Kortave

[ DECISION GUIDE ]

A compliance hire, a consultancy, or Kortave?

Every EU company that processes personal data, ships software, or touches AI has the same three options for getting compliant. They differ by roughly two orders of magnitude in cost. This page lays out the honest trade-offs, including when Kortave is not the right answer.

Context for the timeline: the EU AI Act's main obligations apply from 2 August 2026. DORA has applied to financial entities since January 2025. GDPR enforcement has been running since 2018, with fines up to €20 million or 4% of global turnover.

In-house compliance hireConsultancyKortave
Upfront cost€60,000–90,000 / year salary€10,000–50,000 per projectFrom €99 / month, no setup fee
Time to first documents2–4 months (hiring + ramp-up)4–12 weeks per engagementDays
Regulations coveredDepends on the individualScoped per contractAll nine frameworks: GDPR, AI Act, NIS2, DORA, CRA, Data Act, DGA, DSA, ePrivacy
When the law changesCovered, if they keep upNew engagement, new invoiceDocuments updated continuously, included
Who does the workOne person, single point of failureExternal team, then they leaveAI drafting + specialist review, always on
Scales with growthNeeds a second hire eventuallyCosts scale linearlySame subscription
Best forLarge-scale / high-risk processingOne-off complex matters, auditsSMEs needing complete, maintained documentation

When Kortave is not the right choice

If GDPR Article 37 obliges you to appoint a Data Protection Officer — public authorities, large-scale systematic monitoring, or large-scale special-category data processing — you need the designated officer, and software does not substitute for that role. Kortave can still produce the documentation your DPO works from, but the appointment itself is yours to make.

If you are in active litigation, under an open supervisory investigation, or facing a genuinely novel legal question, you need a qualified lawyer, not a documentation platform. Kortave is a software service and does not provide legal advice.

For everyone else — the thousands of EU companies between 20 and 500 people with no compliance function and a stack of regulatory deadlines — the comparison above is the honest picture: the same deliverables, a fraction of the cost, maintained continuously.

See what the output actually looks like

Two complete, unredacted example deliverables — a GDPR Article 30 record and an EU AI Act Annex IV technical file.

View example documents
See pricing