veille Platform Overview
The platform

One platform. Fifteen frameworks. Continuous proof.

Veille maps every obligation across Law 25, PIPEDA, BC PIPA, AB PIPA, PHIPA, AMF Québec, OSFI E-23, OSFI B-13, CSA/CIRO, the EU AI Act, the TBS Directive, Bill 149, Bill 194, the ISED Code and Canadian human rights law to each of your AI systems, then builds the evidence automatically, in both official languages, and keeps it current as regulations change.

Obligations encoded146 across 15 frameworks
Regulatory detection<4 hours

How it works

Three things Veille does that nothing else does together.

Most compliance tools ask you to declare what you have and trust you. Veille finds what you haven't declared, monitors every obligation continuously, and produces the evidence your auditors will actually accept.

01, Discover
Find the AI systems no one registered.

Veille reads three independent sources: your software spend, your network logs, and the OAuth grants your people approved. Read-only access, nothing extracted, nothing modified. It then reconciles what was found against what you declared, and reports your own coverage gap.

3
detection channels, including the one that finds free-tier AI with no financial trace
Shadow AI detection →
02, Monitor
Know when a regulation changes before your lawyers do.

The Veille agent watches official regulatory sources, from the Gazette officielle du Québec and the Canada Gazette to OSFI and the EU AI Office, and maps every update to your registered systems within 4 hours. No manual review cycle.

<4h
from regulatory change to gap alert
The Veille Agent →
03, Evidence
Audit-ready proof. Bilingual. Tamper-evident. On demand.

Every compliance action is preserved in a WORM-locked evidence vault with SHA-256 hash chains. When your auditor asks for proof of compliance with Law 25 Art. 12.1, you export a bilingual dossier in minutes, not months of reconstruction.

7yr
default retention, WORM, SHA-256 integrity
Evidence vault →

Coverage

Every framework that applies to Canadian AI, encoded at the article level.

Veille doesn't give you a checklist of principles. It encodes every obligation, 146 across fifteen frameworks, at the article level, maps them to the specific systems in your inventory, and flags gaps the moment they appear.

When a regulator asks for proof of compliance with OSFI E-23 Section 5.2, you don't search for the relevant document. You export the dossier.

At the centre sits the AMF's guideline on the use of AI for Québec financial institutions, anchored verbatim to the official AMF texts. It takes effect May 1, 2027, so its obligations are marked effective on that date and start counting toward compliance then. For a caisse, a Québec insurer, or an OCRI dealer, it is the framework that matters most, and it is fully encoded in the library.

View full coverage →
146 Obligations encoded
15 Frameworks: Law 25, PIPEDA, BC PIPA, AB PIPA, PHIPA, AMF Québec, OSFI E-23, OSFI B-13, CSA/CIRO, EU AI Act, TBS, Bill 149, Bill 194, ISED Code, human rights
2 Official languages, bilingual evidence
Tier 1 SLA

Law 25, OSFI E-23, and EU AI Act changes are detected and mapped within 4 hours. Tier 2 frameworks (Bill 149, Bill 194, TBS Directive) are monitored continuously with next-sprint resolution.

Architecture

An AI agent that reads regulations the way a lawyer does, and runs 24 hours a day.

Veille is not a rule engine with a database of checkboxes. It reads regulatory text, reasons about how changes affect each system in your inventory, and drafts the documents that address each gap, bilingual, citing the exact article.

Loop 01
Watch Loop

Monitors regulatory sources on a continuous cadence. Detects amendments, new guidance, and enforcement decisions. Maps changes to affected obligations within 4 hours.

Loop 02
Discovery Loop

Reads spend exports, network logs and OAuth grants for AI not in the registered inventory. Reconciles found against declared, records one system per vendor even when several channels confirm it, and logs each discovery to the audit trail.

Loop 03
Compliance Loop

Evaluates each registered system against its obligations, article by article. Drafts missing documents, transparency notices, PIAs, model cards, and routes them for human review before scoring.

01
Powered by every Anthropic model, matched to the task
Veille runs on the Claude family, task-tiered with automatic failover, routing each task to the right model: the fastest models for high-volume scans, the most capable for deep regulatory reasoning. When Anthropic ships a new model, the agent adds it to the hierarchy automatically.
02
Human in the loop, always
Veille drafts. Humans validate. Every agent-produced document is stored as draft_pending_review and does not improve your compliance score until a designated reviewer opens it and clicks Validate. The score reflects what you've actually confirmed, not what the agent produced.
03
Tamper-evident audit trail from day one
Every agent action, scan initiated, gap detected, document drafted, review completed, is logged with a timestamp and SHA-256 hash. The trail is append-only. Nothing is modified retroactively. When the regulator asks when you knew about a gap, you have the exact timestamp.
Agent architecture →

Security

Your AI inventory is sensitive data. We treat it that way.

Every piece of data Veille stores, your system inventory, compliance gaps, evidence documents, stays in Canada. LLM inference runs on Anthropic's API (US) today for reasoning over compliance metadata and is migrating to AWS Bedrock in Canada for full Canadian residency; your vault documents are never transmitted. Your AI inventory is not a training dataset.

We apply the same compliance standards to ourselves that we help you meet: Veille's own platform is subject to Law 25 and Bill 194 monitoring, and our infrastructure is on the SOC 2 Type II roadmap for Q4 2026.

Data residencyca-central-1
LLM inferenceBedrock ca-central-1 (migrating)
EncryptionAES-256 / TLS 1.3
Training useNever
AccessMFA enforced
ComplianceSOC 2 Type II (Q4 2026)
Evidence vaultWORM, append-only
Audit trailSHA-256 hash chains
RetentionConfigurable, 7-yr default
Breach notification≤ 72 h
Full security details →

Integrations

Read-only access to your ML infrastructure. Nothing more.

Veille connects to where your AI systems actually live, not where they were supposed to be documented. Every connector is read-only: metadata scanning only, no data extraction, no write access.

GitHub

Scans repositories for model deployment configs, ML workflow files, and AI service dependencies not in the declared registry.

Beta
AWS SageMaker

Detects active inference endpoints, training jobs, and deployed model versions across your AWS accounts.

Beta
Databricks

Reads MLflow experiment and model registry metadata. Surfaces models in production that aren't in the compliance inventory.

Beta
Azure ML

Discovery connector for Azure Machine Learning workspaces and deployed endpoints. Planned for Q4 2026.

Planned Q4
All integrations →

See it live

Walk through your AI inventory with us.

A 30-minute call is enough to map your current exposure: which systems you have, which obligations apply, and where the gaps are most likely to be. No deck. No sales process.

Book a call Open evidence vault demo