Skip to content

The rigging

Regulation in,
engineering work out.
Every step auditable.

Landfall is a compliance-to-engineering tool for public bodies, banks and product teams: it reads regulatory text and turns the obligations that apply to your product into engineering work items, each carrying the article it came from.

Context intake

Describe your product. We map the regulations.

Answer questions about your service: audience, data practices, profiling, safety measures, whether it deploys an AI system. Landfall captures structured assumptions, and applicability mapping is rule-based and deterministic, so no model decides what applies to you. For the code scan, connect GitHub or GitLab (gitlab.com or self-hosted) or upload a tarball of the repository: no repository access is required.

  • Categorised assumptions: risk, safety, jurisdiction, AI role
  • Auditable record of every response
  • Rule-based applicability: same answers, same mapping
Obligation mapping

Rules decide what applies. You confirm the interpretation.

Every obligation carries trigger conditions evaluated against your answers, deterministically. AI writes only the interpretation text and an optional narrative, each labelled as AI-written and flagged with a rationale, ready for human review.

  • Obligation ID linked to regulation source
  • Applicability status with reviewer badge
  • Plain-language rationale for every decision
Engineering tickets

Obligations become engineering tickets. Automatically.

Each applicable obligation produces prioritised work items with acceptance criteria, priority levels, and full traceability back to the source regulation.

  • MoSCoW priority assignment (Must / Should / Could)
  • Search, filter, and bulk-select items
  • Push directly to Jira or your issue tracker
Export and audit

Audit-ready packages with tamper-evident integrity.

Generate audit packages, or compliance contracts that live in your codebase and are checked in CI with the @reg-to-backlog/verify CLI (npx @reg-to-backlog/verify). For a Dutch public body the pre-scan exports a draft Algoritmeregister entry, and the FRIA and DPIA tickets ask for one IAMA-aligned assessment record. Export OSCAL assessment results and component definitions for a GRC tool. Share a pre-scan with a colleague who has no account through a scope-exact guest link. Every account can turn on TOTP multi-factor authentication with backup codes.

  • Self-contained HTML audit packages, OSCAL JSON, Algoritmeregister entry
  • SHA-256 integrity verification
  • Compliance contracts verified in CI with @reg-to-backlog/verify
EU AI Act pre-scan

Classify an AI system, and show your working.

For a public body or a regulated deployer: Landfall finds the AI components in your repository, asks about your role and the Annex III area, and computes the risk tier. The classification is deterministic, the same answers always produce the same tier, and a model is only ever asked for an optional, clearly labelled explanatory paragraph.

  • Numbered rationale with an article citation on every step
  • Duties table (Art. 27 FRIA, Art. 49 registration, GDPR Art. 35 DPIA), each row printing its basis
  • Register-entry draft; where a field cannot be derived it says so

Want the step by step: approval gates, ambiguity handling, attestation?

Walk the full passage →

Built for regulated products

Bridging the gap between what the law says and what your team builds.

Five use cases, chosen when you create a project.

AI system pre-scanPrivacy / DPIAChild online safetyAccessibilitySecurity & privacy framework

Full traceability

Every work item links to an obligation, which links to specific regulation text.

Human in the loop

Ambiguities are flagged for human decision. No silent interpretations.

Integrity verification

SHA-256 hashes on every export. Cryptographically tamper-evident.

Separation of duties

Built-in analyst vs approver roles with multi-stage approval gates.

Jira, Linear and GitHub

Push work items directly. Sync status via webhooks. Verify contracts in CI with the @reg-to-backlog/verify CLI.

Hash-chained, tamper-evident audit log

Every action logged with timestamp, user and context. Each entry hashes the one before it, and an admin can verify the chain independently.

Continuous compliance

Point-in-time queries show compliance state at any historical date.

Evidence collection

The rtb-collect CLI (npm install -g @reg-to-backlog/evidence-collector) gathers evidence in your pipeline. Tracks staleness and expiry.

Policy to tests

Map test files to regulations. Prove coverage from law to code.

For Dutch public bodies

A draft Algoritmeregister entry from the pre-scan, an IAMA-aligned assessment record for the FRIA and DPIA, EU-hosted or local models behind a fail-closed residency policy, and self-hosting.

The harbour

Ready to ship
with confidence?

Create your first project in minutes. Landfall reads the regulation; your team builds the product.