The rigging
Regulation in,
engineering work out.
Every step auditable.
Landfall is a compliance-to-engineering tool for public bodies, banks and product teams: it reads regulatory text and turns the obligations that apply to your product into engineering work items, each carrying the article it came from.
Describe your product. We map the regulations.
Answer questions about your service: audience, data practices, profiling, safety measures, whether it deploys an AI system. Landfall captures structured assumptions, and applicability mapping is rule-based and deterministic, so no model decides what applies to you. For the code scan, connect GitHub or GitLab (gitlab.com or self-hosted) or upload a tarball of the repository: no repository access is required.
- Categorised assumptions: risk, safety, jurisdiction, AI role
- Auditable record of every response
- Rule-based applicability: same answers, same mapping
Does your product target or is it likely to be accessed by users under 18?
Does your product use algorithmic profiling or recommendations?
→ assumptions recorded
Rules decide what applies. You confirm the interpretation.
Every obligation carries trigger conditions evaluated against your answers, deterministically. AI writes only the interpretation text and an optional narrative, each labelled as AI-written and flagged with a rationale, ready for human review.
- Obligation ID linked to regulation source
- Applicability status with reviewer badge
- Plain-language rationale for every decision
Product uses algorithmic recommendations for minors
Product collects personal data from minors
Product does not display advertising
Obligations become engineering tickets. Automatically.
Each applicable obligation produces prioritised work items with acceptance criteria, priority levels, and full traceability back to the source regulation.
- MoSCoW priority assignment (Must / Should / Could)
- Search, filter, and bulk-select items
- Push directly to Jira or your issue tracker
Audit-ready packages with tamper-evident integrity.
Generate audit packages, or compliance contracts that live in your codebase and are checked in CI with the @reg-to-backlog/verify CLI (npx @reg-to-backlog/verify). For a Dutch public body the pre-scan exports a draft Algoritmeregister entry, and the FRIA and DPIA tickets ask for one IAMA-aligned assessment record. Export OSCAL assessment results and component definitions for a GRC tool. Share a pre-scan with a colleague who has no account through a scope-exact guest link. Every account can turn on TOTP multi-factor authentication with backup codes.
- Self-contained HTML audit packages, OSCAL JSON, Algoritmeregister entry
- SHA-256 integrity verification
- Compliance contracts verified in CI with @reg-to-backlog/verify
sha256 · 8f3a92c1d47e…b19c
Classify an AI system, and show your working.
For a public body or a regulated deployer: Landfall finds the AI components in your repository, asks about your role and the Annex III area, and computes the risk tier. The classification is deterministic, the same answers always produce the same tier, and a model is only ever asked for an optional, clearly labelled explanatory paragraph.
- Numbered rationale with an article citation on every step
- Duties table (Art. 27 FRIA, Art. 49 registration, GDPR Art. 35 DPIA), each row printing its basis
- Register-entry draft; where a field cannot be derived it says so
→ codebase scan · AI components
Art. 6(2) with Annex III pt 5(a) — an Annex III area other than none was selected.
Want the step by step: approval gates, ambiguity handling, attestation?
Walk the full passage →Built for regulated products
Bridging the gap between what the law says and what your team builds.
Five use cases, chosen when you create a project.
Full traceability
Every work item links to an obligation, which links to specific regulation text.
Human in the loop
Ambiguities are flagged for human decision. No silent interpretations.
Integrity verification
SHA-256 hashes on every export. Cryptographically tamper-evident.
Separation of duties
Built-in analyst vs approver roles with multi-stage approval gates.
Jira, Linear and GitHub
Push work items directly. Sync status via webhooks. Verify contracts in CI with the @reg-to-backlog/verify CLI.
Hash-chained, tamper-evident audit log
Every action logged with timestamp, user and context. Each entry hashes the one before it, and an admin can verify the chain independently.
Continuous compliance
Point-in-time queries show compliance state at any historical date.
Evidence collection
The rtb-collect CLI (npm install -g @reg-to-backlog/evidence-collector) gathers evidence in your pipeline. Tracks staleness and expiry.
Policy to tests
Map test files to regulations. Prove coverage from law to code.
For Dutch public bodies
A draft Algoritmeregister entry from the pre-scan, an IAMA-aligned assessment record for the FRIA and DPIA, EU-hosted or local models behind a fail-closed residency policy, and self-hosting.
Ready to ship
with confidence?
Create your first project in minutes. Landfall reads the regulation; your team builds the product.