{"_id":"@attestly/compliance-core","_rev":"4-0f1ad70e4f128afc8be7cc951f4a421f","name":"@attestly/compliance-core","dist-tags":{"latest":"0.1.3"},"versions":{"0.1.0":{"name":"@attestly/compliance-core","version":"0.1.0","license":"MIT","_id":"@attestly/compliance-core@0.1.0","maintainers":[{"name":"attestly","email":"admin@attestly.dev"}],"dist":{"shasum":"8e1842deb165700bff7d8f17bbbdcc43e0b4a965","tarball":"https://registry.npmjs.org/@attestly/compliance-core/-/compliance-core-0.1.0.tgz","fileCount":8,"integrity":"sha512-H8m788HW5F1pwmn9SQbw5wnwzas8iaXBCMEfRBkRbep8P+169adNxBJ83peC6h9dG3v0mzhBoPJkXeQSRTXKlA==","signatures":[{"sig":"MEYCIQDdTO8JOdjzvDgIUeTBtM89XR9EpxRjugSmSlmyGmpxtQIhALbIUnj0rTJsBXEcqeYKO7jge3MtbRxwE5uhtsXYiNCY","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":58161},"main":"./dist/index.js","types":"./dist/index.d.ts","module":"./dist/index.mjs","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"gitHead":"a4e2838f6dd191ea0d7b80c30709268f51bed6b7","scripts":{"dev":"tsup --watch","build":"tsup"},"_npmUser":{"name":"attestly","email":"admin@attestly.dev"},"_npmVersion":"11.11.0","description":"Zero-latency, Web Standard-based SDK that enforces AI compliance","directories":{},"_nodeVersion":"25.8.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.2","typescript":"^5.4.5"},"_npmOperationalInternal":{"tmp":"tmp/compliance-core_0.1.0_1779679797311_0.37334603540384315","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@attestly/compliance-core","version":"0.1.1","license":"MIT","_id":"@attestly/compliance-core@0.1.1","maintainers":[{"name":"attestly","email":"admin@attestly.dev"}],"dist":{"shasum":"9506b7343fba6d70764a1ceafba04dd1d5c974bf","tarball":"https://registry.npmjs.org/@attestly/compliance-core/-/compliance-core-0.1.1.tgz","fileCount":8,"integrity":"sha512-allKQM4xFwT153RwKq3nLakrdV4/tDWyYRSckzNdpm2K3LydbZcHrFcYlyXucFs+z0GC5mxf2aGVLKAnPNIBTw==","signatures":[{"sig":"MEYCIQCGm4Ji7kaorqePm10PnJIoWQyhvnwfKNk6iDC97sZrogIhAIiGzZ1g3sWjcsfc5DsRqGKm5ilTF2lkjdoe8ondIqyO","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":72454},"main":"./dist/index.js","types":"./dist/index.d.ts","module":"./dist/index.mjs","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"gitHead":"e9cd258057c4ed48336336d2a91df4ae90981961","scripts":{"dev":"tsup --watch","build":"tsup"},"_npmUser":{"name":"attestly","email":"admin@attestly.dev"},"_npmVersion":"11.11.0","description":"Zero-latency, Web Standard-based SDK that enforces AI compliance","directories":{},"_nodeVersion":"25.8.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.2","typescript":"^5.4.5"},"_npmOperationalInternal":{"tmp":"tmp/compliance-core_0.1.1_1779752268134_0.6573315744136066","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@attestly/compliance-core","version":"0.1.2","license":"MIT","_id":"@attestly/compliance-core@0.1.2","maintainers":[{"name":"attestly","email":"admin@attestly.dev"}],"homepage":"https://github.com/Attestly-dev/attestly#readme","bugs":{"url":"https://github.com/Attestly-dev/attestly/issues"},"dist":{"shasum":"33253a40a060e372a63b3cc2000f9f69bff7efab","tarball":"https://registry.npmjs.org/@attestly/compliance-core/-/compliance-core-0.1.2.tgz","fileCount":8,"integrity":"sha512-MDpNpVm79fmuSjEl+zHAKvZe1rgGvdVAHYyCqHxo4ApakrkfhNzDUctlzETVC+o49s5Yw4t2VQ42sODc8pJbUg==","signatures":[{"sig":"MEUCIBc+c/PeOeYWWgtF8emL3M6vdSUNHn4kzr8KnGZ4aoq+AiEAyUdYoP+9jEZ9idcwJjd99akod47lkGa0DHOpz7d2H0s=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":74086},"main":"./dist/index.js","types":"./dist/index.d.ts","module":"./dist/index.mjs","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"scripts":{"dev":"tsup --watch","build":"tsup"},"_npmUser":{"name":"attestly","email":"admin@attestly.dev"},"repository":{"url":"git+https://github.com/Attestly-dev/attestly.git","type":"git"},"_npmVersion":"11.11.0","description":"Zero-latency, Web Standard-based SDK that enforces AI compliance","directories":{},"_nodeVersion":"25.8.