New in the catalogThe EU AI Actarrow_forward

GDPR requirements your engineers and AI agents can actually implement.

RuleMesh defines what to implement across your cloud infrastructure, how to execute it with framework-specific controls, and what evidence proves it was done — ready for engineers and AI agents.

// article_32_1_a.rm
SHALL pseudonymisation AND encryption
IN data_stores AND transit
WHERE risk_assessment_indicates_necessity
USING AES-256, TLS-1.2+
Evidence kms_key_policy.json
GDPR·191 requirements·cloud & security controls
What RuleMesh does

The technical layer between the law and the work.

GDPR tells you the obligation. Security frameworks tell you the control. Auditors ask for proof later. RuleMesh connects those three parts in a form engineers and AI agents can act on.

gavel
Law

Requirement

The cited GDPR obligation.

engineering
Engineering

Control

The engineering action or framework-specific control that satisfies it.

fact_check
Audit

Evidence

The artefact or signal that proves it ran.

How it works

Four steps from
article to
evidence.

01
Connect your agent
Works with Claude Code, Codex, Gemini CLI, Cursor, and other Streamable HTTP MCP clients.
arrow_forward
02
Evaluate your repository
Your coding agent reads the repository in its own environment and compares the relevant files with RuleMesh requirements and evidence criteria.
arrow_forward
03
Generate the evidence signals report
The output shows what was found, what is partial, and what is missing across the relevant GDPR modules.
arrow_forward
04
Track the work in your issue tracker
The Jira app is live; we are building more issue or project integrations.
arrow_forward
Inside your workflow

From GDPR rules
to verified
engineering work.

GDPR rules01
article_32_1_a.rm
Art. 32(1)(a) — Security of Processing
Encryption is one measure a controller may determine is appropriate to the risk.
SHALL implement pseudonymisation
AND encryption
IN data_stores AND transit
WHERE risk_assessment_indicates_necessity
USING AES-256, TLS-1.2+
Cloud implementation
AWS: KMS · S3 SSE · RDS
Azure: Key Vault · SSE
GCP: Cloud KMS
Evidence
· kms_key_policy.json
· tls_config.terraform
· rotation_schedule.yaml
Engineer-ready GDPR rules
Every article becomes a SHALL statement your engineers and AI agents can execute.
Issue tracker02
Compliance in your tracker
Compliance in your tracker
The Jira app is live — posture across your modules, inside the tool your team already uses. We are building more issue or project integrations.
Risk matrix03
Prioritize by risk
Prioritize by risk
See which modules need attention before the next release. High, moderate, low — mapped to Articles.
Checklists04
Verification checklists
Verification checklists
Human review plus agent-scanned evidence signals on every requirement.
By the numbers
191requirements
Structured GDPR IT requirements — versioned, diffable, reviewable.
7modules
Engineering modules mapped to the business-critical flows your team actually ships.
3frameworks
Requirements mapped to the controls that satisfy them: Cloud Security (AWS, Azure, GCP), NIST CSF, and OWASP Top 10.
Frameworks

Mapped across
AWS, Azure, GCP,
NIST & OWASP.

policy
GDPR
191 IT requirements
191
cloud
Cloud Controls
AWS · Azure · GCP
86
shield_lock
NIST CSF
Cyber security framework mappings
185
key
OWASP Top 10
Application security risks
10
Why RuleMesh is different

RuleMesh is built for more than paperwork.

RuleMesh engineers legal obligations into structured rules systems can act on. We are also authoring HCAP, an open protocol for machine-verifiable compliance between systems.

Read the HCAP reportarrow_forwardIETF draft
Built for engineers
“Your coding agent reads your source. RuleMesh does not. The agent reports evidence signals and the file names where signals were detected.”
PD
Privacy by design
MCP-native · agent-agnostic
Reference surfaces

Start from the regulation surface when the question is scope, terms, or next actions.

These pages are for teams working out applicability, definitions, and obligation scope before implementation begins.

Next step

Connect your coding agent first. See what it reports back.

Connect RuleMesh to your coding agent and review the evidence signals from your own repository, against real GDPR requirements.

Connect RuleMesh to your coding agentarrow_forward