ComplyPRO AI Governance Platform Architecture
A purpose-built governance operating system uniting static code analysis, policy verification, evidence ledgers, and MCP interoperability for modern AI agent systems.
Purpose-Built for the Agentic Era
Enterprise software architecture has fundamentally changed with the advent of agentic frameworks. Unlike traditional deterministic software, AI agents dynamically choose tools, formulate queries, and chain operations. Traditional GRC software cannot parse code, while traditional static code analyzers (SAST) do not understand AI agent architectures.
ComplyPRO is built specifically for this intersection. It parses multi-agent architectures (CrewAI, LangGraph, AutoGen, OpenAI Swarm), extracts tool decorators and functions, decomposes scopes (production vs. infrastructure vs. test), and correlates observed capabilities against strict governance baselines.
Core Platform Capabilities
The platform delivers five integrated subsystems that operate collaboratively across the AI lifecycle:
- Client-Side Static AST Sensor: Inspects Python and TypeScript repositories directly in the browser with zero source code upload.
- 5-State Epistemic Engine: Classifies discovered capabilities into verified safe, observed without authorization, or heuristically derived states.
- Cryptographic AI Passports: Generates structured, versioned asset passports detailing identity boundaries, authorized tools, and business lineage (SIPOC).
- Tamper-Evident Audit Ledger: Records governance decisions and finding snapshots using SHA-256 hash chaining for defensible assurance.
- Universal MCP Server: Exposes 14 canonical tools, 7 resources, and 4 prompts over Stdio and Streamable HTTP/SSE with fail-closed RBAC.
Deployment Models: SaaS and Private POD
Enterprise security postures differ across industries. Financial institutions, healthcare systems, and defense contractors often require strict data residency and isolation.
ComplyPRO supports both multi-tenant SaaS with database-enforced tenant isolation (PostgreSQL RLS) and dedicated Private POD deployments (VPC or air-gapped Docker containers) where all telemetry and storage remain entirely within the customer perimeter.
Frequently Asked Questions
Does the platform require access to our live production database?
No. The static scanner operates on code repositories. For operational decision tracking and ledger persistence, ComplyPRO uses its own database (Supabase multi-tenant or private PostgreSQL in POD deployments).
How does the Universal MCP server integrate with our IDEs?
ComplyPRO Universal MCP provides a stdio transport for local IDEs (Cursor, Claude Desktop, VS Code) and a Streamable HTTP/SSE transport for enterprise workflow engines, secured by Bearer token authentication and role-based permissions.
Discover What Your AI Can Do
Run the Free AI Governance Scan in your browser. Zero code upload.
Launch Free Scan