Screen reference — the compliance portal
Every screen of the compliance team’s portal — claim, fill, DORA, unlock, sign, account, team — with each one shown by the one region it exists for, and its other controls named in the text. Use it to look one thing up. To be walked through it as a lived compliance-team session, start with the walkthrough The compliance team →.
Opening a claim & signing in
The engineer’s regixo invite produces a link like
app.regixo.com/claim/clm_<token> and a RoPA_DRAFT.pdf. Opening the
link needs no account — reading is free. Everything lives on that one page, laid out as a
dossier: a sticky rail on the left — Forwarded artifacts (Record (RoPA) ·
DORA register), Sign in to fill, Where this stands, and In this dossier, a
contents list that reaches every activity and annex — and the document itself beside it: the
letterhead, the activities in order, then the annexes (the paid step, your team, connect a machine).
There is no separate “fill”, “team” or “record” address.
The document opens on its letterhead — GDPR · Art. 30 · Record of Processing — drafted from your own systems, Record of Processing Activities, and the DRAFT stamp — then a “Read this first” block ending on the provenance line: what left their machine: metadata only … No column names or row values, ever. It is honest, up front, about what it does not cover: a coverage banner names every source that was unreachable at the last scan.
GDPR · Art. 30 · Record of Processing — drafted from your own systems
Record of Processing Activities
Read this first
- What this is — the list of how your company uses people’s personal data — the “Record of Processing” most EU organisations must keep.
- Where it came from — your engineering team mapped the sources they configure with Regixo, which drafted this from their schemas.
- What’s done — the data inventory is mapped for you.
- What needs you — 10 legal calls are still blank — purpose, your lawful basis, retention and transfers. Your team fills them below; then you sign.
- Your privacy — what reached this page is metadata only: the drafted record, the names of the 4 tables behind it, and counts. No column names, no column types, no row values — they never left your team’s machine.
- What’s not covered —
snowflake-dwh,stripe(unreachable at the last scan).
Forwarded draft — received 2026-07-10 · what left their machine: metadata only — the names of the 4 tables these activities are built from, the drafted record, and counts (4 datasets · 9 personal-data flags). No column names or row values, ever. No account needed to review. · what changed → · who is Regixo? →
Signed out, a needs you field is a link, not a form: + Fill this jumps to the sign-in block on the same page. To fill fields or manage your team, sign in: enter your work email and press Email me a sign-in link (or use SSO where configured). The link is one-time and lasts 15 minutes. Because corporate mail scanners open links, you’ll first see a “Confirm it’s you” page — press Continue to sign in → (that’s what actually consumes the link).
The record & the fill surface
The record lists your activities as numbered document sections — 1 / 3 · Manage customer accounts, its tables underneath, and a counted badge (2 open calls, or ✓ none open). The Article 30 fields sit in a table below, always open, each badged needs you / suggested / confirmed (mechanical facts show found; special-category rows carry ⚠ Art. 9). Once you sign in, each of those rows grows its own inline editor — below, the open Lawful basis row on Manage customer accounts, as an approver sees it:
Manage customer accounts
2 open callsaccounts · customers
| Lawful basis | You need it to provide your product or service. Art. 6(1)(b) contract suggested + Fill this |
|---|
A person confirms legal fields — not Regixo.
- Open it with + Fill this (empty) or ✎ edit (filled).
- Lawful basis → a picker “— pick an Art. 6(1) basis —” listing all six grounds, plus a free-text “…or type the basis in your own words”.
- Art. 9(2) ground (only on special-category rows) → “— pick an Art. 9(2) ground —” with all ten.
- Purpose · Retention · Transfers · Security · Recipients · Data subjects → free-text (Recipients placeholder “e.g. Stripe, AWS, Intercom”).
