About Piotr Reder
Piotr Reder
Founder · aiactaudit.pl
EU AI Act audit specialist for SMB SaaS
Solo operator · autónomo Spain · NIE-resident Norway
EU AI Act Annex III GPAI GDPR SMB compliance
What I do
I run aiactaudit.pl — a focused EU AI Act compliance audit service for SMB SaaS companies (10-200 employees). One person. €799 founding tier audits. 5-day delivery. 30-day money-back guarantee.
I'm not Big4. I'm not a law firm. I'm a solo founder who built this because I went through the EU regulatory gauntlet myself with my other products — and noticed mid-market SMBs are stuck between consultants they can't afford and DIY they can't do.
Why solo
Big4 charges €15-50k for audits because they have partner overhead, junior research time, and global brand premium. Specialized boutiques charge €4,500-9,500 for the same scope. I charge €799 because:
- No partner overhead — direct expert work
- No SaaS subscription model — one-off engagements
- Lifestyle business reality — €30-100k/yr profit target, not VC scale
- Claude Code automation reuse — same tools as my other products (Pricora, LocalBite)
Background
Regulatory experience (operational, not theoretical)
- Apple DSA + EAA compliance — successfully launched LocalBite app on EU 27 App Store after multi-month DSA trader verification, EAA accessibility considerations
- Spanish autónomo — operating cross-border (Norway resident, Spanish business registration), navigating EU tax + VAT IDs + invoicing across jurisdictions
- GDPR — full RoPA + DPIA-equivalent documentation for multiple products (Pricora benchmark dataset, LocalBite restaurant data, audit lead intake)
Technical background
- ~20 years in tech (started as developer, evolved into solo product founder)
- Multiple SaaS products built solo (Pricora, LocalBite, aiactaudit.pl)
- Daily user of Claude Code, AI development tools, AI compliance scanners (AIR Blackbox, VerifyWise)
- Public eat-own-dog-food experiments — see Self-scan with AIR Blackbox
What I'm NOT
Honest about limits is part of value proposition:
- NOT a lawyer — I deliver technical audit + classification, NOT legal opinion. Final compliance posture should always involve EU AI Act-specialized counsel.
- NOT a Big4 — no global brand backing, no partner-level liability insurance. €15M penalty exposure remains client's responsibility.
- NOT a SaaS platform — point-in-time audit, not continuous monitoring. For runtime compliance see AIR Blackbox or VerifyWise.
- NOT specialized in regulated industries beyond audit scope — banking, healthcare, defense have additional sector-specific requirements I'd hand off to specialists.
How I work
Audit process is 100% async — you don't book my calendar, I don't have one open for sales calls.
- Intake form (5 min) — describe your AI systems via /audit-intake.html
- Initial review (24h) — I respond within 4h CET with scope + expected delivery date
- Audit work (3-4 days) — I run AIR Blackbox scan + manual review per Annex III + GDPR crosswalk + GPAI provider verification
- Deliverable (Day 5) — PDF report (typically 12-20 pages) + Loom video walkthrough (15-25 min)
- Q&A (30 days) — async email follow-up included for clarifications
- Money-back — if I don't find at least 3 actionable findings within 30 days, full refund.
What you get in deliverable
- Annex III risk classification per AI feature/system in your product
- Articles 9-15 gap analysis (data governance, oversight, transparency, etc.)
- Provider/deployer scope clarification (GPAI handling)
- Severity ranking with €15M penalty exposure context
- Prioritized remediation roadmap with effort estimates
- Loom walkthrough explaining each finding in plain language
See sample audit for fictional Acme HR-Tech to see exactly what's delivered.
Pricing
- Founding tier: €799 (limited to 10 spots, currently available)
- Standard tier: €1,499 (after Founding sells out)
- Subscription monitoring: €299/month (planned, post-validation)
- 30-day money-back guarantee on all tiers
Contact
Email: piotr@pricora.eu (until aiactaudit.pl email DNS-verified)
LinkedIn: linkedin.com/in/piotr-reder-541779402
GitHub: github.com/TAIKER656 (some private repos)
Documents
- Risk Classification — explicit Annex III determination for aiactaudit.pl itself
- Records of Processing Activities (GDPR Art. 30)
- Security posture + responsible disclosure
- Privacy policy
- Terms of service