
pAIper.one
pAIper.one is an Austrian compliance suite for the EU AI Act, combining a guided risk-classification assistant, a governance platform for documentation and continuous monitoring, and a certified training community for companies deploying AI in Europe.
What is pAIper.one?
pAIper.one is a compliance suite built around the European Union's AI Act, published by PaiperOne GmbH, a company registered in Vienna under FN 626804x at the Vienna Commercial Court and describing its software as Made in Austria. The offer is organised as three products that follow one another along a five-step path shown on the home page: a Risk Quick Check run by the AI-ACT Compliance Assistant, a deeper Risk Analysis through the Compliance Risk Analyzer, risk treatment in the AI-ACT Governance Platform, continuous monitoring via the Compliance Tracker, and ongoing learning in the AI Education Community. The AI-ACT Compliance Assistant is the entry point and, in the publisher's words, the core of the platform. It works in four stages — data input, evaluation, analysis and assessment — and leans on large language model technology to turn regulatory text into concrete recommendations. The user answers questions about an AI application and receives within minutes a risk classification and the steps that follow from it; no legal or technical expertise is assumed, and the number of applications that can be checked is not capped. The AI-ACT Governance Platform takes over once risks are identified. It covers conformity reporting, cooperation, life cycle management and documentation, with workflows, checklists, task assignment across teams, role-based access, detection of contradictions between answers, and automated assembly of the conformity report. Complementary services are sold alongside it, including AI Demand Management for inventorying the AI tools already in use and AI Risk Landscape for a portfolio view of active projects. The AI Education Community covers trainings, workshops, video content and a member network, with certified courses such as AI Compliance Officer, AI Compliance Manager and AI Compliance Auditor. Everything is delivered as an authenticated web product — app.paiper.one for the platform, ai-community.paiper.one for the community — with no mobile application and no public API. The commercial argument on the home page is the regulation's penalty regime: fines of up to 35 million euros or 7% of worldwide annual turnover. The publisher is explicit that the assistant classifies and documents but does not issue certificates.
What it does
- Classify the risk level of an AI application under the EU AI Act through a guided questionnaire
- Determine the legal role assumed, such as provider or deployer, and the obligations that follow from it
- Produce and maintain the technical documentation required by the regulation
- Assemble the text of a conformity report automatically
- Inventory the AI tools used across the company, whether purchased or developed in-house
- Track verified applications over time and record changes made to the system
- Train staff through certified courses, webinars and workshops
When to use pAIper.one / When not to
A quick filter to help you decide if pAIper.one is the right fit.
When to use pAIper.one
- EU-based companies that must classify the risk level of their AI applications and document AI Act compliance
- Compliance officers and risk managers in regulated sectors, the platform being presented as built for the requirements of finance, healthcare and public administration
- SMEs without a dedicated legal or AI governance team, since the assistant states that no expert knowledge is required
- Organisations that need an inventory of the AI tools already used across departments, whether bought or developed in-house
- Employers facing the AI literacy obligation, who want certified courses and workshops for their staff alongside the software
When not to use pAIper.one
- Teams looking for a certificate: the publisher states that the AI Compliance Assistant does not issue certificates, only the steps required to comply
- Engineering teams wanting technical model testing, monitoring or performance auditing, since the tools classify and document rather than inspect a system
- Developers who need to automate compliance from a CI/CD pipeline: no public API and no developer documentation are published
- Buyers who want to evaluate and purchase in self-service, as no pricing exists on the site and entry runs through a sales appointment
- Organisations governed only by non-European AI rules: the scope covered is the EU AI Act and GDPR, and no US framework is documented
How to use pAIper.one
A typical end-to-end flow, from setup to results.
