ($1,999/mo) — seats, jurisdictions, AI doc quotas, API access, and FAQ.
Billing, plans, and the price lock guarantee
Solo/Team/Business/Federal tiers, upgrading, downgrading, and how the price lock works for early subscribers.
Exporting your compliance data
Export all compliance data at any time — AI tools, evidence, assessments, and policy documents.
Cancel and data deletion policy
What happens to your data if you cancel. Data is retained for 30 days then permanently deleted.