ComplyEdge TrustLint — offline EU AI Act compliance checks
Offline TrustLint checks: EU AI Act Article 5, Article 50, GPAI, plus GDPR and HIPAA.
Open source Open in the app JSON README (API)
About
Offline TrustLint checks: EU AI Act Article 5, Article 50, GPAI, plus GDPR and HIPAA.
Details
- Kind
- MCP servers
- Topic
- Security & identity
- Publisher
- complyedge
- Origin
- official
- Category
- ferramentas
- Transport
- local
- Version
- 0.2.18
- Stars
- 4
- Last push
- 2026-09-07T19:07:05Z
- Repository state
- ativo
- Language
- Python
- License
- Apache-2.0
- Added
- 2026-08-29 03:01:48
- Updated
- 2026-09-08 02:13:50
- Origin id
io.github.ComplyEdge/complyedge
README
# ComplyEdge
[](https://pypi.org/project/complyedge/)
[](LICENSE)
[](https://smithery.ai/servers/complyedge/complyedge)
EU AI Act Article 5 and Article 50 runtime deny for AI agents. Not a periodic scanner over a repo: the platform enforces in production, on every request — and the same discipline is available to your agent as an **MCP server** that checks and scans the text you pass it, offline, with an article citation on every finding. Classifiers (`eu-ai-act-*`) score the *system*; ComplyEdge denies *this* prompt or output. Article 50 here is unlabeled or deceptive use, not C2PA.
Ships three ways: a Python SDK, an offline CI linter (TrustLint), and an **MCP server** — a Model Context Protocol server that exposes compliance checks as tools to any MCP host (Claude, Cursor, MCP Inspector).
**Article 5 is already law.** GPAI fines have applied since 2 August 2026. Your AI is either compliant right now, or it isn't.
> What does your compliance tool tell a regulator when it blocks a request? A probability score?
>
> ComplyEdge says: **Article 5(1)(a), rule `rego-art5-1a-001`, timestamp, input hash.** One is an audit trail. One is a guess.
## MCP Server (Model Context Protocol)
ComplyEdge TrustLint is an MCP server built on the official [MCP Python SDK](https://github.com/modelcontextprotocol/python-sdk) (`mcp>=1.9`). It gives an agent article-cited compliance checks instead of a probability score, and it runs fully offline: no API key, no network call, rules evaluated from the bundled YAML corpus.
**Tools** (the server exposes MCP tools only — no resources, no prompts; all three are read-only and idempotent):
| Tool | What it does |
|---|---|
| `check_compliance` | Check text against the TrustLint rule corpus. Returns PASS/FAIL with rule ID, severity, and the article citation behind each finding. |
| `list_rules` | List available rules, filterable by jurisdiction (`EU`, `US`, `Global`, `Universal`). |
| `scan_prompt` | Pre-generation prompt scan. Returns `SAFE` or `RISK_DETECTED` before the model is called. |
**Local (stdio)** — for Claude Desktop, Cursor, MCP Inspector, or any MCP host:
```bash
pip install 'complyedge[mcp]'
complyedge-mcp # or: python -m complyedge.mcp_server
```
```json
{
"mcpServers": {
"complyedge": {
"command": "complyedge-mcp"
}
}
}
```
**Remote (Streamable HTTP):** `https://mcp.complyedge.io/mcp`
Server source: [`sdks/python/complyedge/mcp_server.py`](sdks/python/complyedge/mcp_server.py). Full MCP docs: [`sdks/python/README.md`](sdks/python/README.md). This MCP path uses the offline TrustLint engine; it does not call the hosted OPA/Rego policy API.
**Install (coding agents):**
```bash
pip install complyedge
pip install trustlint
pip install 'complyedge[mcp]'
npx -y @complyedge/mcp
claude mcp add complyedge -- npx -y @complyedge/mcp
```
Listing: [smithery.ai/servers/complyedge/complyedge](https://smithery.ai/servers/complyedge/complyedge)
Cursor one-click: [Install TrustLint MCP](cursor://anysphere.cursor-deeplink/mcp/install?name=ComplyEdge%20TrustLint%20EU%20AI%20Act&config=eyJ1cmwiOiAiaHR0cHM6Ly9tY3AuY29tcGx5ZWRnZS5pby9tY3AifQ)
OpenAI Agents extra (hosted path; needs `COMPLYEDGE_API_KEY`):
```bash
pip install 'complyedge[agents]'
```
```python
from complyedge.agents import create_compliance_guardrail
```
CI: `uses: complyedge/trustlint-action@v1`
GOPAL is an OPA library in your process. ComplyEdge is per-request deny + citation + trust page + MCP.