- Book the free, no-obligation consultation offered on the site: this is the real entry point, as there is no self-service sign-up
- Run the Risk Quick Check from the AI-ACT Compliance Assistant page by answering questions about your AI system
- Read the risk classification and the recommended next steps, returned a few minutes after the information is entered
- For a system classified as high risk, work through the concrete measures the assistant lists
- Move into the AI-ACT Governance Platform and structure the project along the AI life cycle using its workflows and checklists
- Assign tasks and deadlines across teams, and give each role access to the functions and content it needs
- Resolve the contradictions the tool flags between the answers given
- Let the platform assemble the conformity report, and open access to authorities and certification bodies when required
- Register new AI needs through the demand process: an employee submits a request, the responsible manager assesses it, implementation follows
- Sign in at app.paiper.one for the platform and ai-community.paiper.one for the community, bearing in mind that the two accesses are sold separately
Pros & Cons
Pros
- Narrow specialisation on the EU AI Act, where broader GRC suites usually treat the regulation as one module among many
- Fully European legal footing: Austrian publisher based in Vienna, Austrian law and Vienna as the place of jurisdiction
- Complete chain from first triage to continuous documentation and training, rather than a single isolated step
- Founding team with publicly verifiable credentials, including IEEE 7000 and IEEE CertifAIEd Authorized Lead Assessor certifications, the presidency of Women in AI Austria and a seat on an Austrian federal government advisory board
- Usable without prior legal or technical expertise, with a first risk assessment returned in minutes and no cap on the number of applications checked
- Free and non-committal entry point through the Risk Quick Check and the consultation appointment
- Verifiable public references and public backing: Stadt Leoben, MANZ and Stadt Wien among the customers, and development of the assistant supported by Austria Wirtschaftsservice under the AI Adoption programme
Cons
- No public pricing whatsoever: no pricing page, no grid, not even an order of magnitude, as clause 12.1 refers all fees to the individual contract
- No free trial and no permanent free tier, the only free item being a sales consultation, while clause 13.1 makes an annual licence or membership the default and clause 13.2 renews it automatically
- No public API and no developer documentation, so nothing can be automated, and no third-party integration is named anywhere on the site
- No data hosting location is committed: the privacy policy only says that EU server locations are used where possible, if offered
- No published security certification such as ISO 27001 or SOC 2, and no sub-processor list for the SaaS product, only HubSpot and LinkedIn as tools of the website itself
- No published position on whether customer data is used to train models, and no documented opt-out
- Rough edges in the published documents: general terms available only in German even under the English section with the German version prevailing, a privacy policy still labelled version 10.02.2022, German blocks left inside English pages, a single generic contact address and no social account linked from the site
Pricing & Plans
pAIper.one publishes no price. There is no pricing page anywhere on the site, an absence confirmed against the full sitemap rather than against navigation alone, and neither a free plan nor a free trial is documented; the only free item offered is a no-obligation consultation appointment. Under clause 12.1 of the general terms, fees and payment conditions are set in the individual contract, quoted in euros excluding taxes, fees and public charges, and payable within 14 days of receipt of invoice. Clause 12.2 bills on a time-and-materials basis unless otherwise agreed; clause 12.3 stages fixed-price custom development at 40% on signature, 40% on delivery and 20% on go-live; clause 12.4 makes other fixed prices and flat fees due on conclusion of the contract; clause 12.5 makes maintenance flat fees payable monthly in advance. For the SaaS platform and the community, clause 13.1 sets an annual licence or annual membership as the default, automatically renewed under clause 13.2 unless terminated. Platform access and community access are sold separately. No lowest price point can therefore be stated.
- the site presents no plans
- and clause 12.1 of the general terms refers all fees to the individual contract
- an annual licence by default under clause 13.1
- automatically renewed unless terminated
- with no amount attached
- an annual membership by default
- the number of users that can be created depending on the membership taken
- a one-off payment for the Von 0 auf KI basic course granting six months of community access
- extended by six months if the course is not completed
- and a one-year membership included with the AI Compliance Manager and AI Compliance Auditor courses
- followed by an annual fee to continue. These are course access models rather than software tiers
- and no amount is attached to them
Data, GDPR & hosting
A consolidated view of how pAIper.one handles your data.
GDPR overview
GDPR implementation is documented in concrete terms. PaiperOne GmbH, represented by Gabriele Bolek-Fügl, is named as controller at Lindengasse 56, 1070 Vienna, with office@paiper.one also published as the data protection contact. Legal bases are cited under Article 6, and data subject rights are listed article by article: access (15), rectification (16), erasure (17), restriction (18), portability (19), objection (21) and automated decisions (22). The competent supervisory authority is named, the Österreichische Datenschutzbehörde in Vienna, alongside the Austrian DSG and the German BDSG. Security measures include TLS, plus encryption or pseudonymisation where feasible, with an explicit reference to privacy by design and by default under Article 25. The terms add data secrecy and mutual confidentiality duties (clauses 14.1 and 14.2). One caveat: the policy is labelled version 10.02.2022, two years before the company was registered.
Who owns the data?
The general terms are explicit on one side only. Under clause 7.1, all rights in the software programmes and the accompanying documentation supplied to the customer, including exploitation, adaptation and moral rights, remain exclusively with PAIPER.ONE; the customer receives nothing beyond the usage rights set out in its individual contract, and all other intellectual property, notably the source code, is expressly reserved. Clause 13.6 requires the customer to return every document supplied by the publisher when the contract ends, and clause 13.7 makes exit assistance towards the customer or a third party a separately agreed, hourly-billed service. No clause assigns ownership of the data the customer feeds into the platform: on that point the contract is silent. For personal data, the controller named in the privacy policy is PaiperOne GmbH, represented by Gabriele Bolek-Fügl.
