Data Layer

Meridian.
Every regulation.
One signal.

The same alerts and obligations that power Navigator — a living regulatory repository monitoring 150+ regulatory bodies worldwide. Structured obligations, AI-tagged alerts, and daily change detection. The data layer beneath the entire SureStep platform.

150+
Regulatory bodies monitored daily
eCFR
Titles 12 & 31 — full obligation hierarchy
Daily
Change detection with before/after diffs
100+
Regulatory tags across 9 domains
The Data Layer

A public window into
what we built.

Meridian is the foundation of the SureStep platform — the same regulatory data that trains Compass via RAG and powers Navigator's assessments. Browse the repository, search obligations, and see the data quality for yourself.

01

Browse the Repository

Open access to alerts, obligations, sources, and rulebooks. Search the full repository — no login required to explore the data.

02

Track What Applies

Mark obligations applicable to your business, get a curated feed of only the changes that touch you, and work a review queue.

03

Run It in Navigator

When you need AI change-assessment, policy & control management, campaigns, reporting, and GRC platform integration — step up to the full GRC platform.

Built on Trust

Source-faithful data.
Not AI-generated summaries.

Every alert in Meridian links back to the original source document, captured as published. Every obligation traces to the specific eCFR section. No hallucinations, no AI-generated interpretations — just the raw regulatory text, structured, tagged, and citable. The same data that powers Compass and Navigator.

📄

Original Source Snapshots

Every alert is captured as a PDF/HTML snapshot at the moment of publication. The record never rots when an agency moves a page.

🔗

Citation-Level Provenance

Every obligation traces to the specific section and paragraph in the eCFR or source regulation. No summaries, no interpretations.

Same Backend as Compass

This is the same data that trains Compass via RAG and powers Navigator's assessments. The data layer beneath the entire platform.

Always watching. Always tracking. 150+ regulatory bodies worldwide, monitored every day.

Coverage

What's in
the repository.

150+ regulatory bodies worldwide. 30+ compliance frameworks. The eCFR obligation corpus. All captured, normalized, and citable.

Industry Coverage by Region

Where Meridian monitors regulatory change

IndustryUS FederalUS StateCanadaUKEU
Banking & Financial Services
Securities & Investments
Insurance
Fintech & Crypto
AML / Sanctions
Technology & Telecom
AI Governance
Data Privacy & Protection
Healthcare & Life Sciences
Energy & Utilities
Defense & Aerospace
Transportation
Environmental
Labor & Employment
Consumer Protection
US

United States

153 agencies · daily

153 federal agencies via the eCFR, plus the Federal Register and FINRA. State-level coverage includes NY (DFS Part 500), CA, and TX.

SECFDICOCCFedCFPBFinCENCFTCNCUAFTCEPAHHSDOJDODDOEDOTDOLFCCNRC
CA

Canada

Federal + Provincial

Federal regulators including OSFI, FINTRAC, Bank of Canada, and Dept of Finance. Provincial coverage across BC, ON, and QC.

OSFIFINTRACBoCFinanceBCSCAMFFSRACDIC
UK/EU

UK & European Union

Daily

UK FCA, PRA, and Bank of England. EU regulations via EURLEX including the AI Act, DORA, and EBA guidelines.

FCAPRABoEEURLEXEBAEU AI ActDORA

Compliance Frameworks

30+ frameworks mapped and cross-referenced

NIST
  • CSF 2.0
  • SP 800-53
  • SP 800-171
  • AI RMF
ISO/IEC
  • 27001
  • 27002
  • 31000
  • 37301
  • 22989
  • 42001
  • 31010
Financial
  • PCI DSS v4
  • SOX
  • GLBA
  • Basel III
  • DORA
Security
  • CIS Controls v8
  • SOC 2 / TSC
  • AICPA TSC
  • FedRAMP Rev5
  • NERC CIP
Privacy
  • GDPR
  • HIPAA
  • NY DFS Part 500
SureStep
  • AI Governance Framework
  • Risk Taxonomy
  • Compliance Matrix
  • Maturity Assessment
Obligations

The eCFR Corpus

Titles 12 (Banking) & 31 (Treasury) as a full obligation hierarchy — sections to paragraphs — with canonical citations, effective dates, and daily change detection with before/after diffs.

AI Enrichment

Tagged & Linked

Every alert is classified with ~100 regulatory tags across 9 domains, then linked to the obligations it affects — by citation match and by semantic similarity using pgvector embeddings.

Snapshots

The Original, Preserved

A headless-browser service captures the source PDF/HTML of each alert as it was published, stored and served on demand — so the record never rots when an agency moves a page.

Under the Hood

The pipeline behind
the signal.

A small fleet of services that scrape, normalize, enrich, and version regulatory data every day — the same backend that powers Navigator.

01

Scrape

150+ per-source jobs pull alerts daily. eCFR sync polls for obligation changes.

02

Normalize

De-dupe, extract citations & key facts, structure the text.

03

Enrich

AI tags each alert and links it to affected obligations.

04

Snapshot

Capture the original source document and store it immutably.

05

Version

Detect obligation changes and record diffs over time.

Flask REST APICloud RunPostgreSQL + pgvectorVertex AI · GeminiPlaywright snapshotsOAuth 2.0Next.js 16
Family

Meridian is the front door.
Navigator is the operating room.

Same regulatory intelligence underneath — two products for two moments. One gets you in. The other runs your program.

Discover · Public

Meridian

For anyone watching regulation

  • Browse alerts & obligations
  • Track what applies to your team
  • Curated feed of relevant changes
  • API & agent access for builders
  • The data layer beneath the platform
↓ upgrades to
Operate · Enterprise

SureStep Navigator

For compliance teams running a program

  • AI regulatory change assessment
  • Policy & control management
  • Campaigns, tasks & evidence
  • Board-ready reporting
  • Works with all major GRC platforms
FAQ

Frequently asked
questions.

What exactly is Meridian?

Meridian is a repository of regulatory intelligence — alerts from 150+ regulatory bodies worldwide, the full eCFR obligation corpus for Titles 12 and 31, 30+ compliance frameworks, and AI-tagged classifications across 9 regulatory domains. It's the data layer beneath the entire SureStep platform.

What's the difference between Meridian and Navigator?

Meridian is the data layer — browse, search, and monitor regulatory changes. Navigator is the full GRC platform — AI-powered change assessment, policy and control management, campaign workflows, board-ready reporting, and GRC system integration. Meridian is the front door; Navigator is the operating room.

Which regulatory sources does Meridian cover?

Meridian covers 153 US federal agencies via the eCFR (including SEC, FDIC, OCC, CFPB, FinCEN, Federal Reserve, FTC, EPA, and more), US state-level regulations (NY DFS Part 500, CA, TX), Canadian federal and provincial regulators (OSFI, FINTRAC, Bank of Canada, BC, ON, QC), UK regulators (FCA, PRA, Bank of England), and EU regulations via EURLEX (AI Act, DORA, EBA guidelines). 30+ compliance frameworks including NIST, ISO, PCI DSS, HIPAA, GDPR, SOX, FedRAMP, and NERC CIP. All sources are monitored daily with change tracking and diffs.

Can I access Meridian via API?

Yes. Meridian includes a public data API with OAuth 2.0 authentication and an MCP server for agent-ready access. Contact us for API access and integration details.
Proof

The expertise behind
the data.

Explore the repository.
See the data quality.

The same regulatory intelligence that powers the SureStep platform — alerts, obligations, and change detection across 150+ regulatory bodies worldwide.

We use cookies for site analytics (Google Analytics, LinkedIn Insight Tag) to understand how visitors use this site. No data is used until you accept.