# HARPOCRATES COMPLY > AI-powered regulatory compliance platform for any organisation navigating European and related regulations — including EU, UK, Swiss, Norwegian, and national frameworks. Built in Berlin, hosted in the EU, governed by European law. ## About HARPOCRATES Solutions GmbH builds compliance infrastructure designed from the ground up for European and related regulations. Our AI-powered platform serves any organisation — European or global — that needs to navigate EU, UK, Swiss, Norwegian, and national regulatory frameworks. It monitors every regulatory source, extracts requirements automatically, and maps them to actionable controls — transforming weeks of manual compliance work into minutes. ## Products ### HARPOCRATES COMPLY.Reg — Regulatory Intelligence Platform - [Product Overview](https://harpocrates-corp.com/products/comply-reg): AI-powered regulatory monitoring, requirement extraction, and compliance workflow automation - Key capabilities: Continuous regulatory monitoring across EUR-Lex and national repositories, NLP-powered requirement extraction with 95.4% accuracy, cross-walk engine mapping 2,000+ requirements to ~250 actionable controls, automated dispatch to responsible teams - Frameworks covered: GDPR, DORA, NIS2, EU AI Act, MaRisk, ISO 27001, SOX, RED III ### HARPOCRATES COMPLY.Doc — Document Chain Intelligence (Coming Soon) - [Product Overview](https://harpocrates-corp.com/products/comply-doc): Knowledge graph engine mapping relationships between contracts, policies, and regulations - Key capabilities: Automatic chain discovery, living knowledge graph, natural language queries, visual relationship mapping ## Validation — Joint Case Study with PPI AG - [Whitepaper: A New Normal in RegTech](https://harpocrates-corp.com/resources/ppi-whitepaper): Joint case study between PPI AG and HARPOCRATES on AI-powered regulatory compliance - [Download Whitepaper (PDF)](https://harpocrates-corp.com/ppi-whitepaper.pdf): Full proof-of-concept results - Authors: Jan Jensen, Martin Förster (HARPOCRATES Solutions GmbH); Astrid Freier, Alexander Hummel (PPI AG) - Target regulations: EBA/GL/2019/02 (Outsourcing Guidelines) and EBA ICT Security Guidelines - Baseline accuracy: 73% (Outsourcing), 64.1% (ICT Security). After training with auditor annotations: 93.1% and 95.4% - Automatic categorization accuracy after training: above 99% - Processing time reduction: over 99% compared to manual analysis - Three identified use cases: (1) pre-assessment of new/amended regulation, (2) pre-screening of relevant documents, (3) completeness checks against upcoming regulation - Platform is industry- and use-case agnostic: financial services, GDPR, ESG/sustainability, automotive (UNECE), and more ## Thought Leadership — Sovereign Compliance Essays on sovereign compliance and European digital sovereignty. Hub: https://harpocrates-corp.com/thought-leadership - [What sovereign compliance actually means](https://harpocrates-corp.com/thought-leadership/what-is-sovereign-compliance): Sovereign compliance means meeting regulatory requirements over infrastructure that stays under European jurisdiction and control — distinct from data residency, which only governs where data is stored. - [Europe's missing compliance layer](https://harpocrates-corp.com/thought-leadership/europes-missing-compliance-layer): Europe is building sovereign payments and sovereign AI; the layer that interprets its regulation still runs largely on US-controlled software. - [Who interprets European law?](https://harpocrates-corp.com/thought-leadership/who-interprets-european-law): When a European institution relies on a US-controlled model to interpret European law, it delegates legal reasoning beyond European jurisdiction — the question of interpretive sovereignty. - [The sovereignty test](https://harpocrates-corp.com/thought-leadership/what-sovereign-actually-means): Four questions that separate genuine digital sovereignty from an EU region with a sovereignty label. - [Your compliance tool is a third-party risk](https://harpocrates-corp.com/thought-leadership/your-compliance-tool-is-a-third-party): Under DORA, a compliance platform that ingests a bank's documents becomes an ICT third party — often hosted outside the EU. - [The layer Europe's sovereignty push forgot](https://harpocrates-corp.com/thought-leadership/the-missing-layer-in-the-sovereignty-package): The 3 June 2026 EU Technology Sovereignty Package targets chips, cloud, and AI, but not the compliance layer that interprets European regulation. - [The case for keeping your documents where they are](https://harpocrates-corp.com/thought-leadership/why-we-dont-pull-your-documents): COMPLY.Reg inverts the industry default — it sends questions to the customer's documents rather than pulling documents into its cloud. - [The payments channel Europe built and never used](https://harpocrates-corp.com/thought-leadership/what-instex-teaches-about-dependency): INSTEX, built by France, Germany and the UK to trade around US sanctions, processed almost nothing — a lesson in structural dependency. - [Compliance outgrew the spreadsheet](https://harpocrates-corp.com/thought-leadership/compliance-was-never-a-spreadsheet-problem): Most organisations manage compliance in a spreadsheet; it breaks at scoping, translation, drafting, and change. - [When you paste a contract into an AI, who else can read it?](https://harpocrates-corp.com/thought-leadership/every-ai-prompt-is-a-disclosure): Running a document through a foreign AI transmits it to the provider, which US law can compel to