pAIper.one logo
Gov Legal · Legal Assistants

pAIper.one

pAIper.one is an Austrian compliance suite for the EU AI Act, combining a guided risk-classification assistant, a governance platform for documentation and continuous monitoring, and a certified training community for companies deploying AI in Europe.

Active GDPR compliant Contact Sales No public API Verified by Guidaio
Overview

What is pAIper.one?

pAIper.one is a compliance suite built around the European Union's AI Act, published by PaiperOne GmbH, a company registered in Vienna under FN 626804x at the Vienna Commercial Court and describing its software as Made in Austria. The offer is organised as three products that follow one another along a five-step path shown on the home page: a Risk Quick Check run by the AI-ACT Compliance Assistant, a deeper Risk Analysis through the Compliance Risk Analyzer, risk treatment in the AI-ACT Governance Platform, continuous monitoring via the Compliance Tracker, and ongoing learning in the AI Education Community. The AI-ACT Compliance Assistant is the entry point and, in the publisher's words, the core of the platform. It works in four stages — data input, evaluation, analysis and assessment — and leans on large language model technology to turn regulatory text into concrete recommendations. The user answers questions about an AI application and receives within minutes a risk classification and the steps that follow from it; no legal or technical expertise is assumed, and the number of applications that can be checked is not capped. The AI-ACT Governance Platform takes over once risks are identified. It covers conformity reporting, cooperation, life cycle management and documentation, with workflows, checklists, task assignment across teams, role-based access, detection of contradictions between answers, and automated assembly of the conformity report. Complementary services are sold alongside it, including AI Demand Management for inventorying the AI tools already in use and AI Risk Landscape for a portfolio view of active projects. The AI Education Community covers trainings, workshops, video content and a member network, with certified courses such as AI Compliance Officer, AI Compliance Manager and AI Compliance Auditor. Everything is delivered as an authenticated web product — app.paiper.one for the platform, ai-community.paiper.one for the community — with no mobile application and no public API. The commercial argument on the home page is the regulation's penalty regime: fines of up to 35 million euros or 7% of worldwide annual turnover. The publisher is explicit that the assistant classifies and documents but does not issue certificates.

What it does

  • Classify the risk level of an AI application under the EU AI Act through a guided questionnaire
  • Determine the legal role assumed, such as provider or deployer, and the obligations that follow from it
  • Produce and maintain the technical documentation required by the regulation
  • Assemble the text of a conformity report automatically
  • Inventory the AI tools used across the company, whether purchased or developed in-house
  • Track verified applications over time and record changes made to the system
  • Train staff through certified courses, webinars and workshops
Audience

When to use pAIper.one / When not to

A quick filter to help you decide if pAIper.one is the right fit.

When to use pAIper.one

  • EU-based companies that must classify the risk level of their AI applications and document AI Act compliance
  • Compliance officers and risk managers in regulated sectors, the platform being presented as built for the requirements of finance, healthcare and public administration
  • SMEs without a dedicated legal or AI governance team, since the assistant states that no expert knowledge is required
  • Organisations that need an inventory of the AI tools already used across departments, whether bought or developed in-house
  • Employers facing the AI literacy obligation, who want certified courses and workshops for their staff alongside the software

When not to use pAIper.one

  • Teams looking for a certificate: the publisher states that the AI Compliance Assistant does not issue certificates, only the steps required to comply
  • Engineering teams wanting technical model testing, monitoring or performance auditing, since the tools classify and document rather than inspect a system
  • Developers who need to automate compliance from a CI/CD pipeline: no public API and no developer documentation are published
  • Buyers who want to evaluate and purchase in self-service, as no pricing exists on the site and entry runs through a sales appointment
  • Organisations governed only by non-European AI rules: the scope covered is the EU AI Act and GDPR, and no US framework is documented
Get started

How to use pAIper.one

A typical end-to-end flow, from setup to results.

  1. Book the free, no-obligation consultation offered on the site: this is the real entry point, as there is no self-service sign-up
  2. Run the Risk Quick Check from the AI-ACT Compliance Assistant page by answering questions about your AI system
  3. Read the risk classification and the recommended next steps, returned a few minutes after the information is entered
  4. For a system classified as high risk, work through the concrete measures the assistant lists
  5. Move into the AI-ACT Governance Platform and structure the project along the AI life cycle using its workflows and checklists
  6. Assign tasks and deadlines across teams, and give each role access to the functions and content it needs
  7. Resolve the contradictions the tool flags between the answers given
  8. Let the platform assemble the conformity report, and open access to authorities and certification bodies when required
  9. Register new AI needs through the demand process: an employee submits a request, the responsible manager assesses it, implementation follows
  10. Sign in at app.paiper.one for the platform and ai-community.paiper.one for the community, bearing in mind that the two accesses are sold separately
Quick read

