Regulatory Intelligence

HARPOCRATES™ COMPLY.Reg

AI-Powered Compliance for European Regulation

Bring in the EU and German laws that apply to you. Extract their requirements, each traceable to its article. Merge the overlaps into one set of controls, assign the work, and prove it to an auditor. A person approves every AI determination.

Human Approval
EU-Hosted
Article-Level Traceability
Cross-Walk Engine
How It Works

Four steps from regulatory change to action

The AI does the reading. Your team approves each step and keeps the record.

01Ingest

EU law from EUR-Lex and German federal law from the official federal legal database, with weekly change checks.

EUR-LexGerman federal lawWeekly change checks
02Analyze

AI extracts individual requirements from the legal text, each traceable to its article, and groups the overlaps.

Requirement extractionArticle traceabilityCross-walk
03Act

Turn requirements into controls and action items with an owner, priority and due date, synced to Jira, Azure DevOps or Trello.

ControlsAction itemsJira sync
04Report

Dashboards, gap analysis, an append-only audit trail of every approval, and OSCAL export for auditors.

DashboardsGap analysisOSCAL export
Core Technology

Cross-Walk Intelligence Engine

“Regulations overlap. Requirements repeat. Your team should not have to. The cross-walk engine merges overlapping requirements from several laws into one shared set of controls.”

Many

Overlapping requirements

One

Shared set of controls

Redundant requirements are consolidated, gaps are identified, and your compliance team works on what actually matters, not duplicate spreadsheets.

Coverage

Every framework that matters

The EU regulations and German laws that matter most, with more added on request.

GDPR

Active

Data protection & privacy

NIS2

Active

Network & information security

DORA

Active

Digital operational resilience

EU AI Act

Active

AI regulation framework

Cyber Resilience Act

Active

Products with digital elements

MiCA

Active

Markets in crypto-assets

German federal law

Active

KWG, GwG, BSIG, BDSG and more

ISO 27001

Active

Control library, 2022 edition

+ Further EU and German laws added on request, and the NIST CSF 2.0 and SOC 2 control libraries

Who Benefits

Built for every stakeholder

HARPOCRATES COMPLY.Reg delivers value across your entire organisation.

Data Protection Officer

  • Record of processing activities, with AI-assisted import from spreadsheets
  • DPIAs with separate drafter and DPO review
  • Retention rules and legal holds

Compliance Officer

  • Single dashboard for all regulatory obligations
  • Cross-walk merges overlapping requirements into shared controls
  • Gap analysis within and between frameworks
  • Evidence collection and audit trail management

Head of Legal

  • Weekly change checks on German federal law, with impact traced through amendments
  • Every requirement traceable to its article in the legal text
  • Approval workflow, with every override recorded with a reason

IT / Security

  • Technical controls mapped directly from legal requirements
  • Two-way action sync with Jira, Azure DevOps and Trello
  • Hosted in Frankfurt with customer-managed encryption keys
  • SSO (SAML and OIDC), MFA and role-based access control
Proof of Concept

Tested on real regulation with PPI AG

In a joint proof of concept, PPI AG and Harpocrates trained the engine on auditor annotations for two EBA guidelines. Accuracy of requirement extraction and categorisation:

GuidelineBefore trainingAfter training
EBA Outsourcing Guidelines (EBA/GL/2019/02)73%93.1%
EBA ICT Security Guidelines64.1%95.4%

Automatic categorisation of requirements reached above 99%. Read the joint whitepaper.

Data and Security

How your data is handled

  • Hosted on Google Cloud in Frankfurt, with customer-managed encryption keys.
  • The AI runs in Google's EU region on Vertex AI.
  • You choose how evidence is shared: upload files, or use our evidence protocol, which answers requests without sending your source documents.
  • A person approves every AI determination, and approvals are kept in an append-only audit trail.
  • Single sign-on (SAML and OIDC), multi-factor authentication and role-based access control.
  • Built on the ISO 27001 and SOC 2 control frameworks. Certification is planned.

Why we built it this way: the case for keeping your documents where they are.

Guides

Start with the regulation in front of you

Frequently asked questions

What is HARPOCRATES COMPLY.Reg?
Regulatory compliance software from Harpocrates Solutions GmbH in Berlin. It extracts individual requirements from EU and German law, each traceable to its article, merges overlapping requirements into shared controls, and manages controls, evidence and approvals in one place. A person approves every AI determination.
Which regulations does COMPLY.Reg cover?
EU regulations including GDPR, NIS2, DORA, the EU AI Act, the Cyber Resilience Act, MiCA, the General Product Safety Regulation and the Data Act, and German federal law such as the KWG, GwG, BSIG and BDSG. Further EU and German laws are added on request. Control libraries include ISO 27001:2022, NIST CSF 2.0 and SOC 2.
Where is our data stored and processed?
In the EU. COMPLY.Reg runs on Google Cloud in Frankfurt with customer-managed encryption keys, and its AI runs in Google's EU region on Vertex AI.
Do our documents have to leave our systems?
You choose. You can upload evidence files, or use our evidence protocol, which answers evidence requests from your own systems without sending the source documents to us.
How accurate is the AI?
In a joint proof of concept with PPI AG, after training on auditor annotations, extraction and categorisation reached 93.1% on the EBA Outsourcing Guidelines and 95.4% on the EBA ICT Security Guidelines. In the product, a person reviews and approves every AI output, and overrides are recorded with a reason.
Which tools does COMPLY.Reg integrate with?
Action items sync both ways with Jira, Azure DevOps and Trello. Controls and evidence export as OSCAL, and single sign-on works with any SAML or OIDC identity provider.
Can we import our existing compliance spreadsheets?
Yes. Records of processing activities, assessments and control lists can be imported from spreadsheets, and the record of processing import is AI-assisted.
How is COMPLY.Reg priced?
We price against your scope, meaning the regulatory regimes and legal entities you need, rather than a public list price. Tell us your regimes and entity count and we will give you a quote.
Is COMPLY.Reg certified?
COMPLY.Reg is built on the ISO 27001 and SOC 2 control frameworks. Certification is planned.
Get Started

Ready to transform your regulatory compliance?

See how HARPOCRATES COMPLY.Reg can reduce your compliance workload, eliminate redundant efforts, and keep your organisation ahead of every regulatory change.