
Ruler
Ruler is Dutch compliance software for financial institutions supervised by central bank DNB and market authority AFM. It maps each licence profile's legal framework, alerts teams when rules change, and runs structured risk assessments with one-click SIRA export.
What is Ruler?
Ruler is compliance software published by Ruler B.V. in Amsterdam and, since 2026, part of CERRIX, which presents itself as the Intelligent Operating System for Enterprise Risk. The site's baseline is In control. and its promise is that Ruler makes compliance simple. The product comes in two parts. Regulatory Watch gives a view of every law and standard that applies to the organisation, grouped by themes and subjects, sends automatic alerts when a text changes, shows upcoming legislation on a Radar, and keeps a transparent audit trail linking policies, procedures and controls back to the legal framework. Risk Assessment works with themes, scenarios and controls in an identify, assess and manage workflow, offers a risk matrix, ships with scenarios and measures written by Ruler's experts plus sector packages, allows full customisation, sets no limit on user numbers, and exports a complete SIRA in one click. The terms also name a Regulatory Change variant. Everything hinges on profiles. A customer buys the profile or profiles matching its type of organisation and licence, then sees only the regulation that is relevant to it. Content is compiled from EU regulations, directives and delegated regulations, Dutch acts and decrees, guidelines, and the news flow of supervisors (DNB, the Dutch central bank, and AFM, the market conduct authority, plus ESMA, EIOPA, EBA, the ECB and FATF), of courts (Hoge Raad, district courts, Kifid), of trade bodies (NVB, Verbond van Verzekeraars) and of public consultations. Ruler describes the mix as software plus people: it combines smart AI software with the knowledge of real experts, and a named legal editorial team sends targeted alerts daily. An August 2026 article sets out an AI-native approach to translating a text into risks and controls, with explainability and human-in-the-loop by default, and a first working regulatory bridge to CERRIX that turns a Ruler alert into a gap analysis scored low, medium or high. The company claims more than 150 financial institutions and over 1,000 compliance professionals in the Netherlands and Belgium. It is a web application reachable from desktop, laptop, tablet and smartphone at app.ruler.nl. The founders kept their clients' legal frameworks in Excel before building it.
What it does
- Know instantly which laws and rules apply to your organisation
- Receive targeted email alerts as soon as a rule inside your profile changes
- Anticipate change with the Radar view of legislation still to come
- Demonstrate compliance by linking policies, procedures and controls to the legal framework, with a full audit trail
- Run structured risk assessments and export a complete SIRA in one click
- Record how far the organisation complies with each theme and assign follow-up tasks to colleagues
- Plan and follow up compliance activities through the planning module
When to use Ruler / When not to
A quick filter to help you decide if Ruler is the right fit.
When to use Ruler
- Compliance officers at licensed Dutch financial institutions that fall under the supervision of DNB, the central bank, or AFM, the market conduct authority
- In-house lawyers and legal counsel who need one always-current view of the rules attached to their organisation's licence
- Directors and board members who have to show the regulator that the organisation is in control, with an audit trail to prove it
- Risk managers who must build a structured systematic integrity risk analysis (SIRA) and keep a risk matrix current
- Tax, HR and legal teams outside financial services, through the separate profiles for tax, legal doctrine, labour and participation, social security, pensions, legal procedures and the housing market
When not to use Ruler
- Organisations outside Dutch and European financial law: no other national legal framework is covered, and the customer base is described as the Netherlands and Belgium
- Individual professionals and freelancers: the cheapest profile costs EUR 1,840 per year excluding VAT and there is no free plan
- Teams that expect self-service sign-up: every route in runs through a demo request and an annual contract signed with a salesperson
- Developers who want to pull regulatory data into their own systems: there is no public API, no documented SSO and no third-party integration apart from the CERRIX bridge
- Anyone looking for legal advice: Ruler gives the customer no warranty unless agreed in writing (T&Cs art. 3.4) and states that it does not know the customer's specific use or purpose (art. 8.3)
How to use Ruler
A typical end-to-end flow, from setup to results.
