runward

RW™ · V0.11.0

Evidence packs, not dead docs.

runward's compliance angle was framing. It becomes a deliverable: runward compliance turns your conformance work into a regime-framed evidence pack, hand-ready and interoperable. Deterministic, read-only, zero-LLM, never a compliance claim.

The runward compliance <regime> command

It reads your real artifacts at rest (OWASP ASI coverage, rule-conformance status, ADR journal, threat model) and assembles a regime-framed assessment-readiness draft:

  • ISO/IEC 42001: the Statement of Applicability's status + evidence-pointer columns, and the risk & decision records.
  • NIST AI RMF: an ASI-to-subcategory crosswalk and the MEASURE/TEVV documentation.
  • EU AI Act: an Annex IV coverage map, where your ADR journal is a near-verbatim fit for Point 2's design-choice requirement.

And crucially, it explicitly flags the gaps only you can fill: applicability, risk acceptance, management sign-off, the EU declaration of conformity. The machine fills what it can and tells you what remains.

OSCAL: the evidence becomes interoperable

Every run also writes an OSCAL component-definition (the machine-readable standard for control evidence), with deterministic UUIDs for byte-identical re-runs. runward's engineering evidence flows into GRC tools and auditor workflows (Vanta, Drata) rather than competing with them. runward is an upstream provenance layer, not a platform.

The moat: nobody else derives evidence from a human-ratified decision journal. The others scrape live state or LLM-draft it. runward assembles from ratified artifacts, never a model draft.

Honest by construction: a draft, supporting evidence, never "compliant" or "certified". Decided before the code (ADR-0016), proven by the test suite.


Install: npx runward init

Release v0.11.0 on GitHub · CHANGELOG

← All news