Evidence packs, not dead docs.
runward's compliance angle was framing. It becomes a deliverable: runward compliance turns your conformance work into a regime-framed evidence pack, hand-ready and interoperable. Deterministic, read-only, zero-LLM, never a compliance claim.
The runward compliance <regime> command
It reads your real artifacts at rest (OWASP ASI coverage, rule-conformance status, ADR journal, threat model) and assembles a regime-framed assessment-readiness draft:
- ISO/IEC 42001: the Statement of Applicability's status + evidence-pointer columns, and the risk & decision records.
- NIST AI RMF: an ASI-to-subcategory crosswalk and the MEASURE/TEVV documentation.
- EU AI Act: an Annex IV coverage map, where your ADR journal is a near-verbatim fit for Point 2's design-choice requirement.
And crucially, it explicitly flags the gaps only you can fill: applicability, risk acceptance, management sign-off, the EU declaration of conformity. The machine fills what it can and tells you what remains.
OSCAL: the evidence becomes interoperable
Every run also writes an OSCAL component-definition (the machine-readable standard for control evidence), with deterministic UUIDs for byte-identical re-runs. runward's engineering evidence flows into GRC tools and auditor workflows (Vanta, Drata) rather than competing with them. runward is an upstream provenance layer, not a platform.
The moat: nobody else derives evidence from a human-ratified decision journal. The others scrape live state or LLM-draft it. runward assembles from ratified artifacts, never a model draft.
Honest by construction: a draft, supporting evidence, never "compliant" or "certified". Decided before the code (ADR-0016), proven by the test suite.
Install: npx runward init
Release v0.11.0 on GitHub · CHANGELOG
← All news