Questions

Answers, hardest first.

The questions buyers and their AI agents actually ask about RuleMesh, answered directly. Hardest first.

Why not just ask my coding agent?

You can, and for one control you should. Ask Claude Code whether your Python logs access to personal data and it will tell you.

The problem is the question you did not ask. An agent answers what you put to it. It cannot tell you which obligations you never mentioned, because the list of what applies to you is not in your repository. You get a confident, well-formatted answer about logging, and silence on everything else, and the silence looks identical to a clean result.

That is the gap RuleMesh fills. Not the answering, the enumerating. Your agent is good at checking a control once it knows which control to check. It has no way to discover that it is looking at eleven obligations and reported on one.

Two smaller things follow from the same point. An agent does not keep the answer, so there is nothing to show three months later. And it does not record the moment, so you cannot say what was true in March. We give the agent the list and keep the record it produces.

Which obligations actually apply to me?

That depends on what you are, not only on what you built, and it is the question most tools skip.

Under the EU AI Act your obligations differ sharply depending on whether you are a provider, a deployer, an importer, a distributor, an authorised representative, a manufacturer or an operator. Build a credit-scoring model in house and you carry provider obligations. Buy the same model and deploy it and you carry deployer obligations, which are different and fewer.

RuleMesh binds every provision to the actor it governs, and separates obligations from permissions and prohibitions. To give a sense of the asymmetry: in our AI Act graph the provider role carries 150 provisions and the deployer role 27. (Those are provisions at article-paragraph level, a structural count, not the requirement counts quoted elsewhere.)

Half the actors in that regulation are supervisory authorities rather than organisations: the Commission, notified bodies, market surveillance authorities, the AI Office. Those articles create no duty for you at all, which is why counting articles overstates what any company actually owes.

Does RuleMesh read my source code?

No. Your coding agent reads your repository, in your environment, using RuleMesh data. RuleMesh never receives, reads, or stores source code.

What leaves your machine is evidence signals and the file names where your agent detected them. We do not run inside your infrastructure and we never ask for cloud credentials.

This is worth a moment in a procurement review. A vendor with read access to your AWS account is a different security assessment from a vendor that holds no credentials and never sees your code. The second review is much shorter.

Will an auditor accept this as evidence?

Not on its own, and we do not claim otherwise.

RuleMesh produces evidence signals, and the word is chosen deliberately. A signal is an observation that something appears to be in place, reported by your agent, for a person to review. It is not an attestation. Only a human can mark an item verified. An agent never can, by design.

What RuleMesh does for your audit is earlier in the chain and, we would argue, more useful: it tells you which obligation applies, which control satisfies it, and what artefact a reviewer will ask for, before the work is done rather than reconstructed after. Most audit pain comes from evidence nobody knew to keep.

If you need continuous collection from live cloud APIs, that is a different product, and the next answer covers it.

Do I still need Vanta or Drata?

Probably, and they solve a different problem.

Vanta, Drata and Sprinto connect to your cloud, identity and HR systems and continuously collect evidence against framework controls. They are good at that, and RuleMesh does not replace it. We hold no credentials and pull no telemetry.

RuleMesh supplies the layer above: the specification. Which statutory obligation applies to your system, which engineering control satisfies it, what configuration counts, and what evidence a reviewer expects. A GRC platform tracks the status of controls someone already decided on. We are how that decision gets made, with the citation still attached.

The clearest split: a GRC platform answers whether your bucket is encrypted. RuleMesh answers which obligation requires it, whether it applies to you at all, and what an auditor will ask for.

Who writes the rules, and who checks them?

The rules are curated, not generated. We do not have a model read the statute and produce requirements, which is the failure mode that puts a hallucinated legal interpretation into your backlog.

Source law is held with its citation, scope and actor role intact. Each requirement is modelled as obligation, control, configuration and evidence. Control mappings run through a review pipeline before they reach the customer-facing graph, and disputed mappings go to human review rather than shipping.

Two honest limits. RuleMesh is not a law firm and gives no legal advice. And where a statute is genuinely open, as GDPR Article 32 is when it asks for measures "appropriate to the risk", the determination remains yours. We make the decision explicit and traceable. We do not pretend the law removed it.

Is the output deterministic?

The rules are. Ask for the same requirement twice and you get the same answer, with the same citation and version. That is the point of a curated graph rather than a model reading law on demand, and it is what makes a claim traceable back to source.

Your agent’s evaluation of your repository is not deterministic, and we would not claim it is. Two agents on two model versions can report different signals from the same codebase. That is why a person reviews the signals and why the rule layer, not the agent layer, is the part we call deterministic.

What happens when the law changes?

The graph is versioned, and changes and interpretations are tracked rather than silently overwritten. On the paid tier, court rulings and regulatory guidance are mapped to the requirements they affect, so a change reaches the requirement rather than sitting in a newsletter.

What does it cost?

The free tier is genuinely free and not a trial. It gives you GDPR structured as engineering requirements, MCP access for your coding agent, the Jira integration, and a sample of control mappings. No card.

Regulatory Intelligence (INTEL) is $299 / €299 per year and includes one governed system. It adds the EU AI Act, complete control mappings rather than a sample, court rulings and regulatory guidance mapped to your requirements, and full write access to generate and track work as evidence signals. Every regulation we release during your subscription is included at no extra cost.

There are no user limits at any tier.

Which regulations are live?

GDPR and the EU AI Act ship today. GDPR is available on the free tier; the EU AI Act needs INTEL.

The roadmap covers 20+ regulations across the EU, US and Australia, with DORA and NIS2 in progress. Those are not available yet and we will not tell you otherwise.

What does RuleMesh not do?

Worth stating plainly, because the answer is longer than most vendors would like.

We do not scan your code, run in your infrastructure, or hold your credentials. We do not collect evidence from live cloud APIs. We do not write your DPIA, manage vendor questionnaires, run security training, or provide an auditor portal. We do not certify compliance, and we do not produce a compliance score, because we are not in a position to grade you and neither is any vendor.

We do not generate requirements with a model, and we do not give legal advice.

Still deciding?

The free tier needs no card. Connect your coding agent and see what it reports back against real requirements.