Reversa logo
Gov Legal · Legal Assistants

Reversa

Reversa is an AI-powered regulatory intelligence platform whose sector-trained agents identify the rules that apply to an organisation, interpret them against its actual operations, flag every change, and carry the resulting decision through to implementation.

Active GDPR compliant Contact Sales No public API Verified by Guidaio
Overview

What is Reversa?

Reversa is a regulatory intelligence platform built by a Madrid technology company that describes its ambition as building the infrastructure for regulation. Its central claim is not speed but scope: where most software delivers information and most professional services deliver interpretation through lengthy consultation, Reversa says it carries a regulatory problem from identification through to resolution. Its AI agents run the whole chain, identifying which rules apply to an organisation in every jurisdiction where it operates, interpreting them, filtering them against that organisation's actual operations, informing the resulting decision, and supporting implementation.

The company began as a regulatory radar and no longer defines itself that way. It draws three distinctions from conventional monitoring tools. Matching is contextual rather than lexical: sector-specialised agents read each regulation against the business context instead of retrieving documents by keyword, which the company says surfaces tangential references that a keyword search, and often an experienced analyst, would miss. Coverage spans the full regulatory lifecycle, from a proposal first appearing before a legislature through to enforcement and the operational response. And every capability sits in one platform rather than a collection of disconnected tools.

Three modules carry the product. Regulatory Map builds a personalised picture of what applies, based on industry, jurisdictions and activities, with coverage advertised across Europe and the Americas. Agentic Radar reads thousands of new documents every day and explains which ones affect the organisation and why. Legislative Twins maintains a living twin of every EU legislative procedure, from Commission proposal to Official Journal publication, following rapporteurs, votes and amendments in real time.

Reversa reports that client teams spend roughly 90% less time on regulatory information and analysis, and cites a report produced in 44 seconds that had previously required two weeks of law firm work, surfacing 14 gaps and contradictions that had gone undetected. Those figures are published by the vendor and are not independently verified. It names multinationals, public affairs consultancies, Big Four firms and international law firms among its users, and lists membership of the NVIDIA Inception Program, Google for Startups and A&O Shearman's Fuse programme. Access is through a browser-based platform, in English and Spanish.

What it does

  • Map the regulations that genuinely apply to your industry, jurisdictions and business activities
  • Monitor thousands of official sources daily and receive alerts explaining why each one affects you
  • Track EU legislative procedures from Commission proposal through to publication in the Official Journal
  • Assess the operational impact of a regulatory change on your specific business
  • Extract and follow the obligations arising from a given text
  • Produce client-ready reports and automated summaries
  • Determine the regulatory path before entering a market or launching a product
Audience

When to use Reversa / When not to

A quick filter to help you decide if Reversa is the right fit.

When to use Reversa

  • Compliance and legal teams replacing three to six full-time roles spent on manual monitoring in spreadsheets and keyword alerts
  • Public affairs consultancies and trade associations running multi-client monitoring, with white-label dashboards and automated reporting
  • Law firms wanting sector-specialised analysis and client-ready reports without adding analyst hours
  • Multinationals operating across several jurisdictions that must know what applies before entering a market or launching a product
  • Teams in heavily regulated sectors such as finance, pharmaceuticals and energy, tracking DORA, MiCA, NIS2, CSRD/ESG and the EU AI Act

When not to use Reversa

  • Anyone seeking legal advice: outputs are explicitly informational and require independent professional verification
  • Individuals and small teams wanting to sign up online, since access runs through a sales conversation and a purchase order
  • Buyers who need published pricing before making contact, as no rates appear anywhere on the site
  • Developers expecting a public API or documented integrations to embed regulatory data elsewhere
  • Users who need a mobile application or offline access, the product being a browser-based platform only
Get started

How to use Reversa

A typical end-to-end flow, from setup to results.