Who can do what is role-gated: a preparer fills a field (it saves as “provided by you”); an approver (or admin) sees the checkbox “Confirm as legally reviewed — you act as approver; Regixo never confirms a legal field for you.” and can Revert to Regixo’s suggestion. Every activity closes on a folded “A person confirms legal fields — not Regixo.” note, and the document ends on a Schedule — open items on this record, whose index moves through Still needs you → Awaiting confirmation → Nothing still needs you, so nothing is missed.
regixo annotate … --confirm; the full field-by-field guidance is in
Fill the RoPA.DORA fill
The DORA register tab in the rail carries its own count — “4 of 15 sections started” — and the page is 15 sections (B_01.01 … B_99.01), each badged auto-filled / partly auto / needs you. Signed out you can read all of it: a cell you’d have to fill reads “sign in to fill”, a call only an approver may make reads “sign in to rule”, and an empty table reads “No rows yet — sign in to add”.
This is your DORA Register of Information, forwarded with the record — the free DRAFT. Turning it into the checked, sealed xBRL-CSV (the €12,000 plan) is done on your engineer's own Regixo, not on this forwarded record. The split: you fill the cells and rule the scope calls here; they run the export and send you the finished package.
Why draft from your real systems: in the European Supervisory Authorities’ DORA dry-run exercise, only about 6.5% of manually-built registers passed all 116 validation checks.
Your company
2 / 3 startedWho keeps this register · Entity maintaining the register of information
partly autoAdd your organisation’s registered name, LEI, country, entity type, competent authority and reporting date (org profile).
| LEI | Entity name | Country | Entity type | Authority | Reporting date |
|---|---|---|---|---|---|
| 5493001KJTIIGC8Y1R12 provided | Aurelia Payments Oy provided | FI provided | sign in to fill | sign in to fill | sign in to fill |
Signed in, each needs-you cell becomes an inline form (“add…” + Save); contract and
function tables get + Add a row. To fill many at once, use the CSV path: Download the
template (CSV) → Upload & preview → a check page (“Check these rows before they save …
Nothing is saved yet”, showing “Updates row X / Adds a new row”, skipping bad LEIs) → Apply N
rows. LEI cells are checked (ISO 17442 + mod-97) with a GLEIF pointer. Ruling a provider
confirm / exclude in scope, and marking a function’s criticality, are
approver-only acts (a legal judgment). CLI twins: regixo dora import/set; details
in The DORA register.
Check these rows before they save
2 rows from your file ready to save to Your IT third-party providers B_05.01. Nothing is saved yet — rows save when you apply them, each cell marked “provided”.
Skipped from the file: In DORA scope?
Your approver rules these on the row itself — they’re not written from a file. Everything else in those rows still saves.
Columns not on this table (ignored): notes.
- Row 4 — LEI fails its check digits (ISO 17442 mod-97) — row skipped
Look up an LEI on GLEIF search ↗ — the public register of legal-entity identifiers.
| Row reference | Legal name | Service type | HQ country | Provider code | What happens |
|---|---|---|---|---|---|
| stripe | Stripe | Payment processing | US (outside EU) | 5299007QVIQ7IO1L0962 | Updates row stripe |
| datadog | Datadog | Monitoring | EU | 5493001KJTIIGC8Y1R12 | Adds a new row |
Unlock & pay
Read this first: checkout is wired and offline-tested, but the live card-payment run is a launch gate — not switched on yet, so a licence may be issued by invoice today (Enterprise always is). The draft stays free either way. This is the flow it will run.
Inside “Make this record official,” two questions set your plan and its published price —
“How big is your organisation?” and “Are you a regulated financial firm (DORA applies)?”.
The price appears once both are answered (RoPA €6,000/yr · RoPA + DORA €12,000/yr ·
Enterprise from €18,000/yr, invoice). Press Continue to payment (card, via Stripe);
an overlay explains you’ll enter your card on Stripe’s secure page (“Regixo never sees or stores
them”). After returning you’ll see “✓ Payment received — activating your licence…”, then a receipt
with a downloadable invoice. On a €12k purchase the portal shows the engineer’s licence key to set as
REGIXO_LICENCE_KEY.
Choose your plan & pay
Regixo attests mechanical facts only — purpose, lawful basis and retention are confirmed and signed by you. This is not legal advice.