Pros & Cons

Pros

  • Narrow specialisation on the EU AI Act, where broader GRC suites usually treat the regulation as one module among many
  • Fully European legal footing: Austrian publisher based in Vienna, Austrian law and Vienna as the place of jurisdiction
  • Complete chain from first triage to continuous documentation and training, rather than a single isolated step
  • Founding team with publicly verifiable credentials, including IEEE 7000 and IEEE CertifAIEd Authorized Lead Assessor certifications, the presidency of Women in AI Austria and a seat on an Austrian federal government advisory board
  • Usable without prior legal or technical expertise, with a first risk assessment returned in minutes and no cap on the number of applications checked
  • Free and non-committal entry point through the Risk Quick Check and the consultation appointment
  • Verifiable public references and public backing: Stadt Leoben, MANZ and Stadt Wien among the customers, and development of the assistant supported by Austria Wirtschaftsservice under the AI Adoption programme

Cons

  • No public pricing whatsoever: no pricing page, no grid, not even an order of magnitude, as clause 12.1 refers all fees to the individual contract
  • No free trial and no permanent free tier, the only free item being a sales consultation, while clause 13.1 makes an annual licence or membership the default and clause 13.2 renews it automatically
  • No public API and no developer documentation, so nothing can be automated, and no third-party integration is named anywhere on the site
  • No data hosting location is committed: the privacy policy only says that EU server locations are used where possible, if offered
  • No published security certification such as ISO 27001 or SOC 2, and no sub-processor list for the SaaS product, only HubSpot and LinkedIn as tools of the website itself
  • No published position on whether customer data is used to train models, and no documented opt-out
  • Rough edges in the published documents: general terms available only in German even under the English section with the German version prevailing, a privacy policy still labelled version 10.02.2022, German blocks left inside English pages, a single generic contact address and no social account linked from the site
Pricing

Pricing & Plans

pAIper.one publishes no price. There is no pricing page anywhere on the site, an absence confirmed against the full sitemap rather than against navigation alone, and neither a free plan nor a free trial is documented; the only free item offered is a no-obligation consultation appointment. Under clause 12.1 of the general terms, fees and payment conditions are set in the individual contract, quoted in euros excluding taxes, fees and public charges, and payable within 14 days of receipt of invoice. Clause 12.2 bills on a time-and-materials basis unless otherwise agreed; clause 12.3 stages fixed-price custom development at 40% on signature, 40% on delivery and 20% on go-live; clause 12.4 makes other fixed prices and flat fees due on conclusion of the contract; clause 12.5 makes maintenance flat fees payable monthly in advance. For the SaaS platform and the community, clause 13.1 sets an annual licence or annual membership as the default, automatically renewed under clause 13.2 unless terminated. Platform access and community access are sold separately. No lowest price point can therefore be stated.

No pricing tier is published
  • the site presents no plans
  • and clause 12.1 of the general terms refers all fees to the individual contract
AI Education Community
  • an annual membership by default
  • the number of users that can be created depending on the membership taken
Community access models described in clause 3.11.1
  • a one-off payment for the Von 0 auf KI basic course granting six months of community access
  • extended by six months if the course is not completed
  • and a one-year membership included with the AI Compliance Manager and AI Compliance Auditor courses
  • followed by an annual fee to continue. These are course access models rather than software tiers
  • and no amount is attached to them
Special offers — Free, no-obligation consultation appointment (kostenfreies Beratungsgespräch), which is the only free offer published on the site · Risk Quick Check accessible from the AI-ACT Compliance Assistant page · No promotion, discount code or reduced rate for students, jobseekers, non-profits or any other group is announced; clause 3.3 adds that free services not contractually owed may be discontinued at any time without notice
Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how pAIper.one handles your data.

GDPR overview

GDPR implementation is documented in concrete terms. PaiperOne GmbH, represented by Gabriele Bolek-Fügl, is named as controller at Lindengasse 56, 1070 Vienna, with office@paiper.one also published as the data protection contact. Legal bases are cited under Article 6, and data subject rights are listed article by article: access (15), rectification (16), erasure (17), restriction (18), portability (19), objection (21) and automated decisions (22). The competent supervisory authority is named, the Österreichische Datenschutzbehörde in Vienna, alongside the Austrian DSG and the German BDSG. Security measures include TLS, plus encryption or pseudonymisation where feasible, with an explicit reference to privacy by design and by default under Article 25. The terms add data secrecy and mutual confidentiality duties (clauses 14.1 and 14.2). One caveat: the policy is labelled version 10.02.2022, two years before the company was registered.

