compliance-mcp
In developmentA compliance layer for enterprise AI usage that deliberately makes no external AI calls of its own.
When an organisation rolls out AI coding tools, someone has to answer what people are actually doing with them — and answer it without shipping the sensitive material somewhere else to find out.
That constraint is the entire design. The collector makes no external AI calls at all. A compliance tool that forwards the material it is inspecting to a third party has recreated the exact exposure it exists to prevent, so evaluation happens locally and human judgement stays in the analyst's own session, where the data already is.
It runs against a mock mode too, so it can be developed and demonstrated without a live tenant or any real organisation's data.
Early: the collection layer works, the rest is designed but unbuilt.