Reuse rights
The customer's own rights of use are defined solely by its individual contract; the general terms grant no blanket permission to reuse the publisher's software or documentation beyond that scope. On the publisher's side, personal data is processed under Article 6 GDPR on the bases of consent, contract performance, legal obligation and legitimate interest, for delivering and invoicing the services, operating the website securely and efficiently, and communicating by email and social media. Marketing data reaches HubSpot in the United States under standard contractual clauses, with an Article 28 processing agreement in place, and the LinkedIn Insight Tag transfers conversion data on the same legal basis; the policy itself warns that the Court of Justice of the European Union considers that transfers to the United States currently lack an adequate level of protection. Clause 15.1 reserves the right to name the customer and the nature of the services provided as a reference towards third parties. Nothing in the published documents states whether customer data is used to train models, in either direction, and no opt-out is described.
Data retention & training
Hosting summary
The site commits to no hosting location. The only statement available is a preference: where possible, server locations within the EU are used if this is offered, which is a conditional intention rather than an undertaking, and no country or region is named. The same policy warns that, in the view of the Court of Justice of the European Union, transfers to the United States currently lack an adequate level of protection; HubSpot and the LinkedIn Insight Tag, both used on the website, process data in the United States under standard contractual clauses, with an Article 28 processing agreement in place for HubSpot. No sub-processor list is published for the SaaS product itself, and no security certification such as ISO 27001 or SOC 2 is claimed. As a technical observation outside anything the site declares, the domain resolves to 185.166.20.113, hosted by Mittwald CM Service GmbH und Co. KG in Hamburg, Germany, which describes the WordPress showcase site and not necessarily the app.paiper.one platform. Buyers with a real data residency requirement should have it written into the individual contract.
Things to keep in mind
Risks and trade-offs to weigh before adopting pAIper.one.
- The risk classification is declarative: it rests on the answers the user provides, not on an inspection of the system. Treating it as a verdict rather than a first appraisal is the main misuse risk, as it replaces neither legal advice nor a formal conformity assessment, and the assistant issues no certificate
- Budgeting is impossible without a sales appointment, since no price of any kind is published
- The default commitment is an annual licence or membership with tacit renewal (clauses 13.1 and 13.2): check the termination terms before signing
- The general terms are available only in German and the German version prevails in case of contradiction (clause 15.7), while the applicable law is exclusively Austrian and the venue exclusively Vienna 1010 (clauses 15.5 and 15.6)
- Clause 15.1 lets the publisher name the customer and the nature of the services as a reference towards third parties, and clause 15.2 lets it transfer its rights and obligations to a third party without the customer's agreement and without opening a right of termination
- Clause 7.1 keeps all rights in the software and documentation with the publisher, and the terms say nothing about who owns the data the customer uploads; no hosting location is committed either, so both points need to be settled in the individual contract
- Clause 9 limits warranty to repair, excludes price reduction and rescission, and time-bars warranty claims after six months; the privacy policy also still shows version 10.02.2022, predating the company itself, so the current version is worth requesting
Setup & Integrations
Technical difficulty
Low on the technical side. The products are authenticated web applications with nothing to install, no API to integrate and no expert knowledge required; the structure is described as guiding the user step by step, and a first risk assessment is returned within minutes. Clause 6.2 places the necessary technical environment at the customer's own expense. The real prerequisite is organisational rather than technical: knowing which AI applications the company actually uses, involving the right people across teams, and feeding the documentation over time. Access itself runs through a commercial cycle, a consultation appointment and then an individual contract.
Deployment
Supported languages
Behind pAIper.one
Fundraising
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
Who is the AI-ACT Compliance Assistant for?
Can pAIper.one certify my AI application?
Do I need technical or legal knowledge to use it?
How long does a first risk assessment take, and how many applications can I check?
How much does pAIper.one cost?
Is there a free trial or a free plan?
Is there an API or a mobile application?
Where is the data hosted?
Can several departments work on the platform at the same time?
Which languages are available?
Should you pick pAIper.one?
pAIper.one addresses a need that has become mandatory rather than optional: any organisation deploying AI in the European Union must establish the risk class of each application, document it and keep that documentation current. The suite covers that chain end to end, with a guided Risk Quick Check for triage, a governance platform to treat risks and assemble the conformity report, a tracker to follow changes, and a training community to meet the AI literacy obligation. Two things give it credibility: a founding team whose regulatory credentials are public and verifiable, and an entirely European legal footing, with an Austrian publisher, Austrian law and Vienna as the place of jurisdiction. The weak side is transparency. No price, no grid, not even an order of magnitude is published; the default commitment is an annual licence that renews automatically; there is no free trial, no public API, no named integration, no committed hosting location and no security certification. The general terms exist only in German, even on the English pages, and the German text prevails. The decision therefore turns on how a buyer prefers to evaluate software. An organisation that accepts a sales cycle, an individually negotiated contract and an annual commitment will find a focused answer to a real regulatory obligation, backed by people who know the text and by public references in the Austrian public sector and publishing. A team that wants to test the product in self-service, budget it from a published price list or plug it into an existing toolchain will not find what it needs here. The assistant classifies and documents; it does not certify.
- Choosing a selection results in a full page refresh.
- Opens in a new window.