Regula documentation
August 1, 2026 · View on GitHub
Organised by the four Diátaxis documentation types, so you can find docs by what you're trying to do — learn, solve a task, look something up, or understand why.
New to Regula? Start with the Quickstart, then the course. Evaluating without installing anything? Use the browser assessment flow.
Regula is risk indication, not legal classification. Findings are flags for human review; false positives and negatives occur. See What Regula does not do.
Tutorials — learning by doing
Start here if you're new. Guided, step-by-step, first-success paths.
- Quickstart — install and get your first risk indication in one command.
- Course — a 10-part path from setup to custom patterns: setup · risk classification · scanning real code · compliance gaps · dependency security · AI security patterns · CI/CD integration · documentation · framework mapping · custom patterns.
How-to guides — solving a specific task
You know what you want to do; these give you the steps.
- Installation — pipx, uv, and pip; platform notes.
- Consultant guide — using Regula in a paid engagement, reproducibly.
- Evidence-pack guide — produce a review-ready evidence bundle for an auditor or assessor.
- DPV-AIAct export — emit the risk indication as machine-readable JSON-LD for RDF/GRC tooling.
Reference — accurate, complete, look-it-up
Dry, factual descriptions. No interpretation.
- CLI reference — every command and flag.
- Model card — the detection engine's scope, metrics, and limits.
- Precision/recall benchmark — measured precision and recall.
- Detection Rule Licence — the DRL 1.1 terms for the pattern set.
- Evidence Format v1 spec — the evidence-pack + manifest format.
Explanation — understanding why
Background, context, and trade-offs.
- Architecture — how the scanner and precision layers work.
- What Regula does not do — the honest limits (read this).
- AI governance context — how Regula fits the wider governance picture.
- Accessibility — the site/docs accessibility posture.
- Trust — what's verified, reproducibility, security and privacy posture.
- Continuity — key-person risk, honestly stated.
- Support SLA — what support to expect.
- Versioning and deprecation policy — what version numbers promise, the public API they cover, and the 1.9.0 realignment record.
Internal review, research, and planning notes are kept outside this user-facing docs tree and are not part of the published repository.