- Request a demo through the form on ruler.nl: there is no self-service sign-up
- Try Ruler free for 14 days
- Choose the profile or profiles matching your type of organisation and licence, knowing each profile is invoiced separately
- Activate the two user accounts included with every profile, and add extra users with the help of Ruler's consultants
- Work with a Ruler consultant to define your Ruler structure, train the users and run demonstrations
- Log in at app.ruler.nl with a user name and password, optionally with a TIN code or token as second factor
- Browse the legal framework theme by theme and record how far the organisation complies with each item
- Read the daily alerts landing in your inbox, then link policies, procedures and controls to the rules that changed
- Launch a risk assessment across themes, scenarios and controls, then export the complete SIRA in one click
- Ask for additional laws or profiles as your scope grows, and reach the helpdesk at info@ruler.nl from Monday to Friday, 9am to 5pm
Pros & Cons
Pros
- Very precise regulatory scope: one profile per organisation type and licence means you only see the rules that actually apply to you
- Content maintained by a named legal editorial team rather than by an algorithm alone, with daily monitoring of supervisors, case law, trade federations and public consultations
- Built-in audit trail: the evidence of compliance is produced by everyday use instead of being assembled before an inspection
- Data stored and processed in the Netherlands, with all processing inside the EU (T&Cs art. 8.7 and SLA art. 6)
- Prices published openly, profile by profile, with two users included per profile and no user limit on Risk Assessment
- Measurable SLA: 99.5% availability from 7am to 10pm, 96.5% over 24 hours, and an urgent incident picked up within one hour
- Independent security work: third-party penetration tests by RadicallyOpenSecurity, source-code escrow, continuity and recovery plans tested annually, plus consultants for onboarding, gap analyses and monitoring
Cons
- Narrow geographical scope: Dutch and European financial law only, with a customer base described as the Netherlands and Belgium
- The site is mostly in Dutch and the English version is both partial (testimonials left in Dutch, the Compliance Officer, Jurist and Bestuurder pages pointing back to Dutch) and out of date, since it still credits the editorial work to Projective Group while the Dutch pages describe the move to CERRIX
- Contradictory security claims: the Beveiliging page presents a SOC 2 Type 1 certification as still in progress and expected mid-2022, while the terms (art. 5.2) state that Ruler already holds a SOC 2 certification
- No free plan, an entry ticket of EUR 1,840 per year excluding VAT rising to EUR 10,810 per profile per year, several profiles adding up, and no published price for additional users
- Tacit renewal for one year, with cancellation required at the latest two months before the anniversary date
- No public API, no native mobile application and no documented third-party integration apart from CERRIX
- Loose ends in the published documents: two different Chamber of Commerce numbers in the same privacy PDF (59037555 in the header, 69037555 in the body), dead and staging links on the English support page, no customer-facing DPA, no versioned subprocessor list or status page, and no warranty given to the customer unless agreed in writing (art. 3.4)
Pricing & Plans
There is no permanently free plan. Access is sold as an annual subscription per regulatory profile, invoiced yearly and quoted excluding VAT. The lowest entry point is EUR 1,840 per year, for the Pension (HR), Housing market and Legal procedures profiles, while the cheapest financial-services profile is EUR 2,520 per year and the most expensive single profile, Bank prudential, is EUR 10,810 per year. The Risk Assessment module is priced separately at EUR 3,000 per year up to 50 FTE and EUR 5,000 per year above 50 FTE. Each subscribed profile includes two free user accounts; additional users are charged according to their number and type, at a rate that is not published. Several profiles are paid for separately and add up. A 14-day free trial is offered, subscriptions renew automatically for one year unless cancelled two months before the anniversary date, and prices may be indexed annually for inflation and for maintenance and development costs.
