Services · 15 ways across one gap

All services

Work · proof, not promises

All case studies

Insights · street talk, written down

Magazine

Company · AI in production since 2011

About Voidgap

Software

AI features
buyers can sign.

SaaS companies, software vendors and IT service providers. You build AI into the product, and enterprise buyers send questionnaires about it.

01 · Topics

What keeps
you busy.

The topics that come up first when AI meets this industry. If one sounds familiar, that is where we start.

  • 01Enterprise buyers ask for evidence

    Security questionnaires now include the AI Act, ISO 42001 and model risk. Without answers, the deal stalls.

  • 02LLM features open new attack surfaces

    Prompt injection, data leakage, agents with too many permissions. Classic pentests do not cover it.

  • 03Speed versus control

    Coding assistants make the team faster. Nobody reviews what they write at the same speed.

02 · Examples

Where AI
earns its keep.

Input, action, result. The places we would look first, because the work is repetitive, the data exists and a person still signs off.

  • 01AI features in the product

    Use case and data → feature built, evaluated and monitored → shipped with the documentation buyers ask for.

  • 02LLM security testing

    Your AI feature → tested for prompt injection, data leakage and permission abuse → findings with fixes.

  • 03Compliance evidence

    Product and processes → AI Act role, risk class and technical documentation → answers for questionnaires and tenders.

  • 04Coding assistants with guardrails

    Your repositories and pipeline → rules, reviews and scans for AI-written code → speed without silent debt.

sample Illustrative examples, not client references.

03 · The rules

What applies,
and since when.

The rules we plan around in this industry. With the source, so your legal team can check our reading.

  1. 01
    Providers carry the heaviest duties

    If you place an AI system on the market under your name, you are its provider. If it is high-risk, conformity assessment, documentation and monitoring are yours.

    Art. 3(3), 16 AI Acthigh-risk from 2 December 2027
  2. 02
    Your customer’s use case sets the class

    The same model is high-risk in recruiting or credit scoring and minimal-risk in marketing. Know where your product is used.

    Art. 6(2), Annex III AI Actfrom 2 December 2027
  3. 03
    Exploited vulnerabilities are reported

    Manufacturers of software products report actively exploited vulnerabilities and severe incidents, with an early warning within 24 hours.

    Art. 14 Cyber Resilience Actsince 11 September 2026
  4. 04
    NIS2 for digital providers

    Cloud, data centre, managed service and managed security providers above the size thresholds must register, manage cyber risk and report incidents.

    NIS2UmsuCG, BSIGsince 6 December 2025

05 · Services

Where to
start.

Build, Secure, Comply, Enable: the four services we would start software projects with.

06 · Next steps

What happens
after you send it.

Four steps between your request and a decision. No step commits you to anything.

  1. 01 You send the requestThree questions about your situation, then your contact details. It takes a few minutes.
  2. 02 We read it and replyA person reads your answers and replies by email, with questions or a proposal for a first conversation.
  3. 03 First conversationYour use case, your data, the rules that apply. Afterwards you know whether and how to start.
  4. 04 Written proposalIf it fits: scope, approach and effort in writing. You decide.

07 · Download

Take it
with you.

For your team, as a PDF. Leave your email and we send it to you.

In preparation

Checklist: AI Act and CRA for software providers

Provider duties, risk class and vulnerability reporting in one list.

What is inside

  • Provider or deployer: which role you have
  • When your customer’s use case makes you high-risk
  • What the CRA reporting duty requires

The PDF is being prepared. Request it now and you get it as soon as it is ready.

08 · Request

Tell us
where it hurts.

Three short steps. Your answers help us prepare the first conversation for your case.

  1. 01Your situation
  2. 02Your project
  3. 03Contact

Step 1 of 3 Your situation

Is AI part of your product?

Who are your customers?

09 · Questions

Questions
from this industry.

Short answers. Anything else goes into your request.

We only call a model vendor’s API. Are we a provider?

If you put an AI system on the market under your name, yes, even if the model comes from someone else. The model vendor has its own duties for the model.

Do we need ISO 42001?

Not by law. Some enterprise buyers ask for it in tenders. We help you decide whether a certification pays off.

Can you test our AI feature before launch?

Yes. A security assessment before launch costs less than a finding after it. We test the feature the way an attacker would.

Software

Your product,
your void.

Tell us where it hurts. We check which rules apply before the first line of code.