stanz.ia turns your specifications and ISO/IEC standards into Git-versioned files, validated by your CI/CD, verified by AI and traced down to every automated test and signed manual check.
Native compliance packs
The problem
The #1 source of costly bugs, certification delays and painful audits.
Weeks of QA engineers manually maintaining the traceability matrix across specs, automated tests and manual test scripts. One forgotten row and the whole audit derails.
Jama, DOORS, Jira + plugins: rigid, expensive, unversioned. The cost and friction push teams to bypass the tool from the very first sprint.
A simple ChatGPT wrapper cannot guarantee the consistency of a requirements graph. Teams need AI that detects structural and semantic anomalies, not prose generation.
Features
Treated as code, the specification becomes auditable, testable and unbreakable.
YAML files versioned in Git, reviewed in pull requests like code. Lint, diff, history and full reproducibility.
YAML · Git · PRA project automatically inherits the standards and internal baselines it declares. The graph engine detects conflicts between parents at build time.
extends · override · waiverThe CLI blocks the merge if a critical requirement has neither a passing automated test nor a signed manual validation. GitHub Actions, GitLab CI, Jenkins.
GitHub Actions · GitLab CI · JenkinsEmbeddings and RAG analyze every requirement: semantic duplicates across projects, parent/child contradictions, acceptance test skeleton generation.
RAG · Embeddings · pgvectorThe bi-directional RTM regenerates at every commit: requirement → code → CI/CD test → signed manual check, exportable as certified PDF/HTML.
RTM · Audit · ISOAutomated test execution in the pipeline plus manual validation signed by role (auditor, QA, medical officer) via dashboard or mobile.
auto + manual · sign-offMulti-tenant OIDC/OAuth2 authentication with fine-grained RBAC (admin, auditor, developer, viewer). Enterprise SAML/AD SSO.
Keycloak · OIDC · SAMLFull local validation — syntax, graph topology, test mapping — before any push to the platform. Exit 0/1 for the pipeline.
npx stanz · localEU hosting or on-premise, local AI models available. Your confidential specifications never leave your perimeter.
Sovereign Cloud · On-premHow it works
From YAML files in your repository to the certified compliance matrix, everything is automated.
Write .req.yaml files versioned in Git, with multiple standards inheritance via extends. Project typology, criticality, links to tests.
The CLI runs in your CI/CD: lint, graph resolution, JUnit mapping, blocking gate. AI checks duplicates and consistency on every push.
The traceability matrix and gap analysis reports are generated automatically. Your auditors receive proof, not promises.
Compliance
Provided and maintained by stanz.ia, or defined by your company. Every standards update triggers a gap analysis across all your projects.
FAQ
Requirements are stored as versioned YAML files in Git, like source code. Each requirement is identified, reviewed, tested and traced through pull requests, linting and CI/CD pipelines. No more unversioned Word documents and Excel sheets.
A project declares its dependencies on standards and internal baselines via the extends keyword. The graph engine resolves the inheritance, detects contradictory constraints between parents (e.g. power consumption vs sampling frequency) and allows overriding at the child level: deprecated, overridden, waived.
The CLI returns a non-zero exit code if a critical requirement has neither a passing automated test in the pipeline nor a signed manual validation. The PR merge is then blocked by the status check, and the developer receives a precise gap report.
The AI analyzes requirements via embeddings and RAG: semantic duplicate detection across projects or modules (e.g. "REQ-402 in project A ≈ REQ-108 in module B"), verification that a child requirement does not contradict its parent, and generation of acceptance test skeletons (Gherkin, Jest, PyTest).
Yes. At every commit and build, the bi-directional RTM is regenerated: each standard requirement is linked to a project requirement, to code, to a passing CI/CD test and to a signed manual check. Certified PDF/HTML export ready for audit.
EU hosting (Sovereign Cloud) or on-premise in your infrastructure. AI models can run locally (open-source LLMs over your vectors). Your specifications never leave your compliance perimeter.
The web dashboard authenticates via OIDC PKCE, the CLI and CI/CD use client credentials or personal tokens. Multi-tenant RBAC: admin, auditor, developer, viewer. SAML/AD SSO compatible with your enterprise identity provider.
Yes, the CLI and YAML parser are open-source and free: define requirements and validate inheritance in CI/CD with no limits. The SaaS platform (dashboard, AI, RTM, audit) is commercialized as an enterprise subscription.
Early access
Be among the first teams to test the CLI and dashboard. Get the launch announcement, case studies and ready-to-use standards templates. No spam, one-click unsubscribe.
Data used solely for the stanz.ia early access list. GDPR compliant.
Please enter a valid email address.
Subscription confirmed. Thank you, talk soon.
The "Terraform" of requirements, the quality backbone of your company.
Request a demo