Auditable AI compliance reports — deployed in your own infrastructure
Audnexa supports preparing auditable report and gap-analysis drafts (DORA, NIS2, ISO 27001, AI Act) with references to evidence. In offline mode (Bank Mode) data stays in your infrastructure; in hybrid mode only anonymized data is sent to the cloud. A human approves every report.
- Offline mode — data stays in your infrastructure
- A human approves every report
- Customer data is never used to train models
Supports auditing and documenting compliance with
From evidence to an auditable report — faster and repeatable
The biggest time sink isn’t writing the report — it’s compliance: reading dozens of procedures and policies and checking them against requirements. Audnexa helps organize the documentation, relate evidence to requirements and shorten the path from collected evidence to a review-ready draft — without losing control of your data, and with an audit trail.
Pilot results depend on report type and scope; they are not a guarantee.
Data control as a precondition, not an add-on
Designed for the expectations of CISOs, DPOs, internal audit and procurement at regulated institutions.
- offline only — no outbound traffic by default
- customer data not processed by Virtline or third-party AI providers
- customer-controlled infrastructure
- controlled update process
- support access only on explicit customer approval
| Bank Mode (offline) | On-premise (hybrid) | Customer private cloud | |
|---|---|---|---|
| Data leaves infrastructure | No | Only anonymized categories (optional) | Within customer cloud |
| Subprocessors of customer data | None | Disclosed in an appendix | Per customer configuration |
| Generative AI features | Local model | Local or post-anonymization | Per customer policy |
| Vendor / support access | Only on explicit approval | Controlled, on request | Controlled, on request |
| Updates | Customer-controlled | Controlled | Controlled |
We know it’s not just a module for you — as an ICT provider, we are subject to your assessment too. We come prepared.
ISO/IEC 27001:2022 (organization)
Certified organization: Virtline Sp. z o.o., certification body TÜV Nord. We publish the certificate number and validity period; the full certificate and scope are available on request.
AC090 121/2469/6137/2026 · TÜV NORD Polska · 02.2026–02.2029
- Security Architecture Overview
- Deployment & Data-Flow Overview
- Data Processing Agreement (DPA)
- Subprocessor list
- Vulnerability Management Policy
- Exit Plan / data export
- AI Governance & Human Review Statement
Customer data is never used to train models — in any deployment mode.
Human oversight, logging, transparency and clear system limitations. Audnexa makes no autonomous legal or credit decisions and does not replace an auditor’s opinion.
Request the vendor-risk packBuilt by cybersecurity experts
Audnexa was created at Virtline — a cybersecurity firm with over 12 years of experience and an ISO/IEC 27001 certificate, running over 100 audits a year. We built the tool we use ourselves in day-to-day audit work.
Modules — what they actually solve
A maintained compliance methodology, updated for regulatory change. It supports report preparation and documenting compliance — it does not replace an auditor’s or lawyer’s opinion.
Gap analysis for essential and important entities
Maps cybersecurity management obligations and prepares a gap report for the board.
ISMS evidence and control mapping
Organizes policies, procedures and evidence against requirements — ready for review and certification.
Operational resilience and ICT vendor risk
Supports resilience testing and documenting third-party ICT risk in the financial sector.
AI governance and human oversight
Supports documenting human oversight, transparency and system limitations in line with the AI Act.
GDPR audit and personal data protection
GDPR audit support (EU 2016/679): reviewing processing security (Art. 32), DPIAs, records of processing activities, retention and procedures for the 72-hour breach notification under Art. 33. In offline mode, personal data does not leave the customer’s infrastructure.
How it works — a controlled, human-in-the-loop process
AI supports preparing a draft and references to evidence; an authorized team approves the findings and the final version. Every report section has sources and a change history.
Collect evidence
Enter findings and documents in a controlled workspace — with data isolation and an audit trail.
Controlled analysis
The system supports preparing an auditable draft — organizing findings and references to evidence.
Review & approve
The audit/compliance team verifies and approves; export the approved, branded report.
Who it’s for
Primary paths for regulated organizations — from banks to NIS2 entities and audit & compliance teams.
Data control for banking secrecy and DORA
For the CISO, Head of Internal Audit, Compliance Officer, DPO and procurement. Offline mode, vendor-risk pack, outsourcing classification.
From documents to a gap map
For essential and important entities: NIS2/national gap analysis, board report, documenting compliance.
Repeatable, auditable reports
Standardize methodology and accelerate deliverables without scaling the team proportionally.
Are you an audit or advisory firm (GDPR, NIS2, DORA, AI Act)? → Separate track
Case studies & evidence
Outcomes from real use; metrics are measured per client and report type. Full references available under NDA.
Time to first draft (pilot)
Time to a first draft of a gap report — based on a pilot.
Context: an internal audit team preparing a DORA gap report ahead of a risk-committee review.
Measurement: time from a complete evidence set to a review-ready first draft; same scope and report type, measured across 3 cycles.
Reference case studies (with the client name) are shared under NDA, on anonymized data.
| Audnexa | Excel / Word | LLM self-build | Enterprise GRC | |
|---|---|---|---|---|
| Maintained regulatory methodology | Yes | No | Your team | Partial |
| Offline mode / data control | Yes | n/a | Hard | Rare |
| Auditability and trail | Yes | Manual | To build | Yes |
| Vendor-risk pack for DORA | Yes | n/a | None | Depends |
| Total cost of ownership | Low | Hidden (time) | High | Very high |
Audnexa does not replace a central GRC risk register — it shortens the path from evidence to an auditable report.
ROI — what you actually save
Audnexa can pay for itself faster than a single external advisory project. Estimate the saving for your team.
Indicative estimate based on your inputs; not an offer or a guarantee of results.
Deployment and licensing models
For regulated organizations we price by deployment mode, number of modules and support requirements. Audit-firm plans are on a separate track.
Banks, financial institutions, large regulated organizations.
- Bank Mode / on-premise / private cloud
- Implementation, hardening, SSO/AD
- Vendor-risk pack + DPA + exit plan
- SLA and L2/L3 support
- Audit log, isolation, MFA
Audit & advisory firms (compliance / cyber)
AUDITOR / STARTER / PRO plans for smaller audit teams — on a separate page.
A single external project can cost as much as a year of running many audits with Audnexa. Prices are net (B2B). Details and license terms are agreed during the security walkthrough.
FAQ — product, procurement, AI
Is an Audnexa report a legal or auditor’s opinion?
Does data leave the bank’s infrastructure?
Is Audnexa an ICT provider under DORA?
How do you limit AI hallucinations?
Is customer data used to train models?
Can it be deployed without internet?
Can the customer disable generative features?
What about the exit plan and data export?
Do you support the customer’s right to audit?
How is the regulatory methodology updated?
Practical compliance-audit knowledge
Practical guides to IT security and regulatory compliance audits — written by audit practitioners at Virtline.
Book a security walkthrough
We’ll show the architecture, deployment modes and data flow — and hand over the vendor-risk pack. We usually reply within 24 hours.
+48 12 200 27 10 Virtline Sp. z o.o. ul. Wadowicka 8A, 30-415 Kraków, PL biuro@virtline.com NIP 6751499701 · KRS 0000502030