## Live enforcement seals
Not a static badge. These seals reflect live `/v1/check` traffic from open-source projects
embedding ComplyEdge: they change as real enforcement happens.
Both projects below are our own. ComplyEdge runs in production against our own code
before we ask anyone else to run it against theirs.
[](https://trust.complyedge.io/ivd)
[](https://trust.complyedge.io/horizon)
| Project | Live trust page |
|---------|-----------------|
| **IVD Framework** | [trust.complyedge.io/ivd](https://trust.complyedge.io/ivd) |
| **Horizon** | [trust.complyedge.io/horizon](https://trust.complyedge.io/horizon) |
Each trust page is generated from that project's real audit trail: enforcement status, check
volume, and the EU AI Act articles enforced at runtime. (GitHub proxies and caches images, so the
seal above can lag; the trust page is always current.)
Embed one on your own project: [Enforcement Seal docs](https://complyedge.io/docs/trust-badge.html).
## Quick Start
```bash
pip install complyedge
```
```python
from complyedge import compliance_check
@compliance_check(jurisdiction="EU", agent_id="my-agent")
def my_agent(prompt):
return llm.generate(prompt) # every input and output checked
```
Three lines. Every AI input and output evaluated against the EU AI Act rule corpus (Article 5, Article 50, GPAI). Violations blocked before they reach the user: with article citation, rule ID, and timestamp on every decision.
Set `COMPLYEDGE_API_KEY` to your key. The decorator activates by default; to disable without removing the key (e.g., in CI), set `COMPLYEDGE_ENABLED=false`.
## Without a decorator
```python
from complyedge import is_safe, check
import os
api_key = os.environ["COMPLYEDGE_API_KEY"]
# Boolean check: returns True if no violations
if not is_safe(prompt, api_key=api_key, jurisdiction="EU"):
raise ValueError("Prompt violates EU AI Act")
# Full result: returns ComplianceResult with the violations that blocked it
result = check(prompt, api_key=api_key, jurisdiction="EU")
if not result.allowed:
for v in result.violations:
print(v.rule_id, v.severity, v.rule_description)
```
`rule_id` is the citation key: every rule carries its article reference in the corpus (`rego-art5-1c-001` → Article 5(1)(c)), and the full citation text ships with the rule under [`rules/`](rules).
Jurisdiction maps to the rule corpus: `EU` evaluates against EU AI Act Article 5, Article 50, and GPAI obligations. `US` evaluates against HIPAA, SOX, COPPA, TCPA, BIPA, CCPA, Colorado AI Act, NYC LL144, ECPA.
## TrustLint, Offline Linter
No API key required. Scans text against the YAML rule corpus using regex patterns. Published as a standalone package, versioned independently of the SDK.
```bash
pip install trustlint
trustlint check --text "We use social credit scoring to evaluate applicants"
# → CRITICAL: EU_AI_ACT_ART5_SOCIAL_SCORING_001, Article 5(1)(c)
```
Exit codes: `0` = pass, `1` = violations found. Designed for CI/CD pipelines. Source: [`packages/trustlint/`](packages/trustlint).
## Rule IDs: two namespaces
ComplyEdge resolves the same regulations through two engines, each with its own rule-ID namespace:
- **Runtime API (OPA/Rego):** IDs like `rego-art5-1c-001`: returned by `compliance_check` and the `/v1/check` API. This is the audit trail your production system logs.
- **TrustLint (offline, YAML corpus):** IDs like `EU_AI_ACT_ART5_SOCIAL_SCORING_001`: emitted by the offline linter.
Both cite the same legal article and differ only in engine. Map between them via the article reference carried in every rule.
## What's In This Repo
```
sdks/python/ Python SDK (@compliance_check decorator, CLI)
└ complyedge/mcp_server.py MCP server (stdio): check_compliance, list_rules, scan_prompt
packages/trustlint/ Offline regex linter (TrustLint): no API key, for CI/CD
rules/regulations/ 64 YAML rules (EU AI Act, GDPR, HIPAA, SOX, PCI DSS, and more)
rules/rego/ 64 leaf OPA/Rego policies + 7 package aggregators
rules/schemas/ Rule validation schema
rules/scripts/ Schema validator (`validate_rules.py`)
examples/ Usage examples (decorators, OpenAI Agents)
scripts/benchmark/ Runtime benchmark (runner + prompt YAMLs + committed results)
tests/ Rule validation + acceptance tests
```
## Rules
64 YAML rules + 64 deterministic leaf OPA/Rego policies (+ 7 package aggregators) across 4 jurisdictions.
**What a decision from these policies establishes is not uniform, and we publish the split.** Every leaf decides by matching the evaluated text (no LLM on the hot path). For 21 of them the text *is* the regulated act — Article 5 prohibited practices, Article 15 prompt-injection resilience, one US disclosure control — so a block prevents the act and the citation on the decision is load-bearing. The other 43 fire on text *describing* a state the engine cannot verify: no text matcher can establish whether a technical file, a quality management system, a human-oversight assignment or a FRIA exists. Those are useful for triage; they are not a compliance finding, and their silence is not one either. Per-rule table: [`docs/rules-management/corpus-evidence-classification.md`](docs/rules-management/corpus-evidence-classification.md).
