EU AI Act deadline: Aug 2, 2026. EU CRA compliance deadline: Sep 11, 2026. MergeGuide delivers SBOM generation, vulnerability reporting, and AI governance controls.
AI Governance Platform

Your team ships
AI code faster
than you can review it.

MergeGuide embeds governance into every layer of the developer workflow — IDE, AI assistant, Git hooks, and PR Gate — so AI-assisted code meets your standards before it merges. Not after the audit.

Catch at creation
Violations surface in the IDE before commit
One assessment
PolicyMerge deconflicts multiple frameworks
Audit-ready evidence
Immutable, signed artifacts on every evaluation
mergeguide — policy check in progress
$ mergeguide scan --framework SOC2,HIPAA,PCI-DSS --policy-merge
ℹ Loading policy set for 3 active frameworks...
✓ PolicyMerge: 3 frameworks → 1 unified policy set
├── 67 shared controls — assessed once, covers all three
└── SOC 2 strictest-wins on 14 overlapping controls
⚠ HIGH api/auth/jwt.py:83 python.jwt.hardcoded-secret
└── Violates SOC 2 CC6.1 · HIPAA §164.312(a)(1) · PCI 6.3.1
⚠ MED services/db/queries.js:241 sqli.unparameterized
✓ OSCAL export: ready (Assessment Results · Component Def · POA&M)
✓ Evidence retained: immutable · exceeds all framework requirements
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Findings: 2 HIGH · 7 MED · 3 LOW
Coverage: SOC 2 78% · HIPAA 84% · PCI 91%
Report: Unified PDF · OSCAL JSON · CSV
VS Code & Cursor
GitHub · GitLab · Bitbucket · Azure DevOps
MCP Server
Before commit
Violations caught at the moment of creation
Every framework
One unified policy set across all your requirements
Every language
Broad language coverage across your stack
Every layer
IDE, AI assistant, Git hooks, and PR Gate
5 Patents Pending
Policy injection, cryptographic evidence, multi-layer enforcement & PolicyMerge
How It Works

Governance that lives where developers already work.

AI-generated code introduces risk at a pace manual review cannot match. MergeGuide catches violations at every stage — in the IDE, through AI policy injection, at pre-commit, and at the PR gate — without adding tools or switching contexts.

1

IDE — Real-Time Feedback

Policy violations surface as diagnostics in VS Code and Cursor while developers write code. Human or AI-generated — issues appear the moment they're introduced.

2

Policy Injection — AI Generates Compliant Code

Your AI coding assistant queries your active compliance policies before generating code. Violations are prevented at the source — before a line is written, not caught in review.

3

Git Hooks — Pre-Commit Validation

Before code leaves your machine, Git hooks validate against your organization's policies. Issues stay local, not in CI.

4

PR Gate — Server-Side Enforcement

The authoritative enforcement point. PR Gate blocks merge on violations and generates immutable evidence artifacts — cryptographically signed, audit-ready.

Works with the tools your team already uses

Why MergeGuide

The gap between "ships fast" and "ships safely" is widening.

AI-assisted development changed how code gets written. It did not change what your auditors expect. MergeGuide closes that gap — governance at every layer, before code is committed, not after.

For Engineering Leaders

Visibility into what AI is generating across your codebase.

Faster PR cycles — violations caught before submission
Consistent standards across all code — human or AI-generated
No workflow disruption — governance in existing tools
PolicyMesh — 4 graduated layers, earliest possible detection
🛡️

For Security & Compliance

Policy enforcement that scales with AI development velocity.

Pre-built frameworks — SOC 2, HIPAA, PCI-DSS, ISO 27001, NIST 800-53, EU AI Act, DORA, FedRAMP, and more
OSCAL v1.1.2 native export — drops into RegScale, Vanta, and any OSCAL-compliant GRC platform
PolicyMerge: one assessment, every framework — strictest-wins deconfliction
💻

For Developers

Governance in the tools you already use. Nothing new to learn.

VS Code and Cursor — real-time diagnostics in your IDE
Know about violations as you code, not after review
AI policy injection via MCP — your AI assistant generates compliant code by default
Free tier for individuals — get started with zero commitment
Detection Engine

Two engines. One signal.
No blind spots.

MergeGuide runs two independent detection engines in parallel — structural AST-based analysis and high-precision pattern matching — across the languages your team writes in. What one engine misses, the other catches.

