Evidence you can trace. Compliance you can prove.
A public check shows what buyers, partners, and regulators can already see. Every finding maps directly to the EU AI Act risk tiers.
Every public finding sits in one tier
Same labels on the scan landing page, in your report, and in product — no renaming between marketing and output.
High Risk
Systems requiring explicit human supervision and potential kill-switch remediation.
- Algorithmic behavioral tracking
- High-impact AI personalization
- Requires Human-in-the-loop review
Limited Risk
Systems requiring transparency, triggering the AI Trust Badge and Consent Mode.
- Chatbots & virtual assistants
- General AI recommendations
- Handled via Native EU Consent
Minimal Risk
Logged in the immutable ledger for complete Data Moat documentation without disruption.
- Standard analytics tools
- Basic storefront scripts
- Auto-registered in Compliance Ledger
What we can inspect from the outside
Three buckets cover the public surface without overlap — before any connector or document upload.
Third-Party Scripts
Detection of Klaviyo, Rebuy, Nosto and any other AI-powered tools running on your storefront.
Synthetic Media
Scanning your catalog to detect AI-generated descriptions and images (Art. 50(2)).
Native Web Pixels
Deep analysis of Shopify Web Pixels and their data exfiltration targets.
What public scanning cannot see
Think of it as looking through the shop window: you can see what is on display, not how the back-office runs. We are explicit about this gap.
- Supplier contracts and signed processor DPAs
- Internal employee HR algorithms
- Retention, deletion and DSAR handling evidence
- Off-platform LLM usage (e.g. ChatGPT for copy)
How each tier shows up in your report
The official PDF Certificate generated by Aveus AI reflects these exact tiers. Your results carry through — no bait and switch.
EU AI Act Assessment
Generated by Aveus AI Enterprise Platform
1. High Risk Systems (Art. 6)
Requires ActionSystems matching high-risk criteria under Annex III.
> Remediation: Human-in-the-loop review configured.
2. Limited Risk (Art. 50)
TransparentSystems subject to transparency obligations.
> Remediation: AI Trust Badge rendered via App Embed.
3. Minimal Risk (General Data)
LoggedStandard integrations requiring immutable logging.
> Remediation: Added to Data Moat Ledger.