- EUR 10
- 810 per year excluding VAT
- EUR 8
- 190 per year excluding VAT
- EUR 7
- 580 per year excluding VAT
- EUR 5
- 680 per year excluding VAT
- EUR 5
- 680 per year excluding VAT
- EUR 5
- 680 per year excluding VAT
- EUR 5
- 070 per year excluding VAT
- EUR 4
- 410 per year excluding VAT
- EUR 4
- 410 per year excluding VAT
- EUR 4
- 410 per year excluding VAT
- EUR 4
- 410 per year excluding VAT
- EUR 4
- 410 per year excluding VAT
- EUR 4
- 070 per year excluding VAT
- EUR 4
- 070 per year excluding VAT
- EUR 3
- 730 per year excluding VAT
- EUR 2
- 520 per year excluding VAT
- EUR 2
- 520 per year excluding VAT
- EUR 6
- 590 per year excluding VAT
- EUR 6
- 060 per year excluding VAT
- EUR 4
- 330 per year excluding VAT
- EUR 3
- 020 per year excluding VAT
- EUR 1
- 840 per year excluding VAT
- EUR 1
- 840 per year excluding VAT
- EUR 1
- 840 per year excluding VAT
- EUR 3
- 000 per year excluding VAT
- EUR 5
- 000 per year excluding VAT
- Every Regulatory Watch profile includes two free user accounts and is invoiced separately
- profiles are cumulative
- billing is annual
- and additional users are quoted on request
Data, GDPR & hosting
A consolidated view of how Ruler handles your data.
GDPR overview
GDPR is addressed concretely. The SLA annexed to the terms (art. 6) states that Ruler guarantees the online tool complies with all applicable legislation, including the GDPR (AVG in Dutch) and the requirements of DORA, and that all processing takes place within the EU. The privacy statement names Ruler as controller and the user as data subject, and lists access, rectification, erasure, restriction, objection and portability rights, withdrawal of consent at any time without retroactive effect, and objection to direct marketing; requests go to info@ruler.nl. Two processors are named, Microsoft (Azure) and Hyfen, for hosting, management and support, each covered by a processing agreement. No Article 27 representative and no DPO are designated, consistent with a company established in the EU. The statement is versioned 2024/2025 with no stated effective date, and no customer-facing DPA is published. Dutch law and the Amsterdam court apply (art. 13).
Who owns the data?
The customer owns the Data it puts into the platform and is deemed to hold the intellectual property rights attached to it (T&Cs art. 8.1); Ruler or its licensors always remain the owner of the Ruler Data, the legal content its editorial team compiles (art. 8.3). Uploaded documents and files are visible only to the customer (art. 8.6), and Ruler staff cannot see the annotations users write inside a theme, though authorities holding a statutory audit power can compel Ruler to grant access. On termination or insolvency Ruler supplies an extract of the Data on request (art. 8.2), an Excel export is built into the environment, and a source-code escrow covers a definitive cessation of activity (art. 5.4).
Reuse rights
Two different answers apply. Data the customer enters is its own and can be reused without asking: it is visible only to the customer (art. 8.6) and can be taken out at any time through the built-in Excel export or, on request, as a full extract (art. 8.2). The Ruler Data - the legal framework, themes, predefined scenarios and controls - remains the property of Ruler or its licensors (art. 8.3), so it is licensed for use inside the subscription rather than free to republish. On Ruler's side, the privacy statement lists the account email and user name, browsing data on the website, IP and MAC address where functional and tracking cookies are consented to, and contact details given by phone, chat or email. These serve product improvement through analysis on data that is in principle anonymised, the sending of News updates and Alerts, and the handling of questions and complaints; usage information is collected anonymously and can be reported back to the customer on request (art. 8.4). Personal and statistical data are not passed to third parties except to perform the contract, including hosting and invoicing, or under a valid order from a judicial authority. Nothing in the public documents mentions training AI models on customer data, and no opt-out is offered.
Data retention & training
Hosting summary
The terms and conditions (art. 8.7) state that Data is stored and processed in the Netherlands, and that Ruler notifies the customer if it decides to move the storage location. The SLA (art. 6) adds that all data processing takes place within the EU, under appropriate data security standards. The security page places the data in Europe with Amsterdam as the primary location, on the Microsoft Azure cloud. The privacy statement names two processors, Microsoft (Azure) and Hyfen, for hosting, management and support, each covered by a processing agreement; the FAQ names Hyfen (hyfen.eu) as the infrastructure partner. Stated safeguards include TLS, third-party penetration testing by RadicallyOpenSecurity, a source-code escrow, continuity and recovery plans tested annually, and immediate notification in the event of a breach, while the SLA (art. 4) describes the infrastructure manager as SOC 2 classified and the applications and interfaces as built to market standards such as OWASP. One caveat: the public IP address of ruler.nl is a Cloudflare anycast node geolocated in the United States, which is the content delivery network in front of the public website, not the location of the application data.