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.2","typescript":"^5.4.5"},"_npmOperationalInternal":{"tmp":"tmp/compliance-core_0.1.2_1779840317337_0.5745582824793729","host":"s3://npm-registry-packages-npm-production"}},"0.1.3":{"name":"@attestly/compliance-core","version":"0.1.3","description":"Zero-latency, Web Standard-based SDK that enforces AI compliance","repository":{"type":"git","url":"git+https://github.com/Attestly-dev/attestly-oss.git","directory":"packages/compliance-core"},"bugs":{"url":"https://github.com/Attestly-dev/attestly-oss/issues"},"license":"MIT","main":"./dist/index.js","module":"./dist/index.mjs","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"engines":{"node":">=18"},"scripts":{"build":"tsup","dev":"tsup --watch"},"devDependencies":{"tsup":"^8.0.2","typescript":"^5.4.5"},"publishConfig":{"access":"public"},"gitHead":"acb57eef22ecbe4474ffbddb589f07a4a3914aef","_id":"@attestly/compliance-core@0.1.3","homepage":"https://github.com/Attestly-dev/attestly-oss#readme","_nodeVersion":"25.8.0","_npmVersion":"11.11.0","dist":{"integrity":"sha512-sBSGQKhc7WBukS1xCG35pbFTi69NduUS0ZocO7hIwNMj206xUgszaNaHgQpK/8L3XE8XQKLZVdCFHL9FGA0sZA==","shasum":"63a68c850fca296d8b45607b2c04df291f178405","tarball":"https://registry.npmjs.org/@attestly/compliance-core/-/compliance-core-0.1.3.tgz","fileCount":8,"unpackedSize":74140,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCQIQfBqqJgQRnWc1zbox/6058BqoeUiydgelhN2zhRswIgKAoOhbEABHddasFStsvi0jy6p6A5TjLx5IDVeRrXS7I="}]},"_npmUser":{"name":"attestly","email":"admin@attestly.dev"},"directories":{},"maintainers":[{"name":"attestly","email":"admin@attestly.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/compliance-core_0.1.3_1779841156360_0.47632780945416986"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-25T03:29:57.122Z","modified":"2026-05-27T00:19:16.607Z","0.1.0":"2026-05-25T03:29:57.446Z","0.1.1":"2026-05-25T23:37:48.281Z","0.1.2":"2026-05-27T00:05:17.507Z","0.1.3":"2026-05-27T00:19:16.514Z"},"bugs":{"url":"https://github.com/Attestly-dev/attestly-oss/issues"},"license":"MIT","homepage":"https://github.com/Attestly-dev/attestly-oss#readme","repository":{"type":"git","url":"git+https://github.com/Attestly-dev/attestly-oss.git","directory":"packages/compliance-core"},"description":"Zero-latency, Web Standard-based SDK that enforces AI compliance","maintainers":[{"name":"attestly","email":"admin@attestly.dev"}],"readme":"# @attestly/compliance-core\r\n\r\nA zero-latency, Web Standard-based SDK that strictly enforces AI compliance at the route boundary, *before* your API executes.\r\n\r\nBuilt specifically to shift **EU AI Act Compliance**, **Model Version Locking**, and **PII Scrubbing** to the absolute left of your development cycle, without adding any overhead to your production environment.\r\n\r\n## 🚀 Key Value Propositions\r\n\r\n- **Zero-Dependency Core**: The SDK is incredibly lightweight and natively relies on Web Standard `Request` and `Response` objects. No heavy AST parsers or backend-bloat.\r\n- **Zero-Latency (TTFB Protected)**: Validation runs entirely synchronously in milliseconds. In production, the wrapper acts as a near-zero-cost pass-through unless explicitly configured to intercept.\r\n- **EU AI Act Shift-Left**: Catches Prohibited Practices (Article 5), auto-escalates Annex III High-Risk domains (like Law Enforcement, Biometrics, Healthcare, and Critical Infrastructure), and strictly enforces required metadata traceability according to EU regulations.\r\n- **Vercel AI SDK First**: Out-of-the-box support for streaming UIs. It inspects the prompt, scrubs PII, and returns the native `DataStreamResponse` totally untouched so your Lighthouse scores remain pinned at 100.