Compliance infrastructure for software, hardware, and AI.

Something is broken.

To those it concerns:

A regulation sets out what businesses must do. However, it doesn't provide the specifics that technical teams need.

Someone has to work out what the law means for the systems a business builds and operates, and that requires specialist knowledge, manual interpretation, and coordination among compliance, security, and engineering.

Policies matter. But a policy saying access is restricted does not tell an engineer which permissions to implement or show that those permissions work. A retention policy does not delete data. The system has to do that.

RuleMesh exists to connect those two worlds.

We turn regulatory obligations into technical requirements, with mapped controls and clear expectations for evidence. Each requirement traces back to its source, so teams can understand what to build, why it matters and what a reviewer needs to see.

That gives engineers and their AI agents a shared foundation to work from, and makes specialist regulatory knowledge reusable.

Short-term road map

GDPR was the first regulation we packaged end-to-end; the EU AI Act is the second and is now served. The roadmap spans some of the most consequential compliance regimes across the EU, the US, and Australia. For the EU, language support is also on the short-term horizon.

European Union

  • GDPR
  • EU AI Act
  • DORA
  • NIS2
  • Data Governance Act
  • Data Act
  • Digital Services Act
  • Digital Markets Act
  • Cyber Resilience Act
  • Medical Devices Regulation

United States

  • HIPAA (Privacy, Security, Breach, Administrative)
  • COPPA
  • FERPA
  • Gramm-Leach-Bliley (Regulation P)
  • Identity Theft Red Flags
  • CAN-SPAM
  • Fair Credit Reporting Act

Australia

  • Privacy Act
  • Security of Critical Infrastructure Act
  • Online Safety Act
  • Cybercrime Act
  • Surveillance Devices Act
  • Data Availability and Transparency Act
  • Spam Act
  • Criminal Code Act
  • Telecommunications (Interception and Access) Act

We contribute to the standards we depend on.

HCAP: the HTTP Compliance Authorization Protocol.

IETF draft · draft-nyakiso-hcap-00

Compliance-as-infrastructure only works if the infrastructure is open. HCAP is an IETF standards-track draft that moves compliance verification from annual audits to the HTTP layer: providers declare their policy requirements; callers present signed, verifiable credentials; verification happens offline in milliseconds.

HCAP is open, vendor-neutral, and designed to work with any registry, not just ours. We'd rather help define the category than fence it off.