Code used to have two authors.
Now it has three.
Now one policy governs all three.
AI is fast.
Earnie is faster.
Your agents write code faster than your reviews can read it. Earnie is already ahead: it knows your policy before the agent starts typing, and checks the result in context via MCP, at pre-commit and at merge.
Earnie works where the work happens.
can I use fast-charts@4.2.1 in checkout-service? ↳ Checked against checkout-service policy. ↳ fast-charts@4.2.1 is AGPL-3.0, disallowed by checkout-service policy. ↳ FND-2481 blocked. 2 MIT-licensed alternatives suggested.
git commit -m "add charting" ↳ earnie: 1 policy violation in staged changes ↳ FND-2481 · fast-charts@4.2.1 · AGPL-3.0 · policy: no-copyleft ↳ Commit blocked. Run `earnie explain FND-2481` for the evidence.
Blocked at: MCP · pre-commit · PR #312
Evidence: 3 entries, linked to source

Always-on governance for
AI models
Detection over declaration. AI SDKs, model files and API keys found, matched against known models and held to your policy. Documented in an AIBOM with provenance and licence. What's really there, in writing.
Cryptography & PQC
Every cryptographic algorithm in your estate, inventoried and checked against policy, with flags on what won't survive the post-quantum transition. The migration starts with an inventory. Earnie keeps it standing.
OSS licence compliance
Components, licences, obligations, down to the snippet someone pasted. Policy applied before it ships. Attribution and notice files generated, SBOMs versioned and retrievable. The record, ready before anyone asks.
Security vulnerabilities
Known vulnerabilities in what you actually ship, found where they live, tied to remediation at AI speed. The fix arrives with the finding, usually one click away.
The programme we built
Detect
Open source, AI models, cryptography and vulnerabilities, caught wherever they enter: in the agent's session, at the keyboard, at merge.
Report
SBOMs, CBOMs, AIBOMs and notice files, generated from what's actually in the code. Versioned and retrievable.
Remediate
Your policy, in your agent's context. With the rules and the evidence in hand, it writes secure, compliant code the first time.
Maintain
Always-on governance. Every project, every commit, the same policy. Records on demand.

