Industries
SWE · DACH
Software
AI features
buyers can sign.
SaaS companies, software vendors and IT service providers. You build AI into the product, and enterprise buyers send questionnaires about it.
01 · Topics
What keeps
you busy.
The topics that come up first when AI meets this industry. If one sounds familiar, that is where we start.
- 01Enterprise buyers ask for evidence
Security questionnaires now include the AI Act, ISO 42001 and model risk. Without answers, the deal stalls.
- 02LLM features open new attack surfaces
Prompt injection, data leakage, agents with too many permissions. Classic pentests do not cover it.
- 03Speed versus control
Coding assistants make the team faster. Nobody reviews what they write at the same speed.
02 · Examples
Where AI
earns its keep.
Input, action, result. The places we would look first, because the work is repetitive, the data exists and a person still signs off.
- 01AI features in the product
Use case and data → feature built, evaluated and monitored → shipped with the documentation buyers ask for.
- 02LLM security testing
Your AI feature → tested for prompt injection, data leakage and permission abuse → findings with fixes.
- 03Compliance evidence
Product and processes → AI Act role, risk class and technical documentation → answers for questionnaires and tenders.
- 04Coding assistants with guardrails
Your repositories and pipeline → rules, reviews and scans for AI-written code → speed without silent debt.
sample Illustrative examples, not client references.
03 · The rules
What applies,
and since when.
The rules we plan around in this industry. With the source, so your legal team can check our reading.
- 01Providers carry the heaviest duties
If you place an AI system on the market under your name, you are its provider. If it is high-risk, conformity assessment, documentation and monitoring are yours.
Art. 3(3), 16 AI Acthigh-risk from 2 December 2027 - 02Your customer’s use case sets the class
The same model is high-risk in recruiting or credit scoring and minimal-risk in marketing. Know where your product is used.
Art. 6(2), Annex III AI Actfrom 2 December 2027 - 03Exploited vulnerabilities are reported
Manufacturers of software products report actively exploited vulnerabilities and severe incidents, with an early warning within 24 hours.
Art. 14 Cyber Resilience Actsince 11 September 2026 - 04NIS2 for digital providers
Cloud, data centre, managed service and managed security providers above the size thresholds must register, manage cyber risk and report incidents.
NIS2UmsuCG, BSIGsince 6 December 2025
Not legal advice Our reading as of September 2026, not legal advice.
04 · Clients
Worked with.
Names from voidgap.com. Some clients cannot be named; their work appears as anonymised cases.
05 · Services
Where to
start.
Build, Secure, Comply, Enable: the four services we would start software projects with.
06 · Next steps
What happens
after you send it.
Four steps between your request and a decision. No step commits you to anything.
- 01 You send the requestThree questions about your situation, then your contact details. It takes a few minutes.
- 02 We read it and replyA person reads your answers and replies by email, with questions or a proposal for a first conversation.
- 03 First conversationYour use case, your data, the rules that apply. Afterwards you know whether and how to start.
- 04 Written proposalIf it fits: scope, approach and effort in writing. You decide.
07 · Download
Take it
with you.
For your team, as a PDF. Leave your email and we send it to you.
In preparation
Checklist: AI Act and CRA for software providers
Provider duties, risk class and vulnerability reporting in one list.
What is inside
- Provider or deployer: which role you have
- When your customer’s use case makes you high-risk
- What the CRA reporting duty requires
The PDF is being prepared. Request it now and you get it as soon as it is ready.
08 · Request
Tell us
where it hurts.
Three short steps. Your answers help us prepare the first conversation for your case.
- 01Your situation
- 02Your project
- 03Contact
09 · Questions
Questions
from this industry.
Short answers. Anything else goes into your request.
We only call a model vendor’s API. Are we a provider?
If you put an AI system on the market under your name, yes, even if the model comes from someone else. The model vendor has its own duties for the model.
Do we need ISO 42001?
Not by law. Some enterprise buyers ask for it in tenders. We help you decide whether a certification pays off.
Can you test our AI feature before launch?
Yes. A security assessment before launch costs less than a finding after it. We test the feature the way an attacker would.
Software
Your product,
your void.
Tell us where it hurts. We check which rules apply before the first line of code.