Your AI policy, in force.
Checked against the AI you actually run.

Upload the document. Confirm what it states. It checks your registries, every day. Every gap is a finding in your policy's own words, and every activation is sealed in the Evidence Vault.

Your AI policy, in force

Every organization has an AI policy. Few can say which version governs.

The policy is a PDF in a shared drive. Nobody is sure which copy the board approved, when it must be reviewed next, or whether a single AI system in production meets what it says. An AI policy that nobody checks is a statement of intent, not a control.

Policy Center puts your own AI policy in force. One version governs at a time, the rules it states are checked against what you actually run, and the gaps are listed under the rule that produced them, in your own words. The document stays the source of truth. The document proposes. A person confirms.

Upload the document. Confirm what it states. It checks your registries, every day.

01 · Upload

PDF or Word, hashed on arrival and scanned before anyone can download it. Uploading is not approving: a new document is a draft until an administrator activates it.

02 · Activate

One version governs at a time. Activating a new one supersedes the last, and the activation is sealed in the Evidence Vault.

03 · Confirm

PulseAI reads the document and proposes the rules and context values it states, each with its verbatim quote and section. Nothing is authoritative until a person confirms it.

04 · Evaluate

The confirmed rules run against your model and use case registries every day, and again whenever something changes. No model decides. A rule holds, or it does not.

Eight kinds of rule, in your policy's own words.

A rule is an obligation your policy states, shown as one plain sentence with the quote it came from. What the registry can decide is checked automatically. What it cannot becomes a stated expectation and an attestation question, never a finding.

The facts your policy states about you, with provenance.

A policy does more than set rules. It states how much risk your organization will accept, which committee oversees AI, and what makes an AI use case material. Where your document says so, PulseAI proposes those values too, each with its quote and section, and a confirmed value goes into your Organization Context with the policy version and clause it came from recorded beside it.

That context is what recommendations, executive narratives, and your AI assistant are allowed to rely on. Every field shows who confirmed it and when, and it flags itself for review the moment the policy version it cites is no longer the one in force. What the document does not state stays yours to enter.

Read from the policy when it states them

  • Risk appetite for operational, compliance, reputational, financial, and privacy risk, each domain on its own
  • The board or committee accountable for AI oversight
  • What makes an AI use case material to your organization

One rule. One system. One gap.

In your policy's own words

Every gap is a finding under the rule that produced it, with a severity, the system it is about, and the date it was first seen, pinned to the policy version that produced it.

Never evaluated is not zero

Until the first evaluation has run, the page says Never evaluated rather than showing zero findings. An empty list means you are clean only once something has looked.

Accepting a gap is not fixing it

A known, accepted gap becomes an exception: approved by whoever your policy names, limited to the term it allows, with a compensating control on the record. Accepted findings stay visible beside open ones. The record says which.

It expires by itself

When an exception runs out, the findings it covered reopen on their own. Nobody has to remember.

The policy says. The record shows.

On every model and use case

A Policy tab, with a dated clean claim

Each system lists the rules of your active policy that apply to it: met, unmet, or not checked automatically. "Meets every applicable rule" carries the date of the evaluation that looked.

In the Evidence Vault

Every activation, sealed

A write-once record of which version began to govern, from when, who activated it, and the document's hash. Later edits cannot change what it says about that day.

In the governance health report

Open findings as a health signal

Open policy findings, a missing policy, and an overdue review are health signals of their own, in the weekly report and on the dashboard.

From your AI assistant

Ask which rules are unmet right now

Through the PulseAI MCP server, Claude, ChatGPT, or Copilot can already ask which policy rules are unmet, and are told to say "your policy requires", never "the standard requires". Full Policy Center access from your AI assistant is coming soon.

Four things that stay true.

Your policy, not a regulatory finding

An internal rule is a requirement your organization set. It is never dressed up as ISO/IEC 42001 or the EU AI Act, and its framework field is empty for exactly that reason.

One version in force

Drafts are dormant. Exactly one version governs, hashed and pinned, and every download is that version.

Deterministic

No model decides whether a system complies. A rule holds, or it does not.

Honest unknowns

Unknown is not breach. What the registry cannot decide asks for a recorded attribute, at the lowest severity, and never counts as a violation.

Live in Canada and the United States.

Policy Center is available to design partners today. Bring the policy your board approved and we will walk through the upload, the activation, and the first evaluation with your own document.

No commitment required · partnerships@pulseai.now