TwinEthosRequest access

How it works

Your coding agent does the review. TwinEthos supplies the law.

TwinEthos is a maintained data layer, delivered over MCP. Your agent asks which rules and detectors apply to the repository, inspects the code itself, and cites the exact provision behind each finding.

The flow at a glance

  1. TwinEthos

    Official law, captured

    Laws, regulations and standards from 30+ jurisdictions, quoted from the official text and re-checked every week.

  2. TwinEthos

    Turned into checks for code

    Each rule says who it applies to, what to look for in code, and the exact provision to cite. Recommended guardrails sit alongside, labeled as opinion.

  3. Your coding agent

    Asks what applies

    Claude Code, GitHub Copilot or Cursor calls TwinEthos over MCP with your repository's AI patterns and markets.

  4. Your machine

    Pinpoints the code

    Local triage runs the detectors on your repository and points at the files and lines to check. Your code never leaves your machine.

  5. Your pull request

    Findings you can act on

    Each finding names the file and line, the exact provision, and its lane: law in force, law coming, standard, or recommended guardrail.

83–100%of legal findings cite the exact provision with TwinEthos, versus 0–57% alone
100%exact citations on law newer than the model's training (Claude Haiku)
About $2of model usage for a full 17-app review with a small model
Claude and GPTreviewers both improve: the data is model-agnostic

Blind, paired tests on 17 synthetic apps, one run per configuration; method and limits. Informational data, not legal advice.

One review, step by step

  1. Describe the repository. The agent calls review_checklist with the repository's AI integration patterns (chat, RAG, agentic, decision pipeline, …) and the jurisdictions where its users are.
  2. Get detectors, most-exposed first. TwinEthos returns what to look for: file globs, SDK calls, data flows, settings, and missing artifacts — not paragraphs of legal prose. Binding law comes first, then standards, then recommended guardrails.
  3. Inspect the code. The agent checks each detector and reports detected, not_detected, or insufficient_evidence with file and line evidence.
  4. Cite and sort. Each finding names its rule; get_rule returns the citation, the official URL, and the verbatim text of government-edict sources. Findings are reported in four lanes.

Four lanes that never blur

LaneMeaning
Binding law — in forceLaw that applies now: a current legal-exposure question for your counsel.
Binding law — not yet in force or stayedEnacted but not yet applicable (or stayed): reported with its applies-from date, never as a current violation.
Standard / soft lawNIST, ISO, IEEE, OECD, sector guidance: a gap against a named standard.
TwinEthos recommendation (not law)TwinEthos's own recommendation: what a responsible AI integration does anyway. Opinion, never law.

A law that is enacted but not yet in force is reported with its date, never as a current violation. A standard is reported as a gap against that named standard. A recommended guardrail is always labeled as TwinEthos's opinion.

Rules from official text, kept current

  • Anchored to the source. Every legal rule is anchored to a verbatim quote of the official source, checked by hash. Licensed standards (for example ISO and IEEE) are cited, never quoted.
  • Re-checked weekly. A watcher re-checks every stored provision against the live official document and flags drift. Some official hosts block automated clients; those are checked by hand.
  • Broad coverage. 103 binding-law AI rules across 25+ jurisdictions, plus standards and recommended guardrails. A separate AI-adjacent group adds 11 privacy and biometric rules (Illinois BIPA, Texas, Washington, GDPR) where AI data flows trigger them, labeled apart from AI law. Browse the catalog.
  • Dated. Every pack states the date its sources were last verified; versioned data releases come with a change feed.

Knows when a law doesn't apply

Every checklist item says who the duty falls on and whether code can show it at all. A training-data duty on model developers isn't reported against an app that only calls a hosted model; a management-system standard isn't reported as a code defect; a consumer right isn't applied to employees when the law's own definition excludes them. Where applicability depends on facts outside the repository, the item is marked for human determination.

Recommended guardrails, labeled as opinion

TwinEthos recommendations — not law

Law sets a floor. Recommended guardrails cover what a responsible AI integration does anyway, each backed by graded real incidents. They are labeled as TwinEthos opinion at every layer of the data.

  • Law-derived — engineering controls that make a legal duty work: disclosure that reaches the person, reproducible decision records, substantive human review.
  • Agent security — untrusted-content isolation, least-privilege tools, permission-aware retrieval, tool-server authentication, memory-write controls.
  • Operational integrity — controls that quietly disappear under cost pressure: scoped caches, guards that fail closed, re-evaluation on every model change.
  • Ethical use (opt-in, advisory) — engagement design, sycophancy, substantiated capability claims, training consent, age signals. Never reported as a violation.

Browse the recommended guardrails

What TwinEthos is not

  • Not legal advice, and not a verdict on whether you meet any law. Findings are evidence your team and counsel can verify quickly against the cited official text.
  • Not a scanner or CI service. Your coding agent (or scanner) does the inspecting; TwinEthos keeps the data correct, cited, and current.
  • Not general code security. Scope is how software integrates with AI, and what is detectable in code or repository artifacts.