Primust binds governed runs to regulatory bundles and framework mappings, then emits evidence another party can verify independently.
Every regulated surface — AI, finance, healthcare, operational resilience — asks the same underlying question: how do we know the declared controls actually ran? A screenshot, a dashboard, or a self-reported log can't answer it. A VPEC can.
Primust ships named regulatory bundles and framework mappings. Each one binds governed runs to specific articles, rules, or control objectives. One click in the dashboard binds your runs to the ones that apply.
Under the current EU implementation timeline, high-risk AI system obligations for Annex III systems and transparency rules apply from August 2, 2026. The eu_ai_act_art12_v1 bundle maps to Articles 9, 10, 12, 13, 14, and 17 — so every governed run produces a VPEC with the correct regulatory context, retention policy, and risk classification baked in.
A notified body or auditor may ask for evidence stronger than self-reported logs. Primust produces cryptographic evidence they can verify independently.
View Article map ↓The EU AI Act example matters because the affected workflows are ordinary enterprise workflows: credit, insurance, hiring, education, infrastructure, public-sector decisions, and other high-impact systems.
The EU AI Act is the detailed example because it shows the shape of the product: declared controls, automatic records, input commitments, human oversight, retention, and a verifier another party can run offline.
Install and bind with primust init --policy <bundle_id> — or select interactively in the dashboard setup flow at app.primust.com/setup/regulations.
primust init picks up the approved control plan; every VPEC is stamped with the bundle hash and the regulations it satisfies.pip install primust && primust init. Sandbox key is free and unlimited. Swap to pk_live_ when you're ready to ship audit-grade evidence.