\r\n\r\n## 📦 Installation\r\n\r\n```bash\r\nnpm install @attestly/compliance-core\r\n```\r\n\r\n## 🛠 Setup & Initialization\r\n\r\nInstead of hand-coding your manifest, use our interactive CLI to intelligently scan your local codebase and generate a compliant `ai-manifest.json`.\r\n\r\n```bash\r\nnpx @attestly/cli init\r\n```\r\n\r\nThe CLI will:\r\n1. Scan your project for AI model strings (e.g., `gpt-4o`, `claude-3-opus`).\r\n2. Ask you to classify your primary System Domain under the EU AI Act.\r\n3. Automatically escalate the risk category if you select high-risk domains.\r\n4. Output your locked-down `ai-manifest.json`.\r\n\r\n## 💻 Usage\r\n\r\n### The \"One-Shot\" AI Setup Prompt\r\nInstead of reading docs, just copy and paste this prompt directly into **Cursor, GitHub Copilot, or ChatGPT** to have it auto-configure your entire repository:\r\n\r\n> Please configure my codebase for EU AI Act Compliance using Attestly:\r\n> 1. Run \\`npm install @attestly/compliance-core\\` and \\`npm install -D @attestly/cli\\`\r\n> 2. I know \\`npx @attestly/cli init\\` is interactive, so please bypass it and directly create an \\`ai-manifest.json\\` at the root with my allowed AI models and set the euRiskCategory based on my system domain.\r\n> 3. Directly create a global Next.js \\`middleware.ts\\` (or update my existing one) and inject the \\`withAttestlyCompliance\\` wrapper from \\`@attestly/compliance-core\\`.\r\n> 4. Run \\`npx @attestly/cli scan\\` to verify my API routes are 100% compliant.\r\n\r\n### Global Middleware (Recommended)\r\nInstead of wrapping every single API route, drop the wrapper into your Next.js `middleware.ts`. The Attestly CLI scanner will automatically detect this and mark all your routes as protected!\r\n\r\n```typescript\r\nimport { withAttestlyCompliance } from '@attestly/compliance-core';\r\nimport manifest from './ai-manifest.json';\r\nimport { NextResponse } from 'next/server';\r\n\r\nexport default withAttestlyCompliance(async (req) => {\r\n  return NextResponse.next();\r\n}, manifest as any);\r\n\r\nexport const config = {\r\n  matcher: '/api/:path*',\r\n};\r\n```\r\n\r\n### Per-Route Usage (Alternative)\r\nWrap your existing API routes in Next.js, Remix, or Hono. \r\n\r\n#### Standard API Route\r\n\r\n```typescript\r\nimport { withAttestlyCompliance } from '@attestly/compliance-core';\r\nimport manifest from '../../ai-manifest.json';\r\n\r\nasync function handler(req: Request) {\r\n  // Your standard LLM logic here...\r\n  return new Response(JSON.stringify({ success: true }));\r\n}\r\n\r\nexport const POST = withAttestlyCompliance(handler, manifest);\r\n```\r\n\r\n### Streaming API Route (Vercel AI SDK)\r\n\r\n```typescript\r\nimport { withAttestlyStream } from '@attestly/compliance-core';\r\nimport { streamText } from 'ai';\r\nimport { openai } from '@ai-sdk/openai';\r\nimport manifest from '../../ai-manifest.json';\r\n\r\nasync function handler(req: Request) {\r\n  const result = await streamText({\r\n    model: openai('gpt-4-0613'),\r\n    prompt: 'Hello world',\r\n  });\r\n  return result.toDataStreamResponse();\r\n}\r\n\r\nexport const POST = withAttestlyStream(handler, manifest);\r\n```\r\n\r\n## 📊 Attestly Studio (Local Telemetry)\r\n\r\nYou don't need to deploy to test your compliance barriers! Spin up the Attestly Studio right inside your terminal to see a real-time, local dashboard of your AI traffic.\r\n\r\n```bash\r\nnpx @attestly/cli studio\r\n```\r\n\r\nThis launches a local dashboard at `http://localhost:5050`. \r\n\r\n- **Real-Time Feed**: Watch your local API requests stream in.\r\n- **Inspector**: Click on a request to see the raw payload, the PII-scrubbed output, and any triggered EU AI Act violations.\r\n- **Handoff**: Click the \"Generate Trust Center\" button to seamlessly hand off your local manifest to the Attestly SaaS platform to generate a public, SOC2-ready Trust Center!\r\n","readmeFilename":"README.md"}