Prove your AI is governed — with evidence, not a questionnaire.
Rulebound turns what your AI actually does — across your code and your runtime — into a live register and continuous, file-cited compliance evidence, mapped control-by-control to the frameworks your auditors and regulators expect.
Illustrative. Synthetic example — not from a real repository.
India's Digital Personal Data Protection Act is law, and its implementation runway points to enterprises being ready by ~May 2027. Every business processing personal data through AI will need to demonstrate consent, data minimisation, retention limits, right-to-erasure and cross-border controls — not just assert them. Rulebound generates that evidence from your code and runtime today.
Governance frameworks are multiplying — DPDP, GDPR, the EU AI Act, ISO 42001, NIST — and each one wants proof, not promises. But your AI's real behaviour lives in code and runtime, and it changes every sprint. A point-in-time questionnaire is stale the moment someone merges.
Whether consent is captured before the model call, whether erasure actually deletes, where data crosses a border — these are facts in your codebase, invisible to a survey.
DPDP §12, GDPR Article 17, EU AI Act Article 10 — different words, overlapping evidence. Answering each by hand, per repo, per quarter, doesn't scale.
PII flows into prompts, gets logged, gets sent to third parties, sometimes trains a model — and no one has a current record of processing for any of it.
A signed control today means nothing after tomorrow's deploy. Governance has to be continuous, or it's fiction.
Rulebound reads how your AI is built and how it runs, extracts the facts that every framework cares about, and turns them into cited, control-level evidence that re-generates on every commit.
Rulebound reads your code and runtime into one structured evidence base — so a fact found once answers DPDP, GDPR and the EU AI Act at the same time, instead of a separate review per framework.
The same facts about your AI answer two very different mandates — the privacy of the personal data it touches, and the governance of the AI itself.
Scoped to how your AI handles personal data — not a whole-company privacy programme. We evaluate consent before the model call, data minimisation, retention and right-to-erasure, cross-border transfers to model providers, and secondary use such as training on user data.
The full AI-governance posture — risk management, data governance, human oversight, technical documentation, transparency and record-keeping — mapped control-by-control to each framework's clauses and articles.
As the RBI finalises its Model Risk Management guidance, Rulebound already delivers its technical spine — a live model inventory, risk-based tiering, adversarial testing and continuous runtime controls. And for the black-box AI models you can't fully explain, we already provide the compensating controls the draft calls for.
Everyone else asks your team to fill in a form. Rulebound reads the source of truth — your code and your runtime — and hands you the citation.
Every control verdict points at the exact file and line — an auditor can click straight to the proof, or its absence.
Repositories are cloned into an ephemeral workspace, audited, and wiped — even if the run fails. Bring your own key, or use ours. We are not a new place your source lives.
Results are cached to the commit SHA and re-generated when the code changes — governance that tracks reality instead of a quarterly snapshot.
Generated from your code and runtime — every claim backed by a citation, so an audit is a query, not a fire drill.
Re-evaluated on every commit and against live runtime activity. Your posture is always current, never a stale snapshot.
Built for India's DPDP Act down to the section, and equally fluent in GDPR, the EU AI Act, ISO 42001 and NIST AI RMF — one evidence base, every mandate.
Governance connects to discovery, usage, applications and agents — the same graph across every layer AI touches your organization.
Request access and we'll generate a live, file-cited compliance scorecard for one of your AI repositories — mapped to the frameworks you answer to.
Five, each mapped control-by-control: DPDP 2023 and GDPR for the privacy of the personal data your AI touches; and the EU AI Act, ISO/IEC 42001 and NIST AI RMF for the governance of the AI system itself. All five are evidence-backed, not just checklists.
No — and that's deliberate. For DPDP and GDPR we cover the AI slice: how personal data flows through your AI, whether consent is captured before the model call, retention and erasure of AI-processed data, cross-border transfers to model providers, and secondary use like training. It's the part general privacy tools miss, done deeply — not a replacement for your whole privacy programme.
Instead of asking your team to self-attest, Rulebound reads your actual codebase and runtime and extracts the facts — consent gates, erasure paths, data flows, cross-border transfers — each cited to a specific file and line. An auditor can click straight to the proof.
No. Repositories are cloned into an ephemeral workspace, audited, and wiped — guaranteed even if the run fails. You can bring your own LLM key or use the platform's. We are not a new place your code lives.
India's DPDP Act is already law, and its implementation runway points to enterprises needing to be demonstrably compliant by around May 2027. "Demonstrable" is the key word — you'll need evidence of consent, minimisation, retention and cross-border controls, which takes time to build. Starting now means the evidence accrues continuously instead of in a last-minute scramble.
Evidence is cached to each commit and re-generated when the code changes, and it draws on live runtime activity as well — so your governance posture reflects what your AI is doing today, not what a form claimed last quarter.