| Jurisdiction | Rules | Regulations |
|---|---|---|
| **EU** | 36 YAML | EU AI Act Articles 4–6, 9–10, 12–16, 26–27, 50, 53, GPAI, GDPR + Art 15 IPI |
| **US** | 16 YAML | HIPAA, SOX, COPPA, TCPA, BIPA, CCPA, Colorado AI Act, NYC LL144, ECPA |
| **Global** | 1 YAML | PCI DSS |
| **Universal** | 11 YAML | PII detection, prompt injection (direct + indirect) |
Each rule specifies conditions, severity, detection scope, and remediation with legal citations. See the [rule schema](rules/schemas/rule-schema.json) for the format.
### Writing Custom Rules
```yaml
id: MY_CUSTOM_RULE_001
jurisdiction: EU
effective_date: "2025-02-02"
description: "Detect prohibited practice X under Article Y"
severity: critical
conditions:
- type: regex
value: "prohibited pattern"
source:
regulation: "EU AI Act"
article: "Article Y(1)(z)"
```
Validate: `cd rules && python scripts/validate_rules.py`
## Architecture
**Layer 1, Deterministic (hot path):** 64 leaf OPA/Rego policies (+ 7 package aggregators) evaluate every request, no LLM. The engine (OPA/Rego + TrustLint) evaluates in 4.87ms p99 in a local microbenchmark against the current 6-package bundle (`layer1_latency_latest.json`, best of 5 trials, 2026-08-04). End-to-end through the live API, the published 60-prompt run measured a p50 of 139ms and p95 of 2,519ms across the 39 OPA-decided prompts, with individual requests spanning 47ms to 10.7s (`runtime_benchmark_latest.json`, 2026-07-28). That run mixes cold and concurrent invocations against a Lambda-backed API, which is where the long tail comes from; we publish the whole run rather than a hand-picked warm figure. Opting into the Layer 2 LLM adds 2–5s on the long tail. Binary pass/block, legal citation on every decision. (TrustLint applies the same regex corpus offline for CI use.)
**Layer 2, Interpretive (synchronous, opt-in):** When called with `use_semantic_fallback=True`, an LLM evaluates the request and blocks if a violation is found. Off by default since v0.2.2. Adds 2–5s latency per request.
Security products protect AI from bad actors. **ComplyEdge blocks EU AI Act violations at runtime: and logs a cited record on every decision.**
## Benchmark
A 60-prompt corpus runs against the live API. The runner, prompt YAMLs, and the latest result JSON are committed under [`scripts/benchmark/`](scripts/benchmark): inspect the results directly, or re-run with your own `COMPLYEDGE_API_KEY`.
## Contributing
We welcome rule contributions. See [CONTRIBUTING.md](CONTRIBUTING.md) for details.
Every rule must include: article + paragraph citation, verifiable detection condition, and test cases.
## Security
To report a vulnerability, see [SECURITY.md](SECURITY.md). Do not open a public issue for security reports.
## License
Apache License 2.0: see [LICENSE](LICENSE).
## Links
- **Website**: [complyedge.io](https://complyedge.io)
- **MCP server docs**: [sdks/python/README.md](sdks/python/README.md) · remote endpoint `https://mcp.complyedge.io/mcp`
- **Blog**: [complyedge.io/blog/](https://complyedge.io/blog/)
- **GPAI Compliance Benchmark**: [complyedge.io/blog/gpai-compliance-benchmark.html](https://complyedge.io/blog/gpai-compliance-benchmark.html)
- **Why OPA/Rego for EU AI Act**: [complyedge.io/blog/why-opa-rego-eu-ai-act.html](https://complyedge.io/blog/why-opa-rego-eu-ai-act.html)
- **PyPI**: [pypi.org/project/complyedge](https://pypi.org/project/complyedge/)
- **Changelog**: [CHANGELOG.md](CHANGELOG.md)
- **Rule Schema**: [rules/schemas/rule-schema.json](rules/schemas/rule-schema.json)