The block ends with a way out that isn’t a payment: “Prefer to talk it through first?” — Email us →, “a person answers. No obligation; the draft stays free either way.” On a record that already carries a licence, step 2 reads instead “Your plan is set by the licence on this record — nothing to choose or pay.”
Launch gate: checkout is wired and offline-tested; the live card-payment run
isn’t switched on yet, so a licence may be provided by invoice today (Enterprise always is). The CLI
twin (licence-key activation) is regixo verify.
Sign & seal
Signing is the last step — approver or admin only. A “Before you sign” gate names what you are about to do (it removes the DRAFT stamp and records a simple electronic signature under your name — not a qualified electronic signature), lists every legal entry still open, and states that those seal as flagged gaps: the seal never confirms one for you. It also names the controller (required, Art. 30(1)(a)) and asks for the registered legal name if your organisation isn’t named yet.
Before you sign
You are about to sign and seal this record as Dana Kessler (dana@acme.eu). This removes the DRAFT stamp and records a simple electronic signature (eIDAS Art. 25(1)) under your name.
- Manage customer accounts — lawful basis
- Manage customer accounts — security measures
- Uncategorised processing — purpose
- Uncategorised processing — lawful basis
- Uncategorised processing — retention
- Uncategorised processing — security measures
- Take and record payments — security measures
Press 🔓 Sign & seal and the record becomes OFFICIAL — the DRAFT stamp is gone and the page carries the seal block: Who signed · Timestamp · What kind of signature · the tamper-evident seal row · what’s still left for you · Your record, a “Technical details (for your auditor)” panel (sha256 content seal, attestation id, offline verifier), and Download the official PDF. Until the RFC 3161 counter-stamp is switched on (a launch gate), the timestamp row says so in as many words — vendor clock only:
✓ Sealed · 11 Jul 2026 — 7 legal calls below still need confirming
● OFFICIAL — signed & sealed
- Who signed — Dana Kessler, Data Protection Officer of Acme Europe BV — dana@acme.eu, on 11 Jul 2026, 14:02:00 UTC. Identity verified by an email sign-in link.
- Timestamp — The signing time comes from Regixo’s own server clock. No independent counter-stamp is attached. attestation.json records the authoritative timestamp status.
- What kind of signature — A simple electronic signature. Under eIDAS (Art. 25(1)) it cannot be denied legal effect solely because it is electronic. It is not a qualified electronic signature.
- Tamper-evident seal — Locked: any later edit re-opens the signature. Anyone can check it’s genuine offline, without contacting us — see “Technical details”.
- What’s still left for you — 7 legal boxes below still need your confirmation, flagged in the record. The seal never confirms a legal call for you.
- Your record — Plan ropa · valid until 11 Jul 2027. Manage billing →
Technical details (for your auditor)
Content seal sha256:9f2c4d7a1b6e8035c9a2f4d7b1e6803559f2c4d7a1b6e8035c9a2f4d7b1e68035 — any later edit re-opens the signature.
Attestation att_7b3c9d1e5f2a8046b1c7 · key regixo-attest-prod-20260714 · tenant ten_acme.
Verifiable offline: run node verify-attestation.mjs next to the exported attestation.json (key published in ATTESTATION_KEYS.md).
This attestation states a mechanical fact: the auto-filled fields were taken from Regixo’s index of metadata read from the connected systems, as that index stood when this record was generated on 10 Jul 2026. The legal fields (purpose, lawful basis, retention, transfers) are the signatory's to decide. The seal covers the record as it stands; it never confirms a legal call. This document is not legal advice.
A Version history card lists every seal with “what changed” diffs. If the data drifts after
signing, a banner flags “N activities need RE-SIGN” with Review & re-sign → (Regixo
never re-signs for you). CLI twins: regixo verify, regixo seal pull.
Full detail: Unlock, sign & maintain.
