Regulatory & Compliance Engineering
Compliance compiled into the build
Not legal advice — a boundary the system cannot cross, enforced by a test that fails the build the moment it's breached.
Compliance usually lives in a PDF nobody runs. We turn the regulatory boundary into executable code: the rule becomes a CI test, and if the build ever crosses the line, it fails. On Kointel, that means a Web3 module can never custody funds or initiate a transfer — a guard bans the very functions from the codebase. It's the difference between a policy and a constraint.
The policy is a document, not a control
A PDF says what must not happen. Nothing stops a developer doing it on a Tuesday — because nothing checks.
Compliance is discovered at the end
Legal review lands after the architecture is set, so the finding is "rebuild it" instead of "don't build it that way".
Data residency assumed, not architected
"We're POPIA compliant" often means nobody has traced where personal data actually goes once a third-party API is called.
Unsettled law answered with confidence
The riskiest advice is a firm answer where there isn't one. Graded authority beats a guess that reads like a ruling.
What we build
Executable compliance gates
The regulatory line encoded as a build-failing CI test — e.g. banning fund-transfer and signing calls from Web3 modules, so the system cannot custody or move funds by construction.
POPIA / FICA / FAIS engineering
Data-protection and financial-services rules built into the pipeline — POPIA erasure as a real deletion path, KYC/AML flows, and a documented Information Officer register.
AI Act & governance dossiers
EU AI Act Annex IV technical documentation, an Article 14 human-oversight gate, and GDPR retention as a scheduled job — compliance as shipped features, not promises.
Three-tier authority discipline
Every regulatory claim graded SETTLED statute / DRAFT guidance / NO AUTHORITY — and where there's no authority, we say so and stop, rather than guess.
What you walk away with
Deliverables, not a slide deck.
- Your regulatory boundary encoded as build-failing CI tests
- A data-flow map showing where personal information actually travels, including third-party calls
- POPIA/FICA/FAIS implementation: erasure as a real deletion path, consent and notification flows
- EU AI Act Annex IV technical documentation and an Article 14 human-oversight gate, where applicable
- Every claim graded SETTLED statute / DRAFT guidance / NO AUTHORITY — and where there's none, we say so and stop
How we engage
Map
We turn your obligations into bright lines a machine can check.
Encode
Each line becomes an automated gate wired into your pipeline.
Verify
Cross the line and the build fails — before anything ships.
Where it matters most
The situations this is built for.
Regulated market entry
You're shipping into South Africa or the EU and need the obligations built in rather than retrofitted.
Handling money or personal data
The line you must not cross is precise. We make crossing it fail the build.
Procurement or diligence pressure
An enterprise buyer wants evidence, not assurances. Executable gates and registers are evidence.
Proof
Kointel's no-write CI guard: the regulatory line — never custody, never initiate transfers — is a build-failing test that bans the functions outright from Web3 modules.
Questions
Model it. Prove it. Then launch.
Tell us what you're building. We'll come back with a tailored proposal.
Book a technical call