EU AI Act deadline: Aug 2, 2026. EU CRA compliance deadline: Sep 11, 2026. MergeGuide is building SBOM generation ahead of the EU CRA mandate.
AI Governance Platform — Now Available

AI Velocity.
Enterprise
Governance.

The governance platform for AI-assisted development. Enforce your compliance policies across 4 layers — IDE, AI assistant, Git, and PR Gate — with OSCAL export and PolicyMerge for multi-framework deconfliction.

337
Total rule assets across 2 engines
22
Compliance frameworks built
4
Enforcement layers
mergeguide — policy check in progress
$ mergeguide scan --framework SOC2,HIPAA,PCI-DSS --policy-merge
ℹ Loading policy set for 3 active frameworks...
✓ PolicyMerge: 3 frameworks → 1 unified policy set
├── 67 shared controls — assessed once, covers all three
└── SOC 2 strictest-wins on 14 overlapping controls
⚠ HIGH api/auth/jwt.py:83 python.jwt.hardcoded-secret
└── Violates SOC 2 CC6.1 · HIPAA §164.312(a)(1) · PCI 6.3.1
⚠ MED services/db/queries.js:241 sqli.unparameterized
✓ OSCAL export: ready (Assessment Results · Component Def · POA&M)
✓ Evidence retained: immutable · exceeds all framework requirements
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Findings: 2 HIGH · 7 MED · 3 LOW
Coverage: SOC 2 78% · HIPAA 84% · PCI 91%
Report: Unified PDF · OSCAL JSON · CSV
SOC 2 Type II Ready
OSCAL Compliant
EU AI Act
337
Rule assets — 106 Semgrep + 237 regex patterns
22
Compliance frameworks — 18 individual + 4 bundles
14
Languages supported
4
Enforcement layers — IDE, AI, Git, PR
How It Works

Governance where you already work.

Four enforcement layers catch violations at every stage — IDE, AI assistant, Git hooks, and PR gate. No new tools. No context switching. No violations reaching production.

1

IDE — Real-Time Feedback

Detection rules surface as diagnostics in VS Code while you code. Violations are caught the moment they're written — human or AI-generated.

2

Policy Injection — AI Generates Compliant Code

Your AI coding assistant queries your active compliance policies before generating code. Violations are prevented at the source — before a line is written, not caught in review.

3

Git Hooks — Pre-Commit Validation

Before code leaves your machine, Git hooks validate against your organization's policies. Issues stay local, not in CI.

4

PR Gate — Server-Side Enforcement

The authoritative enforcement point. PR Gate blocks merge on violations and generates immutable evidence artifacts — cryptographically signed, audit-ready.

Works with the tools your team already uses

Why MergeGuide

Built for the AI development era.

AI coding assistants generate code faster than traditional review processes can validate. MergeGuide provides governance at every layer — before code is committed, not after.

For Engineering Leaders

Ship AI-assisted code with confidence.

Faster PR cycles — violations caught before submission
Consistent standards across all code — human or AI-generated
No workflow disruption — governance in existing tools
Defense-in-depth — 4 layers catch what one misses
🛡️

For Security & Compliance

Compliance without the friction.

22 pre-built frameworks — SOC 2, HIPAA, PCI-DSS, ISO 27001, NIST 800-53, EU AI Act, DORA, FedRAMP, and more
OSCAL v1.1.2 native export — drops into Vanta, Drata, Hyperproof, eMASS
PolicyMerge: one assessment, every framework — strictest-wins deconfliction
💻

For Developers

No new tools. Real-time feedback.

VS Code extension — real-time diagnostics in your IDE
Know about violations as you code, not after review
AI policy injection — your AI assistant generates compliant code by default
Free tier for individuals — OWASP Top 10 + CWE Top 25
Detection Engine

Dual-layer detection.
Zero blind spots.

MergeGuide runs two independent detection engines in parallel — structural AST-based Semgrep rules and high-precision regex pattern matching — across 14 programming languages.

106
Semgrep YAML Rules
AST-aware · Cross-file data flow · Low false positives
101
Regex Policies — 237 Patterns
Secrets, PII, hardcoded creds · Ultra-fast · High recall
337 total rule assets · 101 catalog controls mapped
106 Semgrep rules + 237 regex patterns · OWASP, CWE, NIST, SOC 2
PythonJavaScriptTypeScript GoJavaPHP RubyC#Kotlin SwiftRustC / C++ TerraformDockerfile
What We Detect
🔐
Secrets & Credentials
API keys, tokens, hardcoded passwords, private keys
🛡️
Injection Vulnerabilities
SQL, Command, LDAP, XPath — OWASP A03
👤
PII Leakage
SSN, email, credit card patterns in logs & responses
🔓
Auth & Crypto Misconfigurations
Weak algorithms, missing HTTPS, JWT issues
📋
Custom Policy Violations
Org-specific policies — pre-built templates or custom-authored
Detection Quality
13 languages supported · 207 detection rules · 78% compliance framework control coverage
Quality-tested across all supported languages · Continuously improved
22 Compliance Templates — 18 Individual + 4 Industry Bundles

Every framework your auditor asks for.

Pre-built, auditor-ready compliance templates — not empty shells. Each template ships with detection patterns mapped to 101 catalog controls, evidence requirements, immutable retention that exceeds every major framework's requirement, and OSCAL-compatible export.

Financial Services BundlePCI-DSS + SOC 2 + DORA
Healthcare BundleHIPAA + SOC 2
Government/Federal BundleNIST SSDF + NIST 800-53 + FedRAMP
EU Compliance BundleGDPR + DORA + NIS2 + EU AI Act
OSCAL v1.1.2 Native Export
3
Document types — Assessment Results, Component Definition, POA&M

Machine-readable OSCAL JSON/XML/YAML that drops directly into Vanta, Drata, eMASS, and any OSCAL-compliant GRC platform. Deterministic UUIDs — stable identifiers across runs. No manual re-entry.

Evidence Retention
Immutable
Exceeds every major framework's retention requirement

Every evaluation generates a cryptographically signed, timestamped evidence artifact. Audit preparation is continuous — not a scramble when your auditor arrives.

Regulatory Deadlines

Three mandates. One platform.

The compliance window is closing. MergeGuide delivers EU AI Act high-risk system controls and EU CRA vulnerability reporting, with SBOM generation in development ahead of the mandate deadline.

Aug 2, 2026

EU AI Act

High-risk AI system requirements take effect. Organizations deploying AI in regulated sectors must demonstrate governance controls — or face penalties up to €30M or 6% global turnover.

Sep 11, 2026

EU Cyber Resilience Act

Mandatory vulnerability reporting and SBOM requirements for products with digital elements. MergeGuide covers vulnerability reporting now; SBOM generation is in development ahead of the deadline. Fines: €15M or 2.5% global turnover.

Active Now

US Federal & State Mandates

Colorado AI Act in effect. Executive Order 14028 and US Army procurement require SBOM for federal software suppliers — SBOM generation is in development. FedRAMP and StateRAMP compliance required for government contracts.

PolicyMerge — Unified Compliance

Running SOX, PCI-DSS, and NY DFS?
You're doing it three times over.

Financial services organizations subject to multiple compliance frameworks assess the same underlying controls repeatedly — each framework using slightly different language for the same requirement. PolicyMerge ends that.

The strictest-wins engine analyzes every overlapping control across all your activated frameworks, selects the strictest requirement, and proves that meeting it satisfies all lesser requirements. One assessment. Every framework. Zero redundant work.

Strictest-Wins Deconfliction
Where SOX, PCI-DSS, and NY DFS 23 NYCRR 500 specify different access control requirements, PolicyMerge identifies the strictest and confirms that meeting it satisfies all three — automatically.
Overlap Visualization
Side-by-side matrix showing every shared control across your frameworks with the winning requirement starred. Sankey and Venn diagrams for executive reporting.
Unified Compliance Report
One PDF covering all your frameworks — with per-framework appendices for individual auditors. Fix a control once, close gaps in multiple frameworks simultaneously.
Compliance Savings Calculator
Quantify how much time your team saves by assessing shared controls once instead of N times across N frameworks.
PolicyMerge — Overlap Matrix
3 frameworks merged
Control Area
SOX
PCI-DSS
NY DFS
Winner ★
Encryption at Rest
Sec. 404: IT controls + key mgmt
Req. 3.5: Strong cryptography
§500.15: Encryption of NPI
★ PCI-DSS
Access Control
Sec. 302/404: Access reviews
Req. 7: Least privilege + MFA
§500.07: Access privileges
★ PCI-DSS
Audit Logging
Sec. 802: 7-year retention
Req. 10.7: 1-year log retention
§500.06: Audit trails 3 years
★ SOX
67 shared controls — assessed once, covers SOX, PCI-DSS, and NY DFS
Meeting the ★ requirement satisfies all lesser requirements automatically
67%
work reduction

Built for financial services complexity. SOX, GLBA, PCI-DSS, NY DFS 23 NYCRR 500, FinCEN/BSA, and SEC Cybersecurity Disclosure Rule — PolicyMerge deconflicts them all into one unified assessment. One security posture. Every regulator covered.

Policy Platform

Start with pre-built templates.
Make them yours.

22 pre-built compliance templates for immediate deployment. Custom policies encode your organization's specific standards — then enforce them at every layer across VS Code, Git hooks, and PR Gate.

📋

Policy Templates

22 frameworks — deploy in one click.

SOC 2, HIPAA, PCI-DSS, ISO 27001, GDPR, NIST, DORA, EU AI Act, and 14 more
Custom policies — author your own from scratch or extend templates
Policy-as-code: version-controlled, travels with the repository
Per-org severity tuning and file-level targeting
🔒

Enterprise Auth

Every auth protocol your enterprise requires.

SAML 2.0 IdP-initiated & SP-initiated
OIDC (OpenID Connect) + OAuth 2.0 + PKCE
SCIM v2 directory sync — automated provisioning
WebAuthn / FIDO2 passkeys + TOTP MFA
🔌

Built-in Integrations

Native connections to the platforms your team already uses.

SCM: GitHub, GitLab, Bitbucket, Azure DevOps
GRC: Vanta, Drata, Hyperproof
Notifications: Slack, Jira, Linear, Teams, email
Pricing

Pricing that scales with your team.

Start free — no credit card required. IDE extension, MCP server, and Git hooks are unlimited at every tier. Free tier includes OWASP Top 10 + CWE Top 25 with PR Gate (50 evaluations/month, resets monthly). Upgrade to Pro for unlimited PR Gate evaluations and additional frameworks.

Free
$0
Forever free
Get started with AI governance

OWASP Top 10 + CWE Top 25
VS Code IDE extension (unlimited)
AI policy injection (MCP server, unlimited)
Git hooks (pre-commit validation, unlimited)
PR Gate (50 evaluations/month, resets monthly)
Dashboard with evaluation history
Get Started Free
Team
$39
per seat / month
(min 5 seats)
Full-framework compliance

Everything in Pro
SOC 2 Type II + HIPAA
EU AI Act + GDPR
OWASP ASVS L2
PolicyMerge full suite
SBOM generation (Coming Q2 2026)
OSCAL v1.1.2 export
SSO / SAML / OIDC + SCIM
Start Free Trial
Business
$79
per seat / month
(min 10 seats)
Enterprise-grade governance

Everything in Team
NIST SP 800-53 Rev 5
ISO 27001:2022 + SLSA v1.0
FedRAMP Moderate + StateRAMP
OSCAL webhook push
Immutable evidence artifacts
Multi-tenant RBAC + Team
Dedicated CSM + SLA
Contact Sales
Enterprise
Custom
 
Defense-in-depth at scale

Everything in Business
DORA + NIS2 + Colorado AI Act
GovCloud deployment (FedRAMP High, IL4/IL5)
Custom detection rule development
White-label options
Dedicated government tenant
CAC/PIV authentication
Air-gapped deployment
Contact Sales
Annual billing available. Special pricing for qualifying startups and nonprofits. View full feature comparison →
Comparison

MergeGuide vs. the alternatives.

Point tools handle pieces. MergeGuide handles the whole — and works before code is written, not after.

Capability MergeGuide Traditional SAST AI Security Tools GRC Platforms
Timing
When enforcement happens Before code written After commit (CI/CD) After AI generates After the fact
AI policy injection (prevents violations at generation) Traffic intercept only
Enforcement
4-layer defense-in-depth 1–2 layers 1 layer
IDE real-time feedback Some Some
PR Gate (server-side block) Some
Compliance
22 pre-built framework templates Partial
PolicyMerge (multi-framework deconfliction)
Immutable evidence artifacts Varies
SBOM generation (CycloneDX 1.5 + SPDX 2.3) — Coming Q2 2026 Varies
OSCAL-compliant export (Assessment Results, Component Def, POA&M) Rare