EU AI Act for IT teams and CTOs
Compliance does not stop at processes – it must be technically implementable. SimpleAct offers API integration, webhooks, OpenAPI documentation, and hosting in Germany. Your IT team stays in control without building another silo.
Typical requirements from IT teams
- Compliance workflows need to integrate with existing tools (Jira, Teams, ServiceNow)
- Audit logs must be technically immutable and exportable
- Hosting requirements: Germany, GDPR, no US cloud provider
- SSO and role-based access control as prerequisites for enterprise rollout
- IT security asks about penetration tests, TLS versions, and encryption at rest
What this looks like in practice
The security team needs to evaluate an AI compliance tool. Requirements: SSO via existing identity provider, Jira integration for audit playbook tasks, data only in Germany. Without SimpleAct: months of evaluation, no tool meets all requirements. With SimpleAct: API-first, OpenAPI docs, native Jira integration, SSO in Enterprise plan, hosted at Hetzner Nuremberg.
What SimpleAct delivers for IT teams
API, webhooks and OpenAPI
Full REST API with API keys, webhook endpoints, and OpenAPI documentation. Your own systems can read, write, and synchronise AI inventory data.
Native integrations
Jira, Microsoft Teams, and ServiceNow out of the box. Incidents and tasks from the audit playbook land directly in your existing tools.
Security architecture
RBAC, 2FA (TOTP), multi-tenancy isolation, session invalidation, TLS 1.2+, encryption at rest. Hosted at Hetzner (DE) and Supabase Frankfurt.
SSO and enterprise auth
SAML/LDAP and SSO in the Enterprise plan. Simple integration with existing identity providers – no separate user management.
What your IT team gets
- REST API with API keys and OpenAPI documentation
- Webhook endpoints for event-driven integrations
- Native Jira, Teams, and ServiceNow integration
- SSO/SAML and LDAP in the Enterprise plan
- RBAC with granular role assignment per tenant
- TLS 1.2+, encryption at rest, 2FA (TOTP), session invalidation
Frequently asked questions from IT teams
Is there public API documentation?
Yes. SimpleAct offers OpenAPI documentation, ingestion endpoints, and webhook support. Details in the Enterprise plan – get in touch.
Where does the system run? Is on-premise possible?
SimpleAct runs as SaaS at Hetzner (Nuremberg) and Supabase (Frankfurt) – all within Germany/EU. On-premise is not currently available; all data stays in the EU.
How is high availability handled?
99.5% availability target per SLA, automated daily backups (point-in-time recovery), and defined incident response processes.
How long does technical integration take?
Basic operation without integration: ready immediately. API integration and Jira connection: a few hours. SSO/SAML configuration: one working day with standard identity providers.
Is there a test environment?
The 30-day trial serves as a full test environment with no credit card required. For enterprise customers we discuss dedicated setups as part of the pilot project.
Integration into existing tech stacks
API-first, secure architecture, hosting in Germany – ready for enterprise rollout.
View API & integrations