Who owns the data?

The general terms are explicit on one side only. Under clause 7.1, all rights in the software programmes and the accompanying documentation supplied to the customer, including exploitation, adaptation and moral rights, remain exclusively with PAIPER.ONE; the customer receives nothing beyond the usage rights set out in its individual contract, and all other intellectual property, notably the source code, is expressly reserved. Clause 13.6 requires the customer to return every document supplied by the publisher when the contract ends, and clause 13.7 makes exit assistance towards the customer or a third party a separately agreed, hourly-billed service. No clause assigns ownership of the data the customer feeds into the platform: on that point the contract is silent. For personal data, the controller named in the privacy policy is PaiperOne GmbH, represented by Gabriele Bolek-Fügl.

Reuse rights

The customer's own rights of use are defined solely by its individual contract; the general terms grant no blanket permission to reuse the publisher's software or documentation beyond that scope. On the publisher's side, personal data is processed under Article 6 GDPR on the bases of consent, contract performance, legal obligation and legitimate interest, for delivering and invoicing the services, operating the website securely and efficiently, and communicating by email and social media. Marketing data reaches HubSpot in the United States under standard contractual clauses, with an Article 28 processing agreement in place, and the LinkedIn Insight Tag transfers conversion data on the same legal basis; the policy itself warns that the Court of Justice of the European Union considers that transfers to the United States currently lack an adequate level of protection. Clause 15.1 reserves the right to name the customer and the nature of the services provided as a reference towards third parties. Nothing in the published documents states whether customer data is used to train models, in either direction, and no opt-out is described.

Data retention & training

Retention summary
The stated principle is minimal retention: personal data is kept only for as long as is strictly necessary to provide the services and products, and is deleted once the reason for processing disappears. The exception is data the law requires to be retained beyond that point, notably for accounting purposes. Where a user asks for deletion or withdraws consent, the policy promises removal as quickly as possible, subject to those legal retention duties. The policy says it details a duration for each processing activity, but no figure appears in the published text, and no retention period at all is stated for the data customers upload into the platform. On the contractual side, clause 13.6 requires documents supplied by the publisher to be returned when the contract ends, clause 13.7 prices exit assistance separately, and clause 14.2 makes confidentiality survive the contract without time limit.
GDPR contact

Hosting summary

The site commits to no hosting location. The only statement available is a preference: where possible, server locations within the EU are used if this is offered, which is a conditional intention rather than an undertaking, and no country or region is named. The same policy warns that, in the view of the Court of Justice of the European Union, transfers to the United States currently lack an adequate level of protection; HubSpot and the LinkedIn Insight Tag, both used on the website, process data in the United States under standard contractual clauses, with an Article 28 processing agreement in place for HubSpot. No sub-processor list is published for the SaaS product itself, and no security certification such as ISO 27001 or SOC 2 is claimed. As a technical observation outside anything the site declares, the domain resolves to 185.166.20.113, hosted by Mittwald CM Service GmbH und Co. KG in Hamburg, Germany, which describes the WordPress showcase site and not necessarily the app.paiper.one platform. Buyers with a real data residency requirement should have it written into the individual contract.

Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting pAIper.one.

  • The risk classification is declarative: it rests on the answers the user provides, not on an inspection of the system. Treating it as a verdict rather than a first appraisal is the main misuse risk, as it replaces neither legal advice nor a formal conformity assessment, and the assistant issues no certificate
  • Budgeting is impossible without a sales appointment, since no price of any kind is published
  • The default commitment is an annual licence or membership with tacit renewal (clauses 13.1 and 13.2): check the termination terms before signing
  • The general terms are available only in German and the German version prevails in case of contradiction (clause 15.7), while the applicable law is exclusively Austrian and the venue exclusively Vienna 1010 (clauses 15.5 and 15.6)
  • Clause 15.1 lets the publisher name the customer and the nature of the services as a reference towards third parties, and clause 15.2 lets it transfer its rights and obligations to a third party without the customer's agreement and without opening a right of termination
  • Clause 7.1 keeps all rights in the software and documentation with the publisher, and the terms say nothing about who owns the data the customer uploads; no hosting location is committed either, so both points need to be settled in the individual contract
  • Clause 9 limits warranty to repair, excludes price reduction and rescission, and time-bars warranty claims after six months; the privacy policy also still shows version 10.02.2022, predating the company itself, so the current version is worth requesting
Setup

Setup & Integrations

Technical difficulty

Low on the technical side. The products are authenticated web applications with nothing to install, no API to integrate and no expert knowledge required; the structure is described as guiding the user step by step, and a first risk assessment is returned within minutes. Clause 6.2 places the necessary technical environment at the customer's own expense. The real prerequisite is organisational rather than technical: knowing which AI applications the company actually uses, involving the right people across teams, and feeding the documentation over time. Access itself runs through a commercial cycle, a consultation appointment and then an individual contract.