disclose under the CLOUD Act. - [The wall under EU–US data transfers just moved](https://harpocrates-corp.com/thought-leadership/trump-v-slaughter-eu-us-data-transfers): A US Supreme Court ruling on FTC independence has unsettled the legal basis for moving European personal data to America. - [The Data Privacy Framework on borrowed time](https://harpocrates-corp.com/thought-leadership/data-privacy-framework-borrowed-time): The long-form, sourced analysis of how Trump v. Slaughter removed a load-bearing assumption beneath EU–US data transfers, and where the question goes next. ## Compliance Guides — Which EU Rules Apply to You Practical, answer-first guides for European businesses and for companies outside Europe that must meet EU regulatory requirements to do business in the EU. Hub: https://harpocrates-corp.com/thought-leadership - [Which EU regulations does my company need to comply with?](https://harpocrates-corp.com/thought-leadership/which-eu-regulations-apply-to-my-company): Scope which EU regulations apply by sector, size, data, and activity, with a business-type-to-regulation map; EU law also reaches many companies based outside the EU. - [Does DORA apply to my company?](https://harpocrates-corp.com/thought-leadership/does-dora-apply-to-my-company): DORA applies to EU financial entities and their ICT third-party providers and has applied since 17 January 2025; two tests decide whether you are in scope. - [Does NIS2 apply to my business?](https://harpocrates-corp.com/thought-leadership/does-nis2-apply-to-my-business): NIS2 covers medium-sized and larger entities in essential and important sectors; a sector test and a size threshold decide scope. - [Does the EU AI Act apply to us, and at what risk tier?](https://harpocrates-corp.com/thought-leadership/does-the-eu-ai-act-apply-to-us): The AI Act applies if you build or deploy AI systems; the requirements scale across four risk tiers, from prohibited uses to minimal risk. - [Non-EU company selling into the EU: what must you comply with?](https://harpocrates-corp.com/thought-leadership/non-eu-company-selling-into-the-eu): EU rules such as GDPR, the AI Act, DORA, and CE/Cyber Resilience Act requirements can reach a company with no EU establishment. - [Regulatory compliance: consultants vs. software vs. in-house](https://harpocrates-corp.com/thought-leadership/compliance-consultants-vs-software-vs-in-house): A balanced comparison of the three approaches across cost, speed, traceability, and data sovereignty. - [EU cybersecurity rules for non-EU manufacturers](https://harpocrates-corp.com/thought-leadership/eu-cybersecurity-rules-for-non-eu-manufacturers): NIS2 governs entities, the Cyber Resilience Act governs products placed on the EU market with no EU establishment required, and EU customers push supply-chain security requirements down by contract. - [How to replace compliance spreadsheets with software](https://harpocrates-corp.com/thought-leadership/replace-compliance-spreadsheets-with-software): What breaks in a compliance spreadsheet (no link from requirement to control to evidence, no ownership, no change history, no regulatory monitoring), the signals it is time to move, and a step-by-step migration one regime at a time. - [What is a DPIA, and when does GDPR require one?](https://harpocrates-corp.com/thought-leadership/what-is-a-dpia-and-when-is-it-required): A DPIA is required under GDPR Article 35 before processing likely to result in a high risk to people's rights; covers the three automatic triggers, national authority lists, the four required contents, DPO sign-off, and Article 36 prior consultation. - [What does EU compliance software cost?](https://harpocrates-corp.com/thought-leadership/what-does-eu-compliance-software-cost): There is no single price — cost scales with the number of regimes, legal entities, member states, users and evidence volume. Covers the pricing models and how to compare against consultants, in-house headcount and spreadsheets. - [PIAs, DPIAs, and death by spreadsheet](https://harpocrates-corp.com/thought-leadership/pia-dpia-death-by-spreadsheet): The difference between a PIA and a GDPR Article 35 DPIA, why DPIA duties are national in practice, why DPIAs fail on process not content, and why a spreadsheet cannot hold a living register of processing (RoPA). ## Key Pages - [Homepage](https://harpocrates-corp.com): Company overview and value proposition - [About](https://harpocrates-corp.com/about): Mission, founders, and European identity - [PPI AG Whitepaper](https://harpocrates-corp.com/resources/ppi-whitepaper): Independent validation results - [Contact](https://harpocrates-corp.com/contact): Get in touch or book a demo ## Regulations Covered - NIS2 Directive (Network and Information Security) - GDPR (General Data Protection Regulation) - DORA (Digital Operational Resilience Act) - EU AI Act (Artificial Intelligence Regulation) - MaRisk (Minimum Requirements for Risk Management — German banks) - MiCA (Markets in Crypto-Assets) - ISO 27001 (Information Security Management) - UK regulations, Swiss FINMA requirements, Norwegian financial regulations, and national transpositions ## Company Facts - Founded in Berlin, Germany - All data hosted exclusively in the European Union - GDPR by design, EU AI Act compliant - Founders: Jan Jensen (30 years in financial services and technology) and Martin Foerster (28 years in data and AI) ## Contact For enterprise inquiries: [Contact](https://harpocrates-corp.com/contact) Email: info@harpocrates-corp.com LinkedIn: https://www.linkedin.com/company/harpocrates/