An open reference implementation of decoupled AI governance: governance requirements are packaged as machine-readable policy objects, the evidence that satisfies them as verifiable credentials, so that policy processing is cleanly separated from capability enforcement.
📖 Full documentation — concepts, architecture, and two hands-on tutorials.
The devcontainer brings up the policy engine, registries, and webapp; open the forwarded port 8000 and follow a tutorial:
- Download — data leaves, encrypted to a requester the policy checked. Start here.
- Inference — data stays put and approved code comes to it, at two hospitals at once.
policy_cards/ Policy Card instances (Rego + docs)
credentials/ Credential type definitions (the evidence vocabulary)
tools/ Webapp, registries, guardians, FL server, policy engine
docs/ The documentation site
This is a reference implementation, not a production governance system. It ships without warranty and is not legal or compliance advice.
Copyright MLCommons. All rights reserved. Licensing to be determined. See LICENSE.