Regulatory & Compliance Engineering

Compliance compiled into the build

Not legal advice — a boundary the system cannot cross, enforced by a test that fails the build the moment it's breached.

Compliance usually lives in a PDF nobody runs. We turn the regulatory boundary into executable code: the rule becomes a CI test, and if the build ever crosses the line, it fails. On Kointel, that means a Web3 module can never custody funds or initiate a transfer — a guard bans the very functions from the codebase. It's the difference between a policy and a constraint.

The policy is a document, not a control

A PDF says what must not happen. Nothing stops a developer doing it on a Tuesday — because nothing checks.

Compliance is discovered at the end

Legal review lands after the architecture is set, so the finding is "rebuild it" instead of "don't build it that way".

Data residency assumed, not architected

"We're POPIA compliant" often means nobody has traced where personal data actually goes once a third-party API is called.

Unsettled law answered with confidence

The riskiest advice is a firm answer where there isn't one. Graded authority beats a guess that reads like a ruling.

What we build

Executable compliance gates

The regulatory line encoded as a build-failing CI test — e.g. banning fund-transfer and signing calls from Web3 modules, so the system cannot custody or move funds by construction.

POPIA / FICA / FAIS engineering

Data-protection and financial-services rules built into the pipeline — POPIA erasure as a real deletion path, KYC/AML flows, and a documented Information Officer register.

AI Act & governance dossiers

EU AI Act Annex IV technical documentation, an Article 14 human-oversight gate, and GDPR retention as a scheduled job — compliance as shipped features, not promises.

Three-tier authority discipline

Every regulatory claim graded SETTLED statute / DRAFT guidance / NO AUTHORITY — and where there's no authority, we say so and stop, rather than guess.

TypeScriptCI gatesCloudflare D1POPIAEU AI ActGDPR

What you walk away with

Deliverables, not a slide deck.

  • Your regulatory boundary encoded as build-failing CI tests
  • A data-flow map showing where personal information actually travels, including third-party calls
  • POPIA/FICA/FAIS implementation: erasure as a real deletion path, consent and notification flows
  • EU AI Act Annex IV technical documentation and an Article 14 human-oversight gate, where applicable
  • Every claim graded SETTLED statute / DRAFT guidance / NO AUTHORITY — and where there's none, we say so and stop
0
custody / transfer functions
3-tier
authority discipline
1
build-failing compliance gate

How we engage

01

Map

We turn your obligations into bright lines a machine can check.

02

Encode

Each line becomes an automated gate wired into your pipeline.

03

Verify

Cross the line and the build fails — before anything ships.

Where it matters most

The situations this is built for.

Regulated market entry

You're shipping into South Africa or the EU and need the obligations built in rather than retrofitted.

Handling money or personal data

The line you must not cross is precise. We make crossing it fail the build.

Procurement or diligence pressure

An enterprise buyer wants evidence, not assurances. Executable gates and registers are evidence.

Proof

Kointel's no-write CI guard: the regulatory line — never custody, never initiate transfers — is a build-failing test that bans the functions outright from Web3 modules.

Read the case study

Questions

Model it. Prove it. Then launch.

Tell us what you're building. We'll come back with a tailored proposal.

Book a technical call