Documentation · Tutorials · FAQ

Help center

Understand, deploy and operate ACF Compliance® day to day. Four article families, a short FAQ, and live support if you get stuck.

Getting started

Create an account, configure your organisation, understand the first hour on ACF.

Create an account (magic link)

Passwordless authentication, link sent to professional email, domain verification.

Detailed article coming soon

First login and onboarding

8-step guided journey: organisation, sector, jurisdictions, first inventory.

Detailed article coming soon

Configure your organisation

SIREN, headcount, sector, operating countries, time zone, default working language.

Detailed article coming soon

Understand your maturity score

0-100 score computation, per-framework weighting, prioritised action plan.

Detailed article coming soon

AI inventory

Discover all AI systems in use across your organisation (including Shadow AI) and classify them.

Connect Google Workspace

Admin OAuth, read-only Drive / Gmail / Calendar scopes, automatic inventory of AI add-ons.

Detailed article coming soon

Connect Microsoft 365

Tenant-wide OAuth, read-only Graph API, Copilot, Power Automate and plug-in detection.

Detailed article coming soon

Deploy the browser extension

Chrome / Edge / Firefox extension, deployment via Workspace or Intune, web AI usage capture.

Detailed article coming soon

Import a CSV inventory

CSV template, column mapping, deduplication, merge with automatic inventory.

Detailed article coming soon

Classify an AI system

EU AI Act step-by-step wizard (prohibited / high-risk / limited / minimal) with justification.

Detailed article coming soon

Documents & audit

Produce DPIAs, registers, AI policies and independently verifiable cryptographic audit trail.

Generate a DPIA

CNIL + AI Office template, auto-fill from inventory, collaborative validation.

Detailed article coming soon

Produce the AI Act article 49 register

High-risk systems register, signed PDF export, incremental updates.

Detailed article coming soon

Draft an internal AI policy

Adaptable template, mandatory sections, optional legal validation by partner firm.

Detailed article coming soon

Verify the Ed25519 audit chain

Public verification via hash + signature, PDF export with verification QR code.

Detailed article coming soon

Qualified eIDAS timestamping (Enterprise option)

RFC 3161 seal on a compliance document for stronger legal weight.

Detailed article coming soon

Electronic signature (Yousign)

eIDAS-qualified signature, multi-signer flow, 7-year retention, public verification.

Detailed article coming soon

Administration

Manage roles, team, billing and integrations.

Roles and permissions (RBAC)

Owner, admin, compliance_lead, member: matrix of allowed actions per role.

Detailed article coming soon

Invite and manage your team

Email invitation, 7-day expiry, suspension, ownership transfer.

Detailed article coming soon

Billing and subscription

Monthly / annual plans, Stripe-managed, PDF invoices, self-service plan changes.

Detailed article coming soon

Integrations and webhooks

HMAC-signed webhooks, available events, automatic retries, delivery log.

Detailed article coming soon

Export your data and cancel

Full ZIP export (JSON + PDF + audit chain), cancellation from billing area.

Detailed article coming soon

Popular articles

Five questions, five answers

How long until I have a usable first AI inventory?

Between 15 minutes (Google Workspace or Microsoft 365 connector with auto-inventory) and 2 hours (browser extension deployment on a few workstations + complementary CSV import).

How does ACF Compliance handle sensitive data?

EU hosting (Vercel Frankfurt + Supabase Frankfurt), AES-256-GCM at rest, TLS 1.3 in transit, per-organisation isolation via Postgres Row Level Security. Details on the /security page.

Does the cryptographic audit trail have evidentiary value?

Yes, for evidentiary purposes — admissible as written evidence (French Civil Code article 1366, AI Act article 12). Ultimate enforceability remains subject to the court's appreciation. Stronger evidentiary weight available via qualified RFC 3161 timestamping (Enterprise option via a recognised European QTSP).

Which regulatory frameworks are covered?

3 cores coded in depth today: EU AI Act, GDPR and ISO 42001. 12 transverse frameworks (DORA, NIS 2, ISO 27001/27701, LGPD, CCPA-CPRA, PIPEDA, CRA, APPI, ISO 23894/42005/5338) under construction over 2026-2027, plus 14 mapped AI jurisdictions (EU + 13 others: UK, US-Fed/CO/CA/NY, CA, BR, CH, JP, CN, KR, AU, IN) usable in the multi-jurisdiction engine. See /coverage for the full list with estimated dates.

Can I export my data and cancel easily?

Yes. Self-service full ZIP export (JSON inventory + PDF documents + signed audit chain). Monthly cancellation with no commitment from the billing area.

A question without an answer?

Our support team answers technical and compliance questions within 24 business hours (4 hours on Enterprise plans).

Help center — ACF Compliance | ACF Compliance