Every artifact your AI touches. Reviewed. Logged. Audit-ready.

Tamper-evident judgment receipts for every change, across code and spreadsheets. Deploys as a GitHub Action. Works with your existing pipeline.

12 regulatory rubric packs. 128 rules. Every one a pattern that runs against your diff.
GUARDSPINE JUDGMENT RECEIPTv0.2.1
#47Add user authentication middleware
sarah-engacme-corp/payments-api247 linesL3CONDITIONS
Reviewers
Codex 5.6
request_changes
Claude Fable 5
request_changes
Kimi K3
approve
Findings
CRITICALHardcoded database password in connection string
HIGHSession tokens stored without encryption
MEDIUMMissing rate limiting on auth endpoint
LOWConsole.log statements in production code
Consensus: 67% agreement | 2 rounds
Sanitization: 3 secrets redacted
Risk: passwordsessiontokencredential
bundle_hash: sha256:9f3a...c7e1
root_hash: sha256:2d81...a4f9
timestamp: 2026-03-15T14:22:08Z
TAMPER-EVIDENT BY DESIGN

Proof that can't be forged.

Every review step -- prompt, model output, findings, consensus -- is individually hashed and chained into a tamper-evident bundle. Modify one byte and the entire chain breaks. No proprietary format. SHA-256 end to end.

PROMPT HASH
SHA-256 of raw prompt
MODEL REVIEWERS
Codex 5.6
Claude Fable 5
Kimi K3
FINDINGS
4 findings hashed
CONSENSUS
67% agreement, 2 rounds
BUNDLE HASHVERIFIED
sha256:9f3a...c7e1
THE GOVERNANCE GAP

Every unchecked commit is a breach waiting for a subpoena.

AI writes code faster than your team can review it. Regulators are not slowing down. The gap between what ships and what is governed grows every sprint. GuardSpine closes it -- automatically, on every PR, with cryptographic proof.

1997
21 CFR Part 11 -- FDA rule requiring audit trails and provable record integrity
Dec 2027
EU AI Act high-risk deadline -- moved from Aug 2026, obligations unchanged
JUDGMENT RECEIPTS

Structured proof that governance happened.

Risk Tier Assigned
Every PR is classified L0-L4 based on file patterns, sensitive zones, and change size.
Models That Reviewed
Multiple AI models review independently. No single model decides alone.
Independent Findings
Each reviewer produces findings before seeing the others. No groupthink.
Cross-Check Results
Round 2 anonymous cross-check. Models evaluate each other's findings.
Consensus Decision
Majority vote with ties breaking strictest. Agreement score quantified.
Hash Chain
SHA-256 chain from prompt to bundle. One bit changes, the whole chain breaks.
HOW IT WORKS

Your engineers install a GitHub Action. You get the dashboard.

For your engineering team
Add one YAML file to the repo
Reviews trigger on every pull request
Results appear as PR comments
No new tool, no context switching
For you
Dashboard shows every reviewed PR
Evidence bundles for auditors on demand
Compliance mapping across SOC 2, HIPAA, PCI
Export-ready reports -- no manual assembly
The adoption problem is solved by design. Engineers never leave GitHub. Leadership never asks engineers to fill out a form. The governance evidence is a byproduct of the existing workflow.
OPEN SOURCE

You should not trust a proprietary tool to audit your code.

The review engine is open source under Apache 2.0. You can read the code, fork it, run it offline. Evidence bundles are verified with an open-source tool. No vendor lock-in for the core governance function.

View on GitHub
evidence-bundle.json
{
  "bundle_hash": "sha256:9f3a...c7e1",
  "root_hash": "sha256:2d81...a4f9",
  "prompt_hash": "sha256:7b2c...e3d8",
  "reviewers": [
    { "model": "gpt-5.6-sol", "response_hash": "sha256:..." },
    { "model": "claude-fable-5", "response_hash": "sha256:..." },
    { "model": "kimi-k3", "response_hash": "sha256:..." }
  ],
  "consensus": { "decision": "CONDITIONS", "agreement": 0.67 },
  "timestamp": "2026-07-28T09:14:02Z"
}
700+ testsApache 2.0BYOKOffline verify

Control-based frameworks ask whether you have a process. Record-based ones ask you to produce the artifact and prove where it came from.

We ship rules for both. The second kind is why customers call us.

Record-based -- the regulator asks for the artifact
21 CFR Part 11
Electronic records, audit trails, signatures
7 rules
Org
DORA ICT
ICT risk and change-management evidence
8 rules
Org
EU AI Act
Art. 11 technical documentation, Art. 12 logging
8 rules
Org
NACHA
US payments processing requirements
8 rules
Org
PSD2 SCA
Strong customer authentication
8 rules
Org
SOX ITGC
Change-control evidence for financial systems
9 rules
Org
Control-based -- the regulator asks whether you have a process
CMMC Level 1
17 rules
Enterprise
CPCSC Level 1
17 rules
Enterprise
GDPR privacy-by-design
7 rules
Team
HIPAA safeguards
13 rules
Org
PCI DSS
16 rules
Org
SOC 2
10 rules
Team
GuardSpine complements Vanta and Drata. They prove your infrastructure is configured. We prove your artifacts were governed. Your auditor gets both.
PRICING

Starts at less than your Drata bill.

Starter
$399/mo
$4,788/yr
1 repo
Up to 5 users
Email support
Community Slack
POPULAR
Team
$1,600/mo
$19,200/yr
Up to 10 repos
Up to 25 users
Priority support
Custom rubric packs
Org
$10,000/mo
$115,200/yr
Unlimited repos
Unlimited users
Dedicated CSM
SSO / SAML
Enterprise
Custom
Contact us
Air-gapped deploy
On-prem Ollama
Custom integrations
SLA guarantee
Platform fee, not per-seat. Add engineers without changing your bill.
THE TEAM

Built by operators, not observers.

David Youssef
David Youssef
CEO & Architect

10 years in enterprise sales and AI adoption. Designed the governance architecture from first principles. Published researcher.

Igor Malovitsa
Igor Malovitsa
CTO

13 years in systems engineering. Rust, cryptography, distributed systems. MSc in Physics. Builds the things that can't break.

FAQ

Common questions

See how GuardSpine produces audit-ready evidence for every code change.

Starts at $399/mo. Platform fee, not per-seat.

By submitting, you agree to be contacted about your trial request.

Open-source engine|Evidence verified offline|BYOK -- no inference costs