Account & billing
The account chip in the masthead (your initials + email) opens the cluster — Profile & sign-in · Notifications · Org profile · Billing — and every page of it carries that same left-hand nav:
- Profile & sign-in — edit the Name shown on a seal; see your verified email and SSO status; Sign out everywhere; request account closure (the operator actions it — never self-serve deletion).
- Notifications — “Email me about” toggles (Licence expiring, Re-signing, Sync stale, Annual review, DORA reference date, Draft activity, Product updates). Quiet by default: the operational alarms are on, while Draft activity — one email a day at most when a DRAFT record you claimed receives an engineer update — and Product updates are off until you switch them on. Receipts and sign-in links are always sent.
- Org profile — registered entity, LEI (checksum-validated), country, data-protection contact, default security measures. Filling these across several records at once isn’t built — set the org profile on each record.
- Billing — one row per record: plan, status (Active / Expires in N days / Expired), and actions — Renew →, Upgrade to RoPA + DORA → (pay the €6,000 difference, expiry unchanged), and Billing in Stripe → (the Stripe Customer Portal — update the card, download invoices; there’s no subscription to cancel).
Team & roles
Admins manage the team from an annex sheet at the foot of the record — Your team (“Roles are per record, never global”), reachable from In this dossier in the rail:
Annex B
Your team
Who can do what on this record. Roles are per record, never global.
- Viewer — can read the record.
- Preparer — read, and fill in the draft (RoPA legal fields & DORA cells), saved as “provided by you”.
- Approver — everything a preparer can, plus the legal acts: confirming a field, ruling a DORA provider in/out of scope, and signing.
- Admin — manages the team (adds people, sets roles), and can do everything an approver can, including signing.
- Handing over — before you leave, promote your successor to admin first. The last admin can never be removed or demoted, so the record is never left without an owner.
| dana@acme.eu | admin | you · added 2026-07-03 |
| omar@acme.eu | approver | change role |
Activity log → every touch of this record, in the append-only ledger your licence includes.
| Role | Can |
|---|---|
| Viewer | Read the record. |
| Preparer | Read, and fill the draft (RoPA fields & DORA cells) — saved “provided by you”. |
| Approver | Everything a preparer can, plus the legal acts: confirm a field, rule a DORA provider in/out of scope, and sign. |
| Admin | Manage the team (add people, set roles). The last admin can’t be removed — promote a colleague first. |
Add a colleague with Send invite (default viewer). Machine tokens live on the next annex
sheet, “Connect a machine (keep the record current)”: admins Generate a machine token there
(ingest-only rgx_sync_*, shown once, can never unlock or sign) for automated
syncs. SSO status shows here and on Profile; connecting your IdP is operator/config work, not an
in-portal screen yet.
Activity log
Admins and approvers get an Activity log — what happened to this record: views, fills, confirmations, sign-ins, payments, seals, downloads. The portal offers no way to change or delete a line of it. It is not a cryptographic proof, and the page says so: it is a log Regixo keeps on its own server, so it shows you what happened but cannot prove to you that Regixo did not alter it. The thing that proves itself without trusting Regixo is the sealed record — it carries its own verifier and checks offline. The Activity log is distinct from the What changed feed (which tracks changes in your systems as each re-scan reports them).
Activity log
What happened to this record — views, fills, confirmations, sign-ins, payments, seals, downloads. Nothing in the portal edits a line of it or removes one. Two limits, stated plainly: erasing a record erases its log with it, and a record your engineer re-sends starts a fresh log.
What it is not is a cryptographic proof. It is a log we keep on our own server, so it can show you what happened — it cannot prove to you that we did not change it. The thing that proves itself without trusting Regixo is your sealed record: it carries its own verifier and checks offline, on your machine.
| When (UTC) | Who | What | Detail |
|---|---|---|---|
| 2026-07-11 14:02 | dana@acme.eu | seal.create | Record signed & sealed · RoPA |
| 2026-07-11 13:58 | dana@acme.eu | payment.received | RoPA · €6,000 · Stripe |
| 2026-07-10 09:20 | omar@acme.eu | field.confirm | Lawful basis · Manage customer accounts |