AST
Structural Analysis (Semgrep)
AST-aware · Cross-file data flow · Low false positives
RE
Pattern Matching (Regex)
Secrets, PII, hardcoded credentials · High recall
Mapped to OWASP, CWE, NIST, and major compliance catalog controls
Two engines running in parallel — what one misses, the other catches
PythonJavaScriptTypeScript GoJavaPHP RubyC#Kotlin SwiftRustC / C++ TerraformDockerfile
What We Detect
🔐
Secrets & Credentials
API keys, tokens, hardcoded passwords, private keys
🛡️
Injection Vulnerabilities
SQL, Command, LDAP, XPath — OWASP A03
👤
PII Leakage
SSN, email, credit card patterns in logs & responses
🔓
Auth & Crypto Misconfigurations
Weak algorithms, missing HTTPS, JWT issues
📋
Custom Policy Violations
Org-specific policies — pre-built templates or custom-authored
Coverage
Broad language support · Deep compliance framework coverage · Continuously expanding
See documentation for full language list and detection catalog
Compliance Frameworks

The frameworks your auditors ask for.

Pre-built, auditor-ready compliance templates — not empty shells. Each template ships with detection patterns mapped to catalog controls, evidence requirements, immutable retention, and OSCAL-compatible export. Deploy one or deploy many — PolicyMerge handles the overlap.

OSCAL v1.1.2 Native Export
3
Document types — Assessment Results, Component Definition, POA&M

Machine-readable OSCAL JSON/XML/YAML that drops directly into RegScale, Vanta, and any OSCAL-compliant GRC platform. Deterministic UUIDs — stable identifiers across runs. No manual re-entry.

Evidence Retention
Immutable
Exceeds every major framework's retention requirement

Every evaluation generates a cryptographically signed, timestamped evidence artifact. Audit preparation is continuous — not a scramble when your auditor arrives.

Regulatory Deadlines

Three mandates. One platform.

The compliance window is closing. MergeGuide delivers EU AI Act high-risk system controls, EU CRA vulnerability reporting, and SBOM generation requirements — from the same platform that governs your daily development workflow.

Aug 2, 2026

EU AI Act

High-risk AI system requirements take effect. Organizations deploying AI in regulated sectors must demonstrate governance controls — or face penalties up to €30M or 6% global turnover.

Sep 11, 2026

EU Cyber Resilience Act

Mandatory vulnerability reporting and SBOM requirements for products with digital elements. MergeGuide generates SBOMs in CycloneDX 1.5 and SPDX 2.3 formats and integrates vulnerability detection into the development workflow. Fines: up to 2.5% global turnover.

Active Now

US Federal & State Mandates

Colorado AI Act in effect. SBOM generation is an industry best practice for supply chain transparency and increasingly expected in enterprise procurement. MergeGuide provides SBOM generation and compliance framework templates for FedRAMP and StateRAMP requirements.

PolicyMesh — Graduated Enforcement

Same rules. Four layers.
Earliest detection.

PolicyMesh runs the same detection engine at four graduated intervention points — from AI code generation through to PR merge. Violations are caught at the earliest, cheapest moment. Developers stay in flow. Governance happens automatically.

MCP Prevention
AI coding assistants write governed code from the start. Violations prevented before code exists. Claude, Copilot, and Cursor all receive your policies via MCP.
IDE Detection
Real-time feedback as developers type. Violations surface inline in VS Code — fix in seconds, never leave flow state.
Pre-Commit Hooks
Code checked before it leaves the developer's machine. Nothing ungoverned reaches your source control.
PR Gate
Final enforcement before merge. Every pull request assessed against your activated compliance frameworks with full evidence generation.
Cost of Remediation
MCP
0 sec — prevented
IDE
~5 sec — inline fix
Hooks
~5 min — pre-commit fix
PR Gate
~30 min — review cycle
Same detection engine at every layer. Earlier detection = cheaper fix.
PolicyMerge — Unified Compliance

Multiple frameworks.
One assessment.

Organizations subject to multiple regulatory frameworks assess the same underlying controls repeatedly — each framework using slightly different language for the same requirement. PolicyMerge eliminates the redundancy.

The strictest-wins engine analyzes every overlapping control across all your activated frameworks, selects the strictest requirement, and proves that meeting it satisfies all lesser requirements. One assessment. Every framework. No redundant assessments.