Deployment

Web app

Supported languages

GermanEnglish
Company

Behind pAIper.one

Company name
PaiperOne GmbH
Founded
09/01/2024
Country of origin
🇦🇹 Austria
Headquarters
Lindengasse 56, 1070 Vienna, Austria
UBO
Gabriele Bolek-Fügl
UBO country
🇦🇹 Austria
Domain registrar country
🇺🇸 United States
Legal contact

Fundraising

Public funding: development of the AI Assistant is supported by Austria Wirtschaftsservice GmbH (aws) as part of the AI Adoption funding programme, with no amount disclosed
aws also appears among the partners displayed on the home page
No private funding round is announced on the site; the share capital recorded in the Austrian commercial register is EUR 10,000
Official links

Resources

All the official URLs gathered for verification and reference.

FAQ

Frequently asked questions

Who is the AI-ACT Compliance Assistant for?
It is aimed at companies, developers and employees working with AI in the European Union. It helps them establish which risk category an AI application falls into and which obligations follow from that classification.
Can pAIper.one certify my AI application?
No. The publisher states explicitly that the AI Compliance Assistant does not issue certificates; it shows which steps must be taken to meet the legal requirements. Any formal certification remains a separate process.
Do I need technical or legal knowledge to use it?
No. The site states that no expert knowledge is required and that the intuitive structure guides the user step by step through the process. You only need to know your own AI application well enough to describe it.
How long does a first risk assessment take, and how many applications can I check?
A result is returned immediately after the necessary information has been entered, within a few minutes according to the product page. The number of applications that can be checked is not limited.
How much does pAIper.one cost?
No price is published on the site. Clause 12.1 of the general terms sets fees in the individual contract, in euros excluding taxes and public charges, payable within 14 days of invoice. Platform access and community access are sold separately.
Is there a free trial or a free plan?
Neither is documented. The only free offer on the site is a no-obligation consultation appointment. Clause 3.3 of the terms adds that free services not contractually owed may be discontinued at any time without notice.
Is there an API or a mobile application?
Neither. No API documentation is published on the site, and there is no iOS or Android application. Access is entirely through the web, at app.paiper.one for the platform and ai-community.paiper.one for the community.
Where is the data hosted?
The site commits to no location. The privacy policy only says that, where possible, server locations within the EU are used if this is offered. HubSpot and the LinkedIn Insight Tag, used on the website, process data in the United States under standard contractual clauses.
Can several departments work on the platform at the same time?
Yes. The platform is presented as optimised for collaboration between teams, with tasks and deadlines assigned to different groups, and with roles receiving access to specific functions and content.
Which languages are available?
The website is published in German and English, and the products claim multilingual options without listing them. Note that the general terms are published only in German, even under the English section, and the German version prevails in case of contradiction.
Conclusion

Should you pick pAIper.one?

pAIper.one addresses a need that has become mandatory rather than optional: any organisation deploying AI in the European Union must establish the risk class of each application, document it and keep that documentation current. The suite covers that chain end to end, with a guided Risk Quick Check for triage, a governance platform to treat risks and assemble the conformity report, a tracker to follow changes, and a training community to meet the AI literacy obligation. Two things give it credibility: a founding team whose regulatory credentials are public and verifiable, and an entirely European legal footing, with an Austrian publisher, Austrian law and Vienna as the place of jurisdiction. The weak side is transparency. No price, no grid, not even an order of magnitude is published; the default commitment is an annual licence that renews automatically; there is no free trial, no public API, no named integration, no committed hosting location and no security certification. The general terms exist only in German, even on the English pages, and the German text prevails. The decision therefore turns on how a buyer prefers to evaluate software. An organisation that accepts a sales cycle, an individually negotiated contract and an annual commitment will find a focused answer to a real regulatory obligation, backed by people who know the text and by public references in the Austrian public sector and publishing. A team that wants to test the product in self-service, budget it from a published price list or plug it into an existing toolchain will not find what it needs here. The assistant classifies and documents; it does not certify.