Policy Center
Upload the document. Confirm what it states. It checks your registries, every day. Every gap is a finding in your policy's own words, and every activation is sealed in the Evidence Vault.
Why it exists
The policy is a PDF in a shared drive. Nobody is sure which copy the board approved, when it must be reviewed next, or whether a single AI system in production meets what it says. An AI policy that nobody checks is a statement of intent, not a control.
Policy Center puts your own AI policy in force. One version governs at a time, the rules it states are checked against what you actually run, and the gaps are listed under the rule that produced them, in your own words. The document stays the source of truth. The document proposes. A person confirms.
How it works
01 · Upload
PDF or Word, hashed on arrival and scanned before anyone can download it. Uploading is not approving: a new document is a draft until an administrator activates it.
02 · Activate
One version governs at a time. Activating a new one supersedes the last, and the activation is sealed in the Evidence Vault.
03 · Confirm
PulseAI reads the document and proposes the rules and context values it states, each with its verbatim quote and section. Nothing is authoritative until a person confirms it.
04 · Evaluate
The confirmed rules run against your model and use case registries every day, and again whenever something changes. No model decides. A rule holds, or it does not.
Rules it reads
A rule is an obligation your policy states, shown as one plain sentence with the quote it came from. What the registry can decide is checked automatically. What it cannot becomes a stated expectation and an attestation question, never a finding.
Organization Context
A policy does more than set rules. It states how much risk your organization will accept, which committee oversees AI, and what makes an AI use case material. Where your document says so, PulseAI proposes those values too, each with its quote and section, and a confirmed value goes into your Organization Context with the policy version and clause it came from recorded beside it.
That context is what recommendations, executive narratives, and your AI assistant are allowed to rely on. Every field shows who confirmed it and when, and it flags itself for review the moment the policy version it cites is no longer the one in force. What the document does not state stays yours to enter.
Read from the policy when it states them
Findings and exceptions
Every gap is a finding under the rule that produced it, with a severity, the system it is about, and the date it was first seen, pinned to the policy version that produced it.
Until the first evaluation has run, the page says Never evaluated rather than showing zero findings. An empty list means you are clean only once something has looked.
A known, accepted gap becomes an exception: approved by whoever your policy names, limited to the term it allows, with a compensating control on the record. Accepted findings stay visible beside open ones. The record says which.
When an exception runs out, the findings it covered reopen on their own. Nobody has to remember.
Where it shows up
On every model and use case
Each system lists the rules of your active policy that apply to it: met, unmet, or not checked automatically. "Meets every applicable rule" carries the date of the evaluation that looked.
In the Evidence Vault
A write-once record of which version began to govern, from when, who activated it, and the document's hash. Later edits cannot change what it says about that day.
In the governance health report
Open policy findings, a missing policy, and an overdue review are health signals of their own, in the weekly report and on the dashboard.
From your AI assistant
Through the PulseAI MCP server, Claude, ChatGPT, or Copilot can already ask which policy rules are unmet, and are told to say "your policy requires", never "the standard requires". Full Policy Center access from your AI assistant is coming soon.
What you can rely on
An internal rule is a requirement your organization set. It is never dressed up as ISO/IEC 42001 or the EU AI Act, and its framework field is empty for exactly that reason.
Drafts are dormant. Exactly one version governs, hashed and pinned, and every download is that version.
No model decides whether a system complies. A rule holds, or it does not.
Unknown is not breach. What the registry cannot decide asks for a recorded attribute, at the lowest severity, and never counts as a violation.
Available now
Policy Center is available to design partners today. Bring the policy your board approved and we will walk through the upload, the activation, and the first evaluation with your own document.
No commitment required · partnerships@pulseai.now