Why RegLens.

Most compliance tools are built around a specific regulator (SOC 2, HIPAA) or built for enterprises that already have a mature GRC program. RegLens is built for the messy middle — sub-200-employee financial services orgs and the SaaS providers they rely on, operating under a stack of federal + provincial + international regulators simultaneously.

Differentiation.

The full side-by-side. RegLens vs generic GRC platforms vs consultant retainers.

AxisRegLensGeneric GRC platformConsultant retainer
ModelSaaS subscription, self-serviceEnterprise license + implementationHourly billable + retainer
Multi-regulator scopeNative across 14 regulations, 4 jurisdictionsBolt-on per regulatorPer-engagement scoping
Real evidence trackingPer-control attachment + freshness + gap indicatorsDocument repository (mostly)Delivered as deliverable at close
Regulator-specific evidenceSame control, different expected evidence per regulator; 13 authored overridesSingle evidence set per controlCustom per engagement
Time to first regulatory-scope answerOne assessment session; single-digit hoursWeeks-months implementationWeeks-months engagement
Suitability for sub-200-employee orgsPurpose-built for this segmentOptimized for enterprise scaleCost profile scales awkwardly at small scale
Corpus depth57 controls, 220 evidence expectations, 27 applicability rulesVaries; often shallow beyond flagship regulatorScoped per engagement
Assessment history + trend visibilityEvery completion snapshotted; dashboard trend chartDepends on moduleHistorical continuity depends on engagement continuity
Self-service vs consultant-mediatedFull self-service; consultant unnecessaryImplementation typically consultant-ledConsultant-mediated by definition
Cost profile (rough band)Low-to-mid four figures/year at pilot pricingFive-to-six figures/year enterprise-gradeFive-to-six figures/year retainer + variable billables

Multi-regulator scope is the point.

Financial services orgs don't operate under one regulator. A federally-regulated Canadian bank with US customers is simultaneously subject to OSFI (federal), Quebec's Law 25 (provincial extraterritorial), CCPA (California residents), and NYDFS §500 if any customers touch NY-DFS-regulated services. Adapting a single-regulator tool to cover this stack produces gaps.

RegLens was built for the stack from the ground up. Every organization profile captures operational jurisdictions + customer jurisdictions + entity type + activity flags. The applicability engine evaluates every rule against that combined profile — the answer is which regulations apply to your specific scope, not a generic checklist.

Real evidence tracking, not just checklists.

Checkbox self-attestation isn't evidence. RegLens tracks actual artifacts — a filed notification, a signed policy, a completed audit report — attached to specific controls with freshness expectations sourced from what each regulator actually asks for.

Every attached evidence item carries: description, optional link to file, matched-to-corpus-expectation, freshness in days, and expiration date. Expiring evidence surfaces on the dashboard. Missing evidence renders in the readiness package with an "expected but not yet attached" line — so you know what you'd still need to produce for a regulator inquiry.

Regulator-specific evidence when it matters.

The same control ("regulator notification for material cyber incidents") means different things across regulators. DORA's Article 19 expects an initial notification by end of the business day plus intermediate + final reports. OSFI's B-13 advisory expects 24-hour notification plus situation updates. GDPR's Article 33 expects a 72-hour notification with defined content elements.

RegLens models this divergence explicitly — same control, different expected evidence per regulator. 13 such overrides are currently authored, with more added as we work through the corpus. Regulator-specific overrides render regulator-specific expected artifacts in the readiness package.

Safe-scope discipline.

When you tell RegLens "we have Canadian customers," we default to including all Canadian provincial regulations — QC-LAW-25 (Quebec), PIPA BC (British Columbia), PIPA AB (Alberta) — unless you affirmatively narrow. Under-inclusive scope is a compliance surprise. Over-inclusive scope is a bit more evidence-gathering.

The discipline is codified in our conventions doc and empirically validated: during a recent vocabulary reconciliation cycle, 7 of our authoring orgs had regulations silently missing from their applicability output. The safe-scope discipline caught the gap; the reconciliation corrected it. Every regulation that attaches to your organization renders a trigger reason — you can always see why.

Assessment history and dashboard visibility.

Compliance readiness isn't a point-in-time snapshot. RegLens captures an immutable snapshot at every assessment completion — composite posture, per-regulator RAG state, applicability set, methodology version. The dashboard shows current cockpit + regulator strip + what moved since last assessment + trend over time.

Combined with next-action prompts (expiring evidence, applicability changed, red-state regulator requires attention), the dashboard converts static reports into continuous readiness state.

Ready to see your scope?

Complete the onboarding wizard and RegLens produces your applicable regulator list, control mapping, and readiness baseline in one session.