Things to keep in mind
Risks and trade-offs to weigh before adopting Ruler.
- The site contradicts itself on SOC 2: the security page presents a Type 1 certification as still in progress and expected mid-2022, the terms (art. 5.2) state that Ruler holds a SOC 2 data certification, and the SLA (art. 4) attributes the SOC 2 classification to the infrastructure manager rather than to Ruler. Ask for the current certificate before relying on any of it
- The same privacy PDF carries two different Chamber of Commerce numbers, 59037555 in the header and 69037555 in the body, the English support page still links to charcoendique.nl and to a staging URL, and the domain's first Wayback snapshot (8 March 2001) predates its registration (30 April 2012), so it says nothing about the company's age
- The English version of the site still credits the editorial work to Projective Group while the Dutch pages describe the integration into CERRIX: check which version you are reading before quoting it
- No customer-facing data processing agreement is published, and no policy at all is published on training AI models with customer data, even though the tool describes itself as AI-native
- Contractual asymmetries: no warranty is given to the customer unless agreed in writing (art. 3.4), Ruler may transfer its rights and obligations to a third party without the customer's consent (art. 12.3), and authorities holding a statutory audit power can compel Ruler to grant access to the customer's use and data
- Commitment terms deserve a diary entry: tacit renewal for one year with two months' notice, prices indexable annually for inflation and for maintenance and development costs, and an unpublished price for additional users
- Over-reliance is the human risk. Daily alerts and a filled-in audit trail can feel like proof of compliance, but Ruler makes its own editorial choices about the content and scope of its data and states that it does not know the customer's specific use or purpose (art. 8.3). It is not legal advice and it does not replace a compliance officer's judgement
Setup & Integrations
Technical difficulty
Low. Ruler is a web application: nothing to install, nothing to deploy, no API to connect, no integration required. Users sign in at app.ruler.nl from a desktop, laptop, tablet or smartphone with a user name and password, optionally with a TIN code or token as second factor; no SSO is documented. The effort is organisational rather than technical: choosing the right profiles, defining your Ruler structure and training users. Ruler's consultants handle onboarding, training and demonstrations, and the legal content, predefined scenarios and controls arrive ready to use. Access starts with a demo request, not an instant sign-up.
Deployment
Integrations
Behind Ruler
Fundraising
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
Who is Ruler designed for?
How much does Ruler cost?
Is there a free plan or a free trial?
Can I pay monthly, and does the subscription renew on its own?
Where is the data hosted?
Who owns the data entered into Ruler?
How long is the data kept?
Is there an API or a mobile app?
Which laws does Ruler cover?
What support is available?
Should you pick Ruler?
Ruler is an unapologetically niche tool. Its subject is Dutch and European financial law, its customers are in the Netherlands and Belgium, and everything follows from one design choice: you buy the profile matching your licence and see only the regulation that applies to you. Its main strength is the combination of legal content maintained by a named human editorial team with automation of the watch itself, through daily alerts, a Radar on texts still to come, an audit trail that turns everyday use into evidence of compliance and, since the 2026 move into CERRIX, a first bridge carrying a signal through to risk, control and gap analysis. Hosting and processing in the Netherlands and the EU, a measurable SLA, third-party penetration tests and a source-code escrow are serious arguments in a supervised sector. The price is public and high. There is no free plan, profiles run from EUR 1,840 to EUR 10,810 per year excluding VAT, they add up, and the cost of extra users is not published. This is a corporate purchase decided after a demo, not something an individual tries out. Two reservations are worth stating rather than resolving. Several pages contradict each other or have not been refreshed: the security page still presents a SOC 2 Type 1 certification as expected mid-2022 while the terms assert that Ruler holds one and the SLA attributes the classification to the infrastructure provider; the privacy PDF carries two different Chamber of Commerce numbers; and the English site still credits the editorial work to Projective Group although the Dutch pages describe the integration into CERRIX. None of that touches the substance of the product, but it points to documents that are rarely reread, an awkward look for a tool sold on regulatory currency.
- Choosing a selection results in a full page refresh.
- Opens in a new window.