HodeiShield: The European TPRM platform with native NIS2, ENS, and DORA
Inventory, classify, and govern your AI systems under the EU AI Act, with security controls proportional to each system's risk tier.
Tiers and example systems
Prohibited practices: social scoring, mass biometric surveillance in public spaces.
Examples: Social scoring
Risk management, data governance, technical documentation, and human oversight.
Examples: Credit scoring, HR screening
Transparency obligations: disclosing interaction with AI.
Examples: Support chatbot, Internal generative AI
No specific AI Act obligations; voluntary best practices.
Examples: Spam filter, Content recommender
Illustrative examples; your actual classification depends on your AI system inventory.
The EU AI Act is the first comprehensive law regulating the use of artificial intelligence. It classifies systems by risk tier — unacceptable, high, limited, and minimal — and assigns growing obligations as risk rises: risk management, data governance, technical documentation, human oversight, robustness, and cybersecurity.
Most organizations already use more AI than they think: in-house models, third-party APIs, AI features embedded in the software they buy, and increasingly generative AI in the hands of their teams. Without an inventory, it is impossible to know which systems fall into the high-risk category or which obligations apply.
AI governance is not just a legal exercise: AI systems introduce their own security risks — data poisoning, model extraction, prompt injection — that require specific technical controls. Treating conformity and security as a single program is what turns a regulatory obligation into a trust advantage.
Four pillars that apply to every service and every solution, not a one-off slogan.
The same team that attacks in the pentest runs the SOC and builds the AI models. Offensive insight informs defense, and AI is applied where we already operate, not bolted on as an extra layer.
HodeiShield, our own platform, automates continuous assessment, control mapping, and evidence generation — so manual work no longer sets the pace of regulatory compliance.
Infrastructure on OVHcloud (France/EU). You speak with the people who sign off on the work, not an account manager who forwards your request to another department.
HodeiShield isn't a third-party product we resell: we build and operate it ourselves, and that's what lets us offer faster compliance and evidence that's always current.
We start by building your organization's AI system inventory — in-house models, third-party APIs, and embedded features — and classify each one by EU AI Act risk tier. For high-risk systems, we map the specific obligations of Annex III and Articles 9 to 15.
We design the governance framework: roles and responsibilities, AI acceptable-use policies, model lifecycle management, and decision records. We align the program with ISO/IEC 42001 (AI management system) and ISO 27001, so that AI governance builds on the security controls you already have.
On the technical side, we assess and harden the security of the AI systems themselves: training-data validation and lineage, defense against prompt injection and model extraction, meaningful human oversight, and monitoring of model behavior in production. The result is a living, auditable conformity file, not a document that ages.
Structured methodology for measurable outcomes.
We catalog all your AI systems (in-house, third-party, and embedded) and classify them by EU AI Act risk tier, identifying which are high-risk and which obligations apply.
We define roles, acceptable-use policies, model lifecycle management, and decision records, aligned with ISO/IEC 42001 and ISO 27001.
We harden technical security: data lineage, defense against prompt injection and model extraction, human oversight, and model monitoring in production.
Tangible outcomes for your organization.
Discovery, execution, delivery and follow-up — a clear path to continuous operation.
AI system discovery and risk-tier classification.
Policies, roles, ISO 42001, and high-risk obligations.
Data, prompt, and model defense; human oversight.
Model monitoring and an always-current conformity file.
A real scenario of how we work, not a marketing figure.
HR wants to adopt an AI-based CV screening tool. Before purchasing it, the inventory is checked: the system falls under Annex III of the AI Act (employment) and is classified as high-risk, which triggers the human-oversight checklist, technical documentation, and decision logging before it's used on a single real candidate.
No names — here's how we work differently, with verifiable facts.
| Criteria | Generalist integrator | Hodeitek |
|---|---|---|
| Focus | Dozens of business lines; cybersecurity is just one of them | 100% cybersecurity and AI |
| Point of contact | An account manager who forwards your request to another department | Direct contact with the founders |
| Regulatory compliance | One-off reports per regulation, manual evidence management | HodeiShield automates evidence and cross-framework NIS2/ENS/DORA mapping |
| Product | Resells third-party licenses | Builds and operates HodeiShield, its own platform |
Talk to our team to evaluate how this solution can protect your organization.
Response within 24h
Cut repetitive SOC work with automation and AI: alert triage, context enrichment, and orchestrated response that lower MTTR (mean time to respond) without removing human control.
Comprehensive guidance to achieve and maintain compliance with the European NIS2 cybersecurity directive.