HARPOCRATES™ COMPLY.Reg
AI-Powered Compliance for European Regulation
Bring in the EU and German laws that apply to you. Extract their requirements, each traceable to its article. Merge the overlaps into one set of controls, assign the work, and prove it to an auditor. A person approves every AI determination.
Four steps from regulatory change to action
The AI does the reading. Your team approves each step and keeps the record.
EU law from EUR-Lex and German federal law from the official federal legal database, with weekly change checks.
AI extracts individual requirements from the legal text, each traceable to its article, and groups the overlaps.
Turn requirements into controls and action items with an owner, priority and due date, synced to Jira, Azure DevOps or Trello.
Dashboards, gap analysis, an append-only audit trail of every approval, and OSCAL export for auditors.
Cross-Walk Intelligence Engine
“Regulations overlap. Requirements repeat. Your team should not have to. The cross-walk engine merges overlapping requirements from several laws into one shared set of controls.”
Many
Overlapping requirements
One
Shared set of controls
Redundant requirements are consolidated, gaps are identified, and your compliance team works on what actually matters, not duplicate spreadsheets.
Every framework that matters
The EU regulations and German laws that matter most, with more added on request.
GDPR
Data protection & privacy
NIS2
Network & information security
DORA
Digital operational resilience
EU AI Act
AI regulation framework
Cyber Resilience Act
Products with digital elements
MiCA
Markets in crypto-assets
German federal law
KWG, GwG, BSIG, BDSG and more
ISO 27001
Control library, 2022 edition
+ Further EU and German laws added on request, and the NIST CSF 2.0 and SOC 2 control libraries
Built for every stakeholder
HARPOCRATES COMPLY.Reg delivers value across your entire organisation.
Data Protection Officer
- Record of processing activities, with AI-assisted import from spreadsheets
- DPIAs with separate drafter and DPO review
- Retention rules and legal holds
Compliance Officer
- Single dashboard for all regulatory obligations
- Cross-walk merges overlapping requirements into shared controls
- Gap analysis within and between frameworks
- Evidence collection and audit trail management
Head of Legal
- Weekly change checks on German federal law, with impact traced through amendments
- Every requirement traceable to its article in the legal text
- Approval workflow, with every override recorded with a reason
IT / Security
- Technical controls mapped directly from legal requirements
- Two-way action sync with Jira, Azure DevOps and Trello
- Hosted in Frankfurt with customer-managed encryption keys
- SSO (SAML and OIDC), MFA and role-based access control
Tested on real regulation with PPI AG
In a joint proof of concept, PPI AG and Harpocrates trained the engine on auditor annotations for two EBA guidelines. Accuracy of requirement extraction and categorisation:
| Guideline | Before training | After training |
|---|---|---|
| EBA Outsourcing Guidelines (EBA/GL/2019/02) | 73% | 93.1% |
| EBA ICT Security Guidelines | 64.1% | 95.4% |
Automatic categorisation of requirements reached above 99%. Read the joint whitepaper.
How your data is handled
- Hosted on Google Cloud in Frankfurt, with customer-managed encryption keys.
- The AI runs in Google's EU region on Vertex AI.
- You choose how evidence is shared: upload files, or use our evidence protocol, which answers requests without sending your source documents.
- A person approves every AI determination, and approvals are kept in an append-only audit trail.
- Single sign-on (SAML and OIDC), multi-factor authentication and role-based access control.
- Built on the ISO 27001 and SOC 2 control frameworks. Certification is planned.
Why we built it this way: the case for keeping your documents where they are.
Start with the regulation in front of you
- Which EU regulations apply to my company?→
- Does DORA apply to my company?→
- Does NIS2 apply to my business?→
- Does the EU AI Act apply to us?→
- EU cybersecurity rules for manufacturers (CRA and NIS2)→
- What is a DPIA, and when does GDPR require one?→
- What does EU compliance software cost?→
- What does a dual-compliance system cost?→
Frequently asked questions
- What is HARPOCRATES COMPLY.Reg?
- Regulatory compliance software from Harpocrates Solutions GmbH in Berlin. It extracts individual requirements from EU and German law, each traceable to its article, merges overlapping requirements into shared controls, and manages controls, evidence and approvals in one place. A person approves every AI determination.
- Which regulations does COMPLY.Reg cover?
- EU regulations including GDPR, NIS2, DORA, the EU AI Act, the Cyber Resilience Act, MiCA, the General Product Safety Regulation and the Data Act, and German federal law such as the KWG, GwG, BSIG and BDSG. Further EU and German laws are added on request. Control libraries include ISO 27001:2022, NIST CSF 2.0 and SOC 2.
- Where is our data stored and processed?
- In the EU. COMPLY.Reg runs on Google Cloud in Frankfurt with customer-managed encryption keys, and its AI runs in Google's EU region on Vertex AI.
- Do our documents have to leave our systems?
- You choose. You can upload evidence files, or use our evidence protocol, which answers evidence requests from your own systems without sending the source documents to us.
- How accurate is the AI?
- In a joint proof of concept with PPI AG, after training on auditor annotations, extraction and categorisation reached 93.1% on the EBA Outsourcing Guidelines and 95.4% on the EBA ICT Security Guidelines. In the product, a person reviews and approves every AI output, and overrides are recorded with a reason.
- Which tools does COMPLY.Reg integrate with?
- Action items sync both ways with Jira, Azure DevOps and Trello. Controls and evidence export as OSCAL, and single sign-on works with any SAML or OIDC identity provider.
- Can we import our existing compliance spreadsheets?
- Yes. Records of processing activities, assessments and control lists can be imported from spreadsheets, and the record of processing import is AI-assisted.
- How is COMPLY.Reg priced?
- We price against your scope, meaning the regulatory regimes and legal entities you need, rather than a public list price. Tell us your regimes and entity count and we will give you a quote.
- Is COMPLY.Reg certified?
- COMPLY.Reg is built on the ISO 27001 and SOC 2 control frameworks. Certification is planned.
Ready to transform your regulatory compliance?
See how HARPOCRATES COMPLY.Reg can reduce your compliance workload, eliminate redundant efforts, and keep your organisation ahead of every regulatory change.