Strictest-Wins Deconfliction
Where SOC 2, PCI-DSS, and ISO 27001 specify different access control requirements, PolicyMerge identifies the strictest and confirms that meeting it satisfies all three — automatically.
Overlap Visualization
Side-by-side matrix showing every shared control across your frameworks with the winning requirement starred. Sankey and Venn diagrams for executive reporting.
Unified Compliance Report
One PDF covering all your frameworks — with per-framework appendices for individual auditors. Fix a control once, close gaps in multiple frameworks simultaneously.
Compliance Savings Calculator
Quantify how much time your team saves by assessing shared controls once instead of N times across N frameworks.
PolicyMerge — Overlap Matrix
3 frameworks merged
Control Area
SOC 2
PCI-DSS
ISO 27001
Winner ★
Encryption at Rest
CC6.1: Encryption controls
Req. 3.5: Strong cryptography
A.10.1: Cryptographic controls
★ PCI-DSS
Access Control
CC6.3: Logical access controls
Req. 7: Least privilege + MFA
A.9.2: User access management
★ PCI-DSS
Audit Logging
CC7.2: Monitoring + 1-year retention
Req. 10.7: 1-year log retention
A.12.4: Logging and monitoring
★ SOC 2
67 shared controls — assessed once, covers SOC 2, PCI-DSS, and ISO 27001
Meeting the ★ requirement satisfies all lesser requirements automatically
67%
work reduction

Built for multi-framework complexity. SOC 2, PCI-DSS, ISO 27001, HIPAA, NIST 800-53, EU AI Act, DORA, FedRAMP — PolicyMerge deconflicts them into one unified assessment. One security posture. Every framework covered.

Policy Platform

Start with pre-built templates.
Make them yours.

Pre-built compliance templates for immediate deployment. Custom policies encode your organization's specific standards — then enforce them at every layer across VS Code, Cursor, Git hooks, and PR Gate.

📋

Policy Templates

Major frameworks — deploy in one click.

SOC 2, HIPAA, PCI-DSS, ISO 27001, GDPR, NIST, DORA, EU AI Act, and more
Custom policies — author your own from scratch or extend templates
Policy-as-code: version-controlled, travels with the repository
Per-org severity tuning and file-level targeting
🔒

Enterprise Auth

Every auth protocol your enterprise requires.

SAML 2.0 IdP-initiated & SP-initiated
OIDC (OpenID Connect) + OAuth 2.0 + PKCE
SCIM v2 directory sync — automated provisioning
WebAuthn / FIDO2 passkeys + TOTP MFA
🔌

Built-in Integrations

Native connections to the platforms your team already uses.

SCM: GitHub, GitLab, Bitbucket, Azure DevOps
GRC: RegScale, Vanta, and any OSCAL-compliant GRC platform
Notifications: Slack, Jira, Linear, Teams
Pricing

Start free. Grow at your own pace.

Start free — no credit card required. IDE extension, MCP server, and Git hooks are unlimited at every tier. Sign in to see full pricing and upgrade options.

Free
$0
Forever free
Get started with AI governance

OWASP Top 10 + CWE Top 25
VS Code IDE extension (unlimited)
AI policy injection (MCP server, unlimited)
Git hooks (pre-commit validation, unlimited)
PR Gate (50 evaluations/month, resets monthly)
Dashboard with evaluation history
Get Started Free
Team
$39
per seat / month
(2–9 seats)
Full-framework compliance for growing teams

Everything in Pro
SOC 2 Type II + HIPAA
EU AI Act + GDPR
OWASP ASVS L2
PolicyMerge full suite
SBOM generation (CycloneDX 1.5 + SPDX 2.3)
OSCAL v1.1.2 export
SSO / SAML / OIDC + SCIM
Start Free Trial
Business
Contact Us
10–49 seats
Enterprise-grade governance for scaling organizations

Everything in Team
DORA + ISO 27001:2022
NIST SP 800-53 Rev 5 + SLSA v1.0
FedRAMP Moderate + StateRAMP
OSCAL webhook push
Immutable evidence artifacts
Multi-tenant RBAC + custom roles
Dedicated CSM + SLA
Contact Sales
Enterprise
Contact Us
50+ seats
PolicyMesh governance at enterprise scale

Everything in Business
NIS2 + Colorado AI Act
Custom detection rule development
Dedicated government tenant
Contact Sales
Annual billing available. Special pricing for qualifying startups and nonprofits. View full feature comparison →
Comparison

Traditional tools were not built for AI-generated code.

SAST tools scan after commit. GRC platforms report after the fact. AI security tools intercept but do not enforce. MergeGuide governs the full lifecycle — from the moment code is written to the moment it merges.

Capability MergeGuide Traditional SAST AI Security Tools GRC Platforms
Timing
When enforcement happens Before code written After commit (CI/CD) After AI generates After the fact
AI policy injection (prevents violations at generation) Traffic intercept only
Enforcement
PolicyMesh — 4-layer velocity engine 1–2 layers 1 layer
IDE real-time feedback Some Some
PR Gate (server-side block) Some
Compliance
Pre-built framework templates Partial
PolicyMerge (multi-framework deconfliction)
Immutable evidence artifacts Varies
SBOM generation (CycloneDX 1.5 + SPDX 2.3) Varies
OSCAL-compliant export (Assessment Results, Component Def, POA&M) Rare