  1. Request a demo through the booking link published on the site, or email the team directly
  2. Discuss scope with the team: which areas, jurisdictions and regulatory domains need covering
  3. Agree perimeter and price in a purchase order, as there is no self-service sign-up
  4. Work with Reversa to design, configure and validate the solution against your operational context
  5. Have your regulatory map built from your industry, jurisdictions and business activities
  6. Configure the sector-specialised agents that will read and filter sources on your behalf
  7. Sign in to the web platform with your credentials, then set up enterprise accounts and permissions
  8. Review the daily alerts, each carrying an explanation of why it affects your organisation
  9. Follow the EU procedures that matter to you through their legislative twins
  10. Confirm in writing at the end of the pilot period whether to continue on an annual basis
Quick read

Pros & Cons

Pros

  • The complete Data Processing Agreement is published as an annex to the terms, appendices included, which is unusually transparent
  • The authorised sub-processor list is published with the location of each service, all of them within the European Union
  • Concrete contractual commitments: breach notification within 36 hours, rights requests forwarded within 5 working days, deletion or return within 30 days
  • An independent penetration test has been completed and its findings remediated, with the report available under NDA
  • The company states plainly that ISO 27001 and SOC 2 are still in progress rather than implying they are already held
  • Confidential customer content is excluded from model training without express authorisation, and that authorisation can be withdrawn at any time
  • Coverage reaches upstream into the legislative process rather than stopping at published texts

Cons

  • No pricing is published anywhere: rates are set in a purchase order, so budgeting requires a sales conversation
  • No free plan and no documented free trial, the only entry point being a demo request
  • No public API and no developer documentation
  • No mobile application, and no named third-party integrations
  • Outputs are explicitly not legal advice and carry no guarantee of accuracy or completeness, the platform being provided as is
  • ISO 27001 and SOC 2 have not yet been granted
  • A young company with a small declared headcount, and a site and interface limited to English and Spanish
Pricing

Pricing & Plans

Reversa does not publish pricing. No pricing page exists on the site, and the terms and conditions state that the applicable price is the one set out in the purchase order, exclusive of VAT and other applicable taxes. There is no permanent free plan and no free trial is documented; the terms refer to a pilot period without stating whether it is chargeable. Any change of scope, such as additional modules, sources or agents, is renegotiated in good faith and formalised in a new purchase order or an addendum. Prospective customers must therefore contact the vendor to obtain a quotation.

Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how Reversa handles your data.

GDPR overview

GDPR implementation is documented rather than merely asserted. The publisher names itself as data controller with its registered company name, tax identification number and Madrid address, and gives a dedicated data protection contact address. The privacy policy is versioned and dated, and states a legal basis for each purpose: performance of a contract, legitimate interest, or consent. Data subject rights, namely access, rectification, erasure, objection, restriction, portability and objection to automated decisions, are listed and free to exercise, with the Spanish Data Protection Agency named as the supervisory authority. The framework cited is the GDPR together with Spain's LOPDGDD, including its Article 32 blocking regime. A full Data Processing Agreement is published as an annex to the terms, committing Reversa to breach notification within thirty-six hours, forwarding rights requests within five working days, and permitting customer audits.

Who owns the data?

The terms draw a firm line. Documents, queries and outputs that a customer enters or generates on the platform are that customer's confidential interaction data and remain its exclusive property; Reversa handles them purely as a data processor, acting on the customer's documented instructions under the Data Processing Agreement published as an annex to the terms. Reversa keeps ownership of the platform itself, including its AI models, prompts, algorithms, methodologies and interfaces, and grants only a limited, non-exclusive, non-transferable and revocable right of use for the duration of the contract. Irreversibly anonymised technical and usage data sits outside this split and may be processed by Reversa to operate and improve the service.

