Compliance for AI-built applications

Audit-ready AI governance — without the enterprise GRC overhead

Eleven first-class framework packs including EU AI Act, ISO 42001, NIST AI RMF and OWASP LLM Top 10. Append-only audit trail enforced at the database. Row-level tenant isolation. Self-host on your own cluster or use the managed SaaS.

Framework library

Eleven first-class packs — EU AI Act, EU Cyber Resilience Act, ISO/IEC 42001, ISO 23894, NIST AI RMF, NIST AI 600-1, MITRE ATLAS, OWASP LLM Top 10, Cyber Essentials, Cyber Essentials Plus, plus an AI-governance starter pack. One-click import per framework.

Compliance in the AI agent's context

An MCP server gives Claude Code the active requirements, open gaps, and a pre-edit check_change consult. When engineers work in their IDE, the AI already knows which requirements their changes affect — and can log evidence against the right control without leaving the editor.

Controls → requirements → evidence

Opinionated data model built for traceability. Link evidence to requirements and requirements to the code changes that produced them.

Gaps you can act on

Log gaps against requirements with severity, target dates, and remediation tasks. AI-summarised so you know what to do next.

Team-ready

Organizations, projects, and invite flows. Owners / admins / members with enforced roles. Per-user API tokens for the MCP.

Your data, your cluster

Ships as a Next.js app + Postgres. Self-host on your own infrastructure with daily backups, or use the SaaS. No telemetry home.

An audit trail written when the work happens

Most AI-compliance tooling waits for someone to upload evidence to a portal weeks after the work. Tracker's MCP server puts the control graph — active requirements, open gaps, and a pre-edit check_changeconsult — directly in Claude Code's context. An engineer fixing a prompt-injection bug can ask “log a gap for prompt injection in the agent service” — and the write lands against the right requirement, visible to the whole team. The result: an audit trail written when the work happens, not when the auditor asks.

# one-time, from any terminal
$ claude mcp add tracker --transport http \
https://app.tracker.trythis.digital/mcp \
--header "Authorization: Bearer trk_..."
# then, in any Claude Code session
you: mark AI-1.2 as met and attach this PR as evidence
→ calls mcp__tracker__update_requirement
→ calls mcp__tracker__add_evidence
✓ visible in the web app in 200ms

Start your EU AI Act readiness in 60 seconds

Sign up, create a workspace, import a framework. Invite the rest of your team when you're ready.