Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
EuConform — EU AI Act Compliance Tool - Risk classification and bias testing | Kitploit
Tools/GitHubGitHub/hiepler/euconform
Static AnalysisPrivacySupply Chain SecurityLearning & EducationCurated ResourcesAI Security
GitHubhiepler/euconform

EuConform

EU AI Act Compliance Tool - Risk classification and bias testing

View Repository
1235235 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Website
Share

EuConform

🇪🇺 Open-Source Evidence Toolkit For AI Compliance

Open evidence format • Local bias evaluation • Schema validation • CycloneDX interoperability
Offline-first • Privacy-preserving • Reusable artifacts • WCAG 2.2 AA accessible

CI Status Coverage MIT License EUPL License

Node.js TypeScript Next.js Biome

EuConform defines an open evidence format for AI compliance and provides the tools to produce, validate, and empirically evaluate it — offline and vendor-independent.


[!IMPORTANT] Legal Disclaimer: This tool provides technical guidance only. It does not constitute legal advice and does not replace legally binding conformity assessments by notified bodies or professional legal consultation. Always consult qualified legal professionals for compliance decisions.


EuConform Interface

🚀 Quick Start · 📖 Docs · 🌐 Deploy · 🐛 Report Bug


✨ Features

FeatureDescription
🧾 Open Evidence FormatProduce portable report, aibom, ci, and bundle artifacts as inspectable JSON documents
🧪 Local Bias EvaluationCrowS-Pairs-based model evaluation with log-probability and latency fallback — reproducible, offline, no vendor dependency
✅ Schema ValidationValidate EuConform JSON documents against the published schemas with euconform validate
📦 Bundle VerificationVerify manifest, directory, or ZIP bundle integrity before handing artifacts to CI, reviewers, or auditors
🚦 Compliance CI GateTurn euconform scan into GitHub-native annotations, CI summaries, and machine-readable artifacts
🎯 Risk ClassificationInteractive quiz implementing EU AI Act Article 5 (prohibited), Article 6 + Annex III (high-risk)
🔄 CycloneDX InteroperabilityImport external CycloneDX SBOMs into the EuConform AI BOM layer as an interoperability bridge
🌐 Offline-FirstCore evidence workflows stay local and inspectable instead of depending on vendor dashboards
🔒 Privacy-PreservingZero tracking, no cookies, no external fonts – your data stays under your control
🌙 Dark ModeBeautiful glassmorphism design with full dark mode support
♿ AccessibleWCAG 2.2 AA compliant with full keyboard navigation
🌍 MultilingualEnglish and German interface

🧰 CLI At A Glance

CommandPrimary outputUse case
scanNative EuConform artifactsGenerate structured evidence from a real repository
biasBias report JSON and/or MarkdownRun reproducible local model evaluation with Ollama — EuConform's distinctive empirical layer
validateValid/invalid status per JSON fileCheck EuConform JSON files against published schemas
verifyBundle integrity statusCheck a manifest, extracted bundle, or ZIP archive
importeuconform.aibom.jsonMap an external CycloneDX SBOM into the EuConform AI BOM layer

🚀 Quick Start

Want to try it without installation? Click the 🌐 Deploy link above to start your own instance on Vercel.

Prerequisites

  • Node.js ≥ 18
  • pnpm ≥ 10 (recommended) or npm/yarn

Installation

# Clone the repository
git clone https://github.com/Hiepler/EuConform.git
cd EuConform

# Install dependencies
pnpm install

# Start development server
pnpm dev

# Open http://localhost:3001

Build The CLI

The repo-local examples below use the built CLI directly:

# Build the CLI
pnpm --filter @euconform/cli build

Workflow 1: Scan A Repository

Generate native EuConform artifacts from a real codebase:

node packages/cli/dist/index.js scan . --scope production

This writes:

  • .euconform/euconform.report.json
  • .euconform/euconform.aibom.json
  • .euconform/euconform.summary.md
  • .euconform/euconform.bundle.json

Typical use:

  • evidence collection for local OSS or internal AI projects
  • CI gating and reviewer handoff
  • portable artifact generation without a vendor platform

For CI usage, add GitHub-native annotations and fail thresholds:

node packages/cli/dist/index.js scan . --scope production --ci github --fail-on high

For portable artifact exchange, create a bundle archive:

node packages/cli/dist/index.js scan . --scope production --zip true

Workflow 2: Validate And Verify Existing Artifacts

Validate individual EuConform JSON documents against the published schemas:

node packages/cli/dist/index.js validate .euconform

Typical output:

  • one line per file such as euconform.aibom.json — valid (euconform.aibom.v1)
  • exit code 0 for fully valid input, 1 for schema errors, 2 when no EuConform JSON files are found

Verify a bundle manifest, extracted bundle directory, or ZIP archive:

node packages/cli/dist/index.js verify .euconform/euconform.bundle.json

Typical use:

  • reviewer-side schema checking before manual analysis
  • CI sanity checks for artifact sets already produced elsewhere
  • portability checks before sharing bundles with downstream tools

Workflow 3: Evaluate Model Bias Locally

Run a reproducible CrowS-Pairs bias evaluation against a local Ollama model:

node packages/cli/dist/index.js bias llama3.2 --lang de --output all

This is EuConform's distinctive empirical evidence layer. It produces model-behavior data that no other open-source compliance tool currently offers — completely offline, reproducible, and independent of any vendor API.

Typical use:

  • empirical model-behavior evidence for Art. 10 bias/fairness documentation
  • reproducible local evaluation before and after model updates
  • adding a behavioral evidence layer on top of structural evidence from scan

Workflow 4: Import An External CycloneDX SBOM

Map an external CycloneDX JSON file into the EuConform AI BOM layer:

node packages/cli/dist/index.js import ./third-party.cdx.json \
  --scope production \
  --output /tmp/euconform-import

node packages/cli/dist/index.js validate /tmp/euconform-import/euconform.aibom.json
Download Tool