Drop two files into any GitLab repo. Claude scans every MR against SOC2, HIPAA, PCI-DSS. Critical violation? Your phone rings.
GitGuard doesn't just use an LLM. It leverages six distinct Anthropic API capabilities to deliver production-grade compliance automation.
See exactly WHY something is a violation with transparent, step-by-step reasoning. Full thinking trace logged for audit compliance.
Every finding references the exact compliance policy clause. Verifiable, not hallucinated. Auditors can trace every decision.
Claude orchestrates GitLab API and Vapi as callable tools — commenting on MRs, creating issues, and triggering phone calls autonomously.
Upload SOC2, HIPAA, PCI-DSS framework documents. Claude analyzes them natively — no parsing, no chunking, no data loss.
Guaranteed JSON schema for compliance reports and audit logs. Machine-readable results feed dashboards and alerting pipelines.
Tracks violation patterns across your codebase. Identifies repeat offenders. Learns your organization's compliance posture over time.
No server. No Docker. No database. Just two files and two environment variables.
sk-ant-... key.api. Copy your glpat-... token.GitLab → Settings → CI/CD → Variables
merge_request_event — push to a branch and open an MR.allow_failure: true in .gitlab-ci.yml.