Bring your MiFIR/SFTR reports. A deterministic engine of real ESMA validation rules checks every field against the authoritative sources — GLEIF, FIRDS, ISO — as of the trade date, catches the valid-but-wrong errors a format checker can't see, traces where each field broke, and seals audit-ready evidence. It runs in your own Azure tenant; your data never leaves.
Today they're answered with custom Java harnesses, Kafka scripts, SQL, spreadsheets, Jira tickets and SME investigation — slowly, inconsistently, and with weak evidence when the regulator asks. And the downside is not small: transaction-reporting failures have drawn some of the largest regulatory fines — tens of millions — for firms whose controls missed the breaks.
Taxonomy-driven and deterministic at the core; AI only where it's checked. The same run works on a laptop in simulator mode or against a bank's real SIT/UAT pipeline — no re-architecture.
Synthetic trades and lifecycle events across MiFIR & SFTR — checksum-valid identifiers, real venues, RTS 22 field-consistent, every reporting edge case.
Push them through a reporting pipeline — Kafka, data lake, enrichment, reporting engine, ARM/TR — real or mocked.
Every field against real ESMA validation rules and the authoritative reference data (GLEIF, FIRDS, ISO) — format errors, cross-field & CFI-conditional breaks, and the valid-but-wrong ones, plus T+1/T+10 deadlines.
Field-level lineage: for each break, where the value came from, what it was checked against (as-of the trade date), and where in the chain it broke — cited to the exact RTS 22 / ESMA rule.
Human-approved, hash-chained evidence packs, stamped with the exact ruleset version that produced the verdicts. Audit-ready PDF and JSON, immutable once sealed.
Agents that attack and test the deterministic core can only produce false alarms. Agents that act in the pipeline could produce false reports. So RegLab is maximally agentic on the attack side — and keeps zero agent authority on the act side.
Every AI explanation cites the exact evidence it used, or abstains. When many trades break at once, a systemic investigation clusters them, hypothesises one root cause, and an independent judge panel verifies it before a human ever sees it. Nothing is decided by AI — it's proven, checked, and human-approved.
Paste a CSV of your own MiFIR/SFTR reports. The deterministic engine says exactly which would be rejected and why — cited to the real ESMA rule — and flags T+1 breaches. A free, read-only sweep of your reporting quality.
When a bad release breaks 97 trades, RegLab reports one root cause — not 97 defects — verified across completeness, parsimony and grounding by an independent judge panel.
Dozens of validation rules across nine predicate kinds — format, cross-field, CFI-conditional (Set 8), date-consistency — mapped to the real ESMA CON codes, over a computed slice of the 65-field RTS 22 report. Adding a rule is config, not code.
Every LEI against GLEIF, every instrument against FIRDS, every MIC and currency against the ISO lists — as of the trade date, not a checksum proxy. The reference-data breaks a real ARM would raise.
Self-dealing, an option type that contradicts its instrument, a DEAL that isn't on own account, a maturity before the trade — schema-valid reports that are factually wrong. A format checker passes them; the engine doesn't.
Every finding becomes a human-approved, SHA-256 hash-chained evidence pack with separation of duties. Recompute the hash any time; the chain verifies or it doesn't.
Breadth is measured against a canonical trade taxonomy, never asserted. Adding a trade type is configuration, not code. See exactly what's covered and what isn't.
Simulator mode needs zero infrastructure. Non-prod injection tests a real SIT/UAT Kafka pipeline. Production shadow observes read-only. Same engine throughout.
Explanations draft on your own Azure OpenAI deployment — the model never leaves your boundary. Rule-based fallback means the lab never blocks on a model.
Nobody combines synthetic trade generation, pipeline testing, break intelligence and sealed evidence for MiFIR/SFTR. We test controls — we never replace your reporting engine.
Paste your reports, get cited findings and a sealed evidence pack in minutes — or run a 100-scenario pack and watch the whole pipeline tested live. Read-only, in your own tenant.
This live demo runs open on synthetic data. Production is authenticated (Clerk), tenant-isolated (Postgres row-level security), and deployable in your own Azure tenant — the AI runs in-tenant; your data never leaves.