Veille maps every obligation across Law 25, PIPEDA, BC PIPA, AB PIPA, PHIPA, AMF Québec, OSFI E-23, OSFI B-13, CSA/CIRO, the EU AI Act, the TBS Directive, Bill 149, Bill 194, the ISED Code and Canadian human rights law to each of your AI systems, then builds the evidence automatically, in both official languages, and keeps it current as regulations change.
How it works
Most compliance tools ask you to declare what you have and trust you. Veille finds what you haven't declared, monitors every obligation continuously, and produces the evidence your auditors will actually accept.
Veille reads three independent sources: your software spend, your network logs, and the OAuth grants your people approved. Read-only access, nothing extracted, nothing modified. It then reconciles what was found against what you declared, and reports your own coverage gap.
The Veille agent watches official regulatory sources, from the Gazette officielle du Québec and the Canada Gazette to OSFI and the EU AI Office, and maps every update to your registered systems within 4 hours. No manual review cycle.
Every compliance action is preserved in a WORM-locked evidence vault with SHA-256 hash chains. When your auditor asks for proof of compliance with Law 25 Art. 12.1, you export a bilingual dossier in minutes, not months of reconstruction.
Coverage
Veille doesn't give you a checklist of principles. It encodes every obligation, 146 across fifteen frameworks, at the article level, maps them to the specific systems in your inventory, and flags gaps the moment they appear.
When a regulator asks for proof of compliance with OSFI E-23 Section 5.2, you don't search for the relevant document. You export the dossier.
At the centre sits the AMF's guideline on the use of AI for Québec financial institutions, anchored verbatim to the official AMF texts. It takes effect May 1, 2027, so its obligations are marked effective on that date and start counting toward compliance then. For a caisse, a Québec insurer, or an OCRI dealer, it is the framework that matters most, and it is fully encoded in the library.
View full coverage →Law 25, OSFI E-23, and EU AI Act changes are detected and mapped within 4 hours. Tier 2 frameworks (Bill 149, Bill 194, TBS Directive) are monitored continuously with next-sprint resolution.
Architecture
Veille is not a rule engine with a database of checkboxes. It reads regulatory text, reasons about how changes affect each system in your inventory, and drafts the documents that address each gap, bilingual, citing the exact article.
Monitors regulatory sources on a continuous cadence. Detects amendments, new guidance, and enforcement decisions. Maps changes to affected obligations within 4 hours.
Reads spend exports, network logs and OAuth grants for AI not in the registered inventory. Reconciles found against declared, records one system per vendor even when several channels confirm it, and logs each discovery to the audit trail.
Evaluates each registered system against its obligations, article by article. Drafts missing documents, transparency notices, PIAs, model cards, and routes them for human review before scoring.
draft_pending_review and does not improve your compliance score until a designated reviewer opens it and clicks Validate. The score reflects what you've actually confirmed, not what the agent produced.Security
Every piece of data Veille stores, your system inventory, compliance gaps, evidence documents, stays in Canada. LLM inference runs on Anthropic's API (US) today for reasoning over compliance metadata and is migrating to AWS Bedrock in Canada for full Canadian residency; your vault documents are never transmitted. Your AI inventory is not a training dataset.
We apply the same compliance standards to ourselves that we help you meet: Veille's own platform is subject to Law 25 and Bill 194 monitoring, and our infrastructure is on the SOC 2 Type II roadmap for Q4 2026.
Integrations
Veille connects to where your AI systems actually live, not where they were supposed to be documented. Every connector is read-only: metadata scanning only, no data extraction, no write access.
Scans repositories for model deployment configs, ML workflow files, and AI service dependencies not in the declared registry.
BetaDetects active inference endpoints, training jobs, and deployed model versions across your AWS accounts.
BetaReads MLflow experiment and model registry metadata. Surfaces models in production that aren't in the compliance inventory.
BetaDiscovery connector for Azure Machine Learning workspaces and deployed endpoints. Planned for Q4 2026.
Planned Q4See it live
A 30-minute call is enough to map your current exposure: which systems you have, which obligations apply, and where the gaps are most likely to be. No deck. No sales process.