Reuse rights

Reversa may process customer personal data only to deliver the service, on documented instructions and for the purposes listed in the Data Processing Agreement: running, configuring and supporting the platform, communications, account management, invoicing, hosting and backups, security logging, and statutory record-keeping. The categories are deliberately narrow, covering names and user identifiers, email addresses, IP addresses and access logs, and billing details, and no special categories of personal data are processed. Training is where the documents deserve close reading. Confidential customer content is not used to train or fine-tune Reversa's models without express authorisation. The terms then treat signature of the purchase order as that authorisation, limited to properly anonymised interactions and content, and the customer may withdraw it in writing at any time, with effect within thirty calendar days and without affecting the main service. The privacy policy describes a stricter mechanism for the same purpose: explicit, granular consent kept separate from the main processing, with provision of the service never conditional upon it. Product analytics inside the platform runs on servers in the European Union, rests on legitimate interest, and feeds neither advertising nor model training.

Data retention & training

Retention summary
Retention is tied to purpose. Contract data is kept for the life of the contract and then for as long as legal liabilities may arise, under the blocking regime of Spanish data protection law. Contact and prospecting data is kept until consent is withdrawn or an objection is made. Browsing data generated on the platform is kept for a maximum of one year. When the contract ends the customer chooses: Reversa deletes or returns the personal data within thirty calendar days of a written request, backups included. Statutory retention obligations override this, and data kept on that basis stays covered by the agreement and blocked, reserved for courts, prosecutors and competent authorities until the limitation period expires, after which it is destroyed. Confidentiality obligations run for five years after the contract ends.
Trains on customer data
Configurable
Training opt-out available
Yes
Subprocessors disclosed
Yes
DPA available
Yes
GDPR contact

Hosting summary

The Data Processing Agreement published with the terms includes a sub-processor annex listing each service alongside its location, and every entry sits in the European Union: cloud infrastructure and storage, application hosting, the database, natural language processing, transactional email and product analytics. A footnote adds that Reversa uses AI models from market-leading providers within a closed system. The annex names service categories rather than individual vendors, the named list being available from the publisher on request. The privacy policy separately confirms that product analytics inside the platform runs on servers located in the European Union. One caveat deserves attention: the agreement also reserves the right for Reversa or its sub-processors to store personal data on servers outside the EEA, in which case transfers are covered by standard contractual clauses adopted by the European Commission, binding corporate rules or an equivalent mechanism. No individual hosting country is named anywhere, only the region. The public website itself relies on cookieless analytics tooling, which is website infrastructure and distinct from where customer data lives.

Hosting regions
EU
Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting Reversa.

  • AI outputs may be inaccurate, incomplete, out of date or hallucinated; the vendor says so plainly, and final responsibility for every decision rests with the customer
  • Source coverage is not guaranteed to be exhaustive, so the absence of an alert is not evidence that nothing has changed
  • Treating the platform as a substitute for professional judgement is the central risk: it is built to support regulatory analysis, not to replace a qualified adviser
  • The two legal documents describe consent to model training differently, the privacy policy requiring separate granular consent while the terms derive it from signing the purchase order
  • The sub-processor annex places every service in the European Union, but the agreement reserves the right to store personal data outside the EEA under standard safeguards
  • Unless the customer objects in writing, its name, trade mark and logo may be used as a commercial reference, with removal taking up to fifteen days after objection
  • Liability is capped at the amount paid over the preceding twelve months, the service is provided as is, and availability is not guaranteed
Setup

Setup & Integrations

Technical difficulty

Technically undemanding, functionally involved. There is nothing to install: the platform runs in a browser and access is by credentials. The effort sits in scoping. Reversa designs, configures and validates the solution jointly with the customer, tuning it to the industry, jurisdictions, activities and agent perimeter agreed in the purchase order, with support throughout the contract. Where the service is embedded in a customer-controlled environment, the customer remains responsible for its own systems, access management, patching and retention. With no API and no named integrations, there is no integration work to plan. Time to go live is not published.

Deployment

Web app

Supported languages

EnglishSpanish
Company

Behind Reversa

Company name
DISRUPTIVE LABS, S.L.
Founded
INFORMATION_NOT_FOUND
Country of origin
🇪🇸 Spain
Headquarters
Calle Valle de la Fuenfría 10, P1, 6ºC, 28034 Madrid
UBO
INFORMATION_NOT_FOUND
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
🇺🇸 United States
Support contact

Social

Official links

Resources

All the official URLs gathered for verification and reference.

FAQ

Frequently asked questions

What does Reversa do beyond regulatory monitoring?
It runs the full chain rather than the alert alone: identifying the regulation that applies to an organisation across every jurisdiction it operates in, interpreting it, filtering it against that organisation's actual operations, informing the resulting decision, and supporting implementation.
What are the three modules?
Regulatory Map builds a personalised map of what applies to you. Agentic Radar has sector-specialised agents read thousands of official sources daily and explain which changes affect you. Legislative Twins maintains a living twin of each EU legislative procedure, from Commission proposal to Official Journal.
Which regulations are covered?
The site publishes dedicated pages for the EU AI Act, DORA, NIS2, CSRD/ESG, MiCA and the GDPR. Monitored sources include national and regional official gazettes and the European institutions, though the terms note that coverage is not guaranteed to be exhaustive.
How much does Reversa cost?
The price is not public. The terms state that it is the amount set out in the purchase order, exclusive of VAT, so a quotation requires contacting the vendor. There is no pricing page on the site.
Is there a free trial or a free plan?
Neither is documented. The terms mention a pilot period after which the parties confirm in writing whether to continue on an annual basis, but they do not say whether that pilot is free of charge.
Is there an API or a mobile app?
Neither was found. There is no API documentation and no developer portal, and no iOS or Android application. Reversa is used through its web platform, with access by credentials.
Is my data used to train Reversa's models?
Confidential customer content is not used for training without express authorisation. The terms treat signing the purchase order as authorisation covering properly anonymised interactions and content, and that authorisation can be withdrawn in writing at any time, taking effect within thirty calendar days. The privacy policy describes a stricter mechanism, requiring separate and granular consent.
Where is the data hosted?
The sub-processor annex to the Data Processing Agreement places cloud infrastructure and storage, application hosting, the database, natural language processing, transactional email and product analytics in the European Union. The agreement nonetheless reserves the possibility of servers outside the EEA under standard contractual clauses or an equivalent safeguard.
Does Reversa hold ISO 27001 or SOC 2?
Not yet. Both are described as in progress: the underlying information security management system is operating and the ISO 27001 internal audit is complete, with the external audit outstanding. Reversa states it does not claim either certification until formally granted, and it has completed an independent penetration test with all findings remediated.
Do the outputs count as legal advice?
No. The terms state that outputs are for information and guidance only, do not constitute legal, regulatory or tax advice, and do not replace a qualified professional's judgement. The customer remains solely responsible for decisions taken on their basis.
Conclusion

Should you pick Reversa?

Reversa occupies a narrow but clearly argued position. Rather than telling a compliance team that a rule has changed, it sets out to establish what that change means for one organisation and what should be done about it, bringing identification, interpretation, filtering, decision support and implementation into a single platform. The three modules are coherent with that ambition, and Legislative Twins in particular reaches where most monitoring tools do not: upstream, into procedures still being negotiated.

What stands out on inspection is the legal transparency. The full Data Processing Agreement is published rather than promised, sub-processors are listed with their locations, and retention and deletion rules are specific. The security page is equally candid: an independent penetration test has been completed and remediated, while ISO 27001 and SOC 2 are described as in progress and explicitly not yet granted. That restraint is worth more than a badge.

The reservations are real. Nothing about pricing is public, there is no free plan or documented trial, and the only way in is a demo request followed by a purchase order, which rules the tool out for anyone needing to compare costs before making contact. There is no API, no mobile application and no named integrations. Outputs carry an explicit disclaimer: informational, not legal advice, and requiring independent professional verification. Readers should also note a discrepancy between the two legal documents on how consent to model training is obtained, and that the sub-processor annex places everything in the EU while the agreement itself reserves the right to store data outside the EEA.

For a multinational, consultancy or law firm with a structured compliance or public affairs function, Reversa is worth a conversation. For anyone wanting to try before talking, it is not yet approachable.