Shift-Left Compliance

Design-Stage Compliance Review

Most compliance review happens after there’s a product to test. Our pre-build compliance assessment happens before there is one.

Why do you need it? A compliance violation caught at the spec stage costs a scope adjustment. Caught after launch, it costs 100x to rebuild.

48-hour turnaround · European lawyer · Fixed-price engagement

EU Authorised Representative - European EU AI Act

Compliance gaps found in the spec is a sentence.
Found after launch, it’s a rebuild.

A PRD or epic can trigger obligations under three or four EU frameworks before a line of code exists. Most product teams find out after the build, when the fix is a refactor instead of a sentence in the spec.

Data collection workflows, automated decision logic, deletion flows, logging behaviour, these aren’t implementation details you clean up later. Under several EU frameworks they’re design requirements, and a requirement discovered post-deployment means re-architecting something that shipped, not editing something that hasn’t.

We work with product and engineering teams building AI-enabled or regulated digital products who want the legal read before the roadmap is committed, not a compliance audit once it’s live.

A lawyer-reviewed check against every EU framework that could reach your feature.

The EU AI Act gets the attention. The Cyber Resilience Act, DORA, the revised Product Liability Directive, the Data Act, the Digital Services Act, and the sector-specific rules behind them can all attach to the same feature before it’s built. For the full list, get a free copy of our 2026 Digital Regulatory Map.

We check the EU compliance frameworks, standards, and protocols that actually apply to what you’re submitting, not a fixed list, against your PRD before most teams have looked at any of them.

EU AI Act

Whether the feature triggers risk classification, a prohibited practice, or a technical obligation, logging, human oversight, documentation, that has to be architected in rather than added later.

Example: an epic titled “user data deletion workflow” reads as a GDPR erasure feature and stops there. Run against Art. 12(1) AI Act, the same epic can require the system be technically capable of automatic event logging. A logging policy doesn’t satisfy that, the capability has to be built in.


Cyber Resilience Act

Whether the feature introduces a vulnerability-handling, reporting, or secure-by-design duty that needs to be reflected in the architecture before build, not patched in after a security review.


GDPR

Whether the feature requires a DPIA or a data-protection-by-design decision before processing begins, not after the feature is live and processing data.

Other Applicable Frameworks

Where a feature falls under a framework outside our authored core, PLD, Data Act, sector-specific rules, it’s assessed by direct legal review, not skipped. The deliverable tells you which frameworks were engine-checked and which were reviewed by hand.


How We Work

A scoping call. A fixed-price engagement. A documented position you own. No open-ended retainers or hourly billing.

Step 1 — Scoping call (free, 15 minutes)

We confirm what you’re sending us, PRD, epic, or roadmap document, and whether this assessment is the right fit before you commit to anything.

Step 2 — Assessment

We run your document against our authored frameworks and manually review it against the rest. Deliverable: a posture report showing which obligations fire, under which frameworks, and why, plus a short memo on the trap items specific to what you’re building, provider-shift risk, grace-period forfeiture, carve-outs that look like they apply but don’t.

Step 3 — You build with the answer already in hand

No integration, no new tool for your team to log into. You get a document, your PMs write the ticket with the obligation already in it.

Shift-left compliance - pre-product design stage assessment

Find out what your next feature triggers before you build it.

A fixed-fee assessment of your PRD or roadmap, without reading the regulations yourself or logging into a separate compliance portal.

Typical turnaround: one to two business days · Fixed fee, agreed before work starts · Not a subscription

Frequently Asked Questions

Do you scan our Jira or Linear tickets automatically?

No. This is a document you send us, we assess it and send back a report. Automated ticket-level scanning is on our roadmap, it isn’t part of this engagement today, and we won’t sell it to you as if it were.

What do you need from us?

A PRD, an epic, or a roadmap document. The more concrete the feature description, the more specific the assessment. Most digital products are subject to at least three of 72+ EU frameworks simultaneously. The scoping call establishes which ones reach yours.

How is this different from a compliance audit?

An audit checks a system that’s already built and often already shipped. This pre-product assessment checks a feature before it exists, so what you get back is a design input, not a remediation list.

The honest check: 72+ frameworks, binding instruments, and standards are applicable to digital products (with or without AI), depending on what the product does, who it serves, and what sector it operates in. Good news: no single digital product is subject to all of them.

What frameworks are covered?

The AI Act is our deepest authored coverage, with the Cyber Resilience Act in active build. Frameworks outside that core are assessed by direct legal review rather than by the engine, and the deliverable tells you which is which for every item in your report.

Does this replace legal sign-off before launch?

No. It tells you what to design for before you build. What you build still needs your own final sign-off before it ships.

What does this cost, and is that the final number?

Fixed at €1,950. No open-ended retainer, no surprise invoice after delivery. If your feature or roadmap document turns out to need work outside that scope, additional systems, additional frameworks, legal representation, that’s a separate engagement, quoted and agreed with you before we start it, not added to the bill after the fact.

How long does an assessment take?

A single-system, single framework assessment delivers within two working days of completed intake. Timeline starts from receipt of a completed intake checklist, not from payment. A short scoping call precedes every engagement to confirm scope and timeline before work begins.

What do I receive at the end of an assessment?

A written assessment memo, a risk classification report, an obligation map covering every applicable Article or provision across every framework in scope, a role determination, a gap analysis ranked by enforcement risk, a prioritised remediation roadmap, and an audit-ready compliance data room setup. A deliverable you own, not a summary that lives in someone else’s system.