Annexweave
A repository review integration that detects approved technical evidence changes, maps them to separately versioned control questions, and produces source-linked GDPR, EU AI Act, ISO 27001, NIS2 and DORA draft updates for qualified review.
Engineering changes often reach legal and compliance teams after documentation is already stale. Annexweave creates a change-triggered drafting workflow from authorized repository evidence. The source research sharply limits the claim: the cited open project is pre-release, had minimal adoption, and listed continuous-integration support as a future roadmap item rather than a shipped capability. A separate project demonstrates a narrow action pattern, and one referenced interface was verified. Repository code can show declared services, dependencies and configurations, but it cannot prove real processing, contracts, organizational controls, risk acceptance or legal applicability. Secrets and credential files are never read, copied or included. Each detected fact keeps repository, commit, file and exact line provenance, plus uncertainty. GDPR, EU AI Act, ISO 27001, NIS2 and DORA remain separate regimes and control systems; a shared technical fact can be reused without claiming one fact satisfies all obligations. Change detection, evidence candidate, control mapping, document draft, legal or compliance review, approval, publication and external acceptance remain distinct. Success is earlier, cited documentation review and fewer stale technical descriptions—not automated compliance, certification or legal advice.
An enterprise product security, governance, risk, compliance or privacy leader responsible for keeping technical evidence and compliance documentation aligned.
Current regulatory programs and recent projects support urgency.
Evidence extraction and document diffs scale through software, while applicability and approval require experts.
One cross-reference and two inbound links support moderate convergence.
A concrete shift-left workflow, one verified interface and an unoccupied enterprise product form support a narrow pilot.
The main open project is pre-release, its integration is unshipped, code evidence is incomplete, buyer evidence is broad and incumbents can add repository hooks.
Discussion
No comments yet — be the first to weigh in.
