Requirements as code.
Compliance automated.

stanz.ia turns your specifications and ISO/IEC standards into Git-versioned files, validated by your CI/CD, verified by AI and traced down to every automated test and signed manual check.

Multiple standards inheritance Blocking pipeline gate RTM generated at every build
stanz.ia requirements traceability dashboard: RTM matrix, test coverage and signed manual checks

Native compliance packs

IEC 62304 ISO 27001 ISO 26262 ASPICE HIPAA SOC 2 GDPR ISO 13485

The problem

The gap between what is specified and what is actually tested

The #1 source of costly bugs, certification delays and painful audits.

The Excel matrix nightmare

Weeks of QA engineers manually maintaining the traceability matrix across specs, automated tests and manual test scripts. One forgotten row and the whole audit derails.

Heavy tools at sky-high prices

Jama, DOORS, Jira + plugins: rigid, expensive, unversioned. The cost and friction push teams to bypass the tool from the very first sprint.

Generic AI that hallucinates

A simple ChatGPT wrapper cannot guarantee the consistency of a requirements graph. Teams need AI that detects structural and semantic anomalies, not prose generation.

Features

The "Terraform" of requirements

Treated as code, the specification becomes auditable, testable and unbreakable.

Requirements-as-Code

YAML files versioned in Git, reviewed in pull requests like code. Lint, diff, history and full reproducibility.

YAML · Git · PR

Multiple inheritance

A project automatically inherits the standards and internal baselines it declares. The graph engine detects conflicts between parents at build time.

extends · override · waiver

CI/CD validation

The CLI blocks the merge if a critical requirement has neither a passing automated test nor a signed manual validation. GitHub Actions, GitLab CI, Jenkins.

GitHub Actions · GitLab CI · Jenkins

AI anti-duplicate & consistency

Embeddings and RAG analyze every requirement: semantic duplicates across projects, parent/child contradictions, acceptance test skeleton generation.

RAG · Embeddings · pgvector

Automatic traceability matrix

The bi-directional RTM regenerates at every commit: requirement → code → CI/CD test → signed manual check, exportable as certified PDF/HTML.

RTM · Audit · ISO

Hybrid checks & signatures

Automated test execution in the pipeline plus manual validation signed by role (auditor, QA, medical officer) via dashboard or mobile.

auto + manual · sign-off
§

Keycloak SSO

Multi-tenant OIDC/OAuth2 authentication with fine-grained RBAC (admin, auditor, developer, viewer). Enterprise SAML/AD SSO.

Keycloak · OIDC · SAML

100% offline CLI

Full local validation — syntax, graph topology, test mapping — before any push to the platform. Exit 0/1 for the pipeline.

npx stanz · local

Data sovereignty

EU hosting or on-premise, local AI models available. Your confidential specifications never leave your perimeter.

Sovereign Cloud · On-prem

How it works

From specification to audit deliverable, in 3 steps

From YAML files in your repository to the certified compliance matrix, everything is automated.

Declare your requirements

Write .req.yaml files versioned in Git, with multiple standards inheritance via extends. Project typology, criticality, links to tests.

Validate in the pipeline

The CLI runs in your CI/CD: lint, graph resolution, JUnit mapping, blocking gate. AI checks duplicates and consistency on every push.

Audit in one click

The traceability matrix and gap analysis reports are generated automatically. Your auditors receive proof, not promises.

Compliance

Immutable standards packs, rolled down into project requirements

Provided and maintained by stanz.ia, or defined by your company. Every standards update triggers a gap analysis across all your projects.

Medical software

  • IEC 62304 software lifecycle
  • ISO 13485 medical quality
  • Downward requirements traceability
  • Checks signed by QA officer

Automotive & aerospace

  • ISO 26262 functional safety
  • ASPICE engineering process
  • ASIL management and inheritance
  • Mandatory test coverage

Security & data

  • ISO 27001 information security
  • SOC 2 and GDPR / HIPAA
  • Audited overrides and waivers
  • Traced compliance sign-offs

FAQ

Frequently asked questions

What are requirements-as-code?

Requirements are stored as versioned YAML files in Git, like source code. Each requirement is identified, reviewed, tested and traced through pull requests, linting and CI/CD pipelines. No more unversioned Word documents and Excel sheets.

How does multiple inheritance work?

A project declares its dependencies on standards and internal baselines via the extends keyword. The graph engine resolves the inheritance, detects contradictory constraints between parents (e.g. power consumption vs sampling frequency) and allows overriding at the child level: deprecated, overridden, waived.

What exactly does CI/CD validation block?

The CLI returns a non-zero exit code if a critical requirement has neither a passing automated test in the pipeline nor a signed manual validation. The PR merge is then blocked by the status check, and the developer receives a precise gap report.

What does the AI do, concretely?

The AI analyzes requirements via embeddings and RAG: semantic duplicate detection across projects or modules (e.g. "REQ-402 in project A ≈ REQ-108 in module B"), verification that a child requirement does not contradict its parent, and generation of acceptance test skeletons (Gherkin, Jest, PyTest).

Do you generate the traceability matrix?

Yes. At every commit and build, the bi-directional RTM is regenerated: each standard requirement is linked to a project requirement, to code, to a passing CI/CD test and to a signed manual check. Certified PDF/HTML export ready for audit.

Our specs are confidential, where are they hosted?

EU hosting (Sovereign Cloud) or on-premise in your infrastructure. AI models can run locally (open-source LLMs over your vectors). Your specifications never leave your compliance perimeter.

How does Keycloak integration work?

The web dashboard authenticates via OIDC PKCE, the CLI and CI/CD use client credentials or personal tokens. Multi-tenant RBAC: admin, auditor, developer, viewer. SAML/AD SSO compatible with your enterprise identity provider.

Is the CLI free?

Yes, the CLI and YAML parser are open-source and free: define requirements and validate inheritance in CI/CD with no limits. The SaaS platform (dashboard, AI, RTM, audit) is commercialized as an enterprise subscription.

Early access

Join the early access list

Be among the first teams to test the CLI and dashboard. Get the launch announcement, case studies and ready-to-use standards templates. No spam, one-click unsubscribe.

Data used solely for the stanz.ia early access list. GDPR compliant.

Please enter a valid email address.

Subscription confirmed. Thank you, talk soon.

Ready to turn your requirements into infrastructure?

The "Terraform" of requirements, the quality backbone of your company.

Request a demo