Eleven first-class framework packs including EU AI Act, ISO 42001, NIST AI RMF and OWASP LLM Top 10. Append-only audit trail enforced at the database. Row-level tenant isolation. Self-host on your own cluster or use the managed SaaS.
Eleven first-class packs — EU AI Act, EU Cyber Resilience Act, ISO/IEC 42001, ISO 23894, NIST AI RMF, NIST AI 600-1, MITRE ATLAS, OWASP LLM Top 10, Cyber Essentials, Cyber Essentials Plus, plus an AI-governance starter pack. One-click import per framework.
An MCP server gives Claude Code the active requirements, open gaps, and a pre-edit check_change consult. When engineers work in their IDE, the AI already knows which requirements their changes affect — and can log evidence against the right control without leaving the editor.
Opinionated data model built for traceability. Link evidence to requirements and requirements to the code changes that produced them.
Log gaps against requirements with severity, target dates, and remediation tasks. AI-summarised so you know what to do next.
Organizations, projects, and invite flows. Owners / admins / members with enforced roles. Per-user API tokens for the MCP.
Ships as a Next.js app + Postgres. Self-host on your own infrastructure with daily backups, or use the SaaS. No telemetry home.
Most AI-compliance tooling waits for someone to upload evidence to a portal weeks after the work. Tracker's MCP server puts the control graph — active requirements, open gaps, and a pre-edit check_changeconsult — directly in Claude Code's context. An engineer fixing a prompt-injection bug can ask “log a gap for prompt injection in the agent service” — and the write lands against the right requirement, visible to the whole team. The result: an audit trail written when the work happens, not when the auditor asks.
Sign up, create a workspace, import a framework. Invite the rest of your team when you're ready.