☁️Haven GRC - easier governance, risk, and compliance 👨⚕️👮♀️🦸♀️🕵️♀️👩🔬
-
Updated
Jun 14, 2021 - JavaScript
☁️Haven GRC - easier governance, risk, and compliance 👨⚕️👮♀️🦸♀️🕵️♀️👩🔬
Executable Rego policies for AI compliance, each traceable to a named article or control: EU AI Act, UK pro-innovation principles and UK GDPR Arts 22A-22D, NIST AI RMF, PRA SS1/23, FCA Consumer Duty, ICAO/FAA/EASA aviation, FERPA, SRA/BSB legal practice. Per-article coverage matrices state what is implemented and what is not.
Runnable React prototype for teacher, student, and school-administration workflows.
Document ingestion with CUI detection, ITAR/EAR screening, PII/PHI protection, and audit trails with hash-chain integrity. HIPAA Safe Harbor coverage.
Governed AI agents for education — 8 reference workflows on Amazon Bedrock with deny-by-default authorization, student-PII masking, human-in-the-loop enforcement, and tamper-evident audit trail aligned to FERPA, COPPA, IDEA/504, and ADA Title II. Built for K-12, community colleges, and universities.
[WIP] A database of University of California employee wages.
FERPA-safe AI-assisted Canvas LMS toolkit — audit, build, and grade with the instructor as the author.
Production-grade Claude Code skills, pedagogical frameworks, and AI workflows for K-12 educators. Built by a practicing literacy specialist. FERPA-safe. Ready for Monday.
Policy enforcement for AI agents in regulated environments (FERPA, HIPAA, GLBA, GDPR): framework adapters for CrewAI, AutoGen, LangChain, Semantic Kernel, Haystack
Compliance enforcement middleware for voice AI pipelines: warm transfer state management, PII scrubbing, confidence-gated escalation, and HIPAA/FERPA/EU AI Act enforcement for Pipecat, LiveKit, and Twilio deployments.
Policy-as-code for FERPA + Title IV: a deterministic guardrail that decides before any LLM speaks. Risk-tiered, citation-faithful, with an MCP server, OSCAL/SARIF exports, a GitHub Action, and a live web demo.
FERPA/HIPAA/GDPR-compliant RAG patterns: identity-scoped retrieval, audit logging, and framework adapters for regulated enterprise AI
EdTech-specific profile of the AI Procurement Decision Card v0.3 vault contract. Names FERPA's 7 PII categories (34 CFR §99.3) + COPPA's 10 PI categories (16 CFR §312.2, 2025 refresh) as concrete data_vault_targets exemplars + per-category retention rules. Four-doctrine consent_basis_taxonomy. EdTech-readiness scaffolding, not certification.
Kinetic Gain Protocol Suite: eleven open JSON specs for the answer-engine and agent era. Five core (AEO, Prompt Provenance, Agent Cards, AI Evidence, MCP Tool Cards), the EdTech trio (Tutor Cards, Student AI Disclosure, Classroom AI AUP), Clinical AI Disclosure, plus two cross-cutting cards (AI Incident, AI Procurement Decision).
Locally hosted, role-scoped RAