Capability, not marketing

What Regula covers—and what it does not

“Coverage” can mean executable decision logic, a reference mapping, or a dated regulatory summary. Those are different capabilities. This page keeps them separate so you can choose the right path and interpret the result honestly.

Reviewed 26 August 2026 · capabilities are version-specific

Three coverage levels

A higher level does not certify compliance. It means Regula implements more of the review path.

Decision support implemented

EU · South Korea · Colorado

A versioned questionnaire and evidence-gated decision model evaluate facts you declare. Detector matches remain observations, never legal facts.

  • EU AI Act
  • South Korea AI Basic Act
  • Colorado SB 26-189
Selected crosswalk references

Framework and control navigation

Findings can link to selected provisions or control families. Regula does not test applicability, implementation, equivalence, or conformity.

  • NIST and ISO references
  • OWASP, MITRE, SOC 2 and EU CRA
  • LGPD, pending Brazilian framework and UK principles
Dated regulatory tracker

Research, not executable logic

Region pages distinguish enacted law, proposals, policy, guidance and standards, with a review date and sources. They do not classify your deployment.

  • Brazil and United Kingdom
  • South Africa and UAE/GCC
  • Global comparison pages
None of these levels means “compliant”. Intended purpose, deployment, operator role, real system behaviour, governance practice and local law require evidence outside source code and accountable human review.

The supported review journey

Start from the task, preserve uncertainty, and end with a human decision—not an automated badge.

  1. Choose scope. Record jurisdiction, role, intended purpose, deployment, domain and the source tree to inspect.
  2. Declare facts. Keep who supplied each fact, when, from which source, and whether it is yes, no, unknown or not applicable.
  3. Scan locally. Review discovered, eligible, scanned, skipped, unsupported and failed files before interpreting findings.
  4. Review observations. Inspect why each signal matched and suppress or configure it with a recorded reason where appropriate.
  5. Resolve context. Answer the facts blocking the next decision; contradictions and unknowns stay visible.
  6. Prepare evidence. Generated documents are reviewer-completable scaffolds, not an audit opinion.
  7. Make an accountable decision. A qualified reviewer confirms, rejects or requests evidence Regula cannot observe.

Methods, evidence and open gaps

The test suite establishes engineering behaviour. It does not establish real-world legal or detector validity.

Reproducibility

Versioned conformance tests

Synthetic fixtures, decision-model mutations, runtime parity checks and output-contract tests are committed and repeatable.

Diagnostic evaluation

Pinned open-source corpus

Licensed repositories at exact commits test completion, repeatability and known positive/negative expectations without executing target code. This is diagnostic, not precision or recall.

Observed corpus result: 18/18 variants were byte-repeatable; 11/13 predeclared diagnostic assertions passed. Two retained failures and 10/36 completed-with-skips runs remain visible. These fractions are not accuracy metrics.

Not yet established

Independent real-world validity

Representative multi-annotator production evaluation, qualified legal validation, moderated usability research and proficient screen-reader testing remain outstanding.