How it works
Your coding agent does the review. TwinEthos supplies the law.
TwinEthos is a maintained data layer, delivered over MCP. Your agent asks which rules and detectors apply to the repository, inspects the code itself, and cites the exact provision behind each finding.
The flow at a glance
- TwinEthos
Official law, captured
Laws, regulations and standards from 30+ jurisdictions, quoted from the official text and re-checked every week.
- TwinEthos
Turned into checks for code
Each rule says who it applies to, what to look for in code, and the exact provision to cite. Recommended guardrails sit alongside, labeled as opinion.
- Your coding agent
Asks what applies
Claude Code, GitHub Copilot or Cursor calls TwinEthos over MCP with your repository's AI patterns and markets.
- Your machine
Pinpoints the code
Local triage runs the detectors on your repository and points at the files and lines to check. Your code never leaves your machine.
- Your pull request
Findings you can act on
Each finding names the file and line, the exact provision, and its lane: law in force, law coming, standard, or recommended guardrail.
Blind, paired tests on 17 synthetic apps, one run per configuration; method and limits. Informational data, not legal advice.
One review, step by step
- Describe the repository. The agent calls
review_checklistwith the repository's AI integration patterns (chat, RAG, agentic, decision pipeline, …) and the jurisdictions where its users are. - Get detectors, most-exposed first. TwinEthos returns what to look for: file globs, SDK calls, data flows, settings, and missing artifacts — not paragraphs of legal prose. Binding law comes first, then standards, then recommended guardrails.
- Inspect the code. The agent checks each detector and reports
detected,not_detected, orinsufficient_evidencewith file and line evidence. - Cite and sort. Each finding names its rule;
get_rulereturns the citation, the official URL, and the verbatim text of government-edict sources. Findings are reported in four lanes.
Four lanes that never blur
| Lane | Meaning |
|---|---|
| Binding law — in force | Law that applies now: a current legal-exposure question for your counsel. |
| Binding law — not yet in force or stayed | Enacted but not yet applicable (or stayed): reported with its applies-from date, never as a current violation. |
| Standard / soft law | NIST, ISO, IEEE, OECD, sector guidance: a gap against a named standard. |
| TwinEthos recommendation (not law) | TwinEthos's own recommendation: what a responsible AI integration does anyway. Opinion, never law. |
A law that is enacted but not yet in force is reported with its date, never as a current violation. A standard is reported as a gap against that named standard. A recommended guardrail is always labeled as TwinEthos's opinion.
Rules from official text, kept current
- Anchored to the source. Every legal rule is anchored to a verbatim quote of the official source, checked by hash. Licensed standards (for example ISO and IEEE) are cited, never quoted.
- Re-checked weekly. A watcher re-checks every stored provision against the live official document and flags drift. Some official hosts block automated clients; those are checked by hand.
- Broad coverage. 103 binding-law AI rules across 25+ jurisdictions, plus standards and recommended guardrails. A separate AI-adjacent group adds 11 privacy and biometric rules (Illinois BIPA, Texas, Washington, GDPR) where AI data flows trigger them, labeled apart from AI law. Browse the catalog.
- Dated. Every pack states the date its sources were last verified; versioned data releases come with a change feed.
Knows when a law doesn't apply
Every checklist item says who the duty falls on and whether code can show it at all. A training-data duty on model developers isn't reported against an app that only calls a hosted model; a management-system standard isn't reported as a code defect; a consumer right isn't applied to employees when the law's own definition excludes them. Where applicability depends on facts outside the repository, the item is marked for human determination.
Recommended guardrails, labeled as opinion
Law sets a floor. Recommended guardrails cover what a responsible AI integration does anyway, each backed by graded real incidents. They are labeled as TwinEthos opinion at every layer of the data.
- Law-derived — engineering controls that make a legal duty work: disclosure that reaches the person, reproducible decision records, substantive human review.
- Agent security — untrusted-content isolation, least-privilege tools, permission-aware retrieval, tool-server authentication, memory-write controls.
- Operational integrity — controls that quietly disappear under cost pressure: scoped caches, guards that fail closed, re-evaluation on every model change.
- Ethical use (opt-in, advisory) — engagement design, sycophancy, substantiated capability claims, training consent, age signals. Never reported as a violation.
What TwinEthos is not
- Not legal advice, and not a verdict on whether you meet any law. Findings are evidence your team and counsel can verify quickly against the cited official text.
- Not a scanner or CI service. Your coding agent (or scanner) does the inspecting; TwinEthos keeps the data correct, cited, and current.
- Not general code security. Scope is how software integrates with AI, and what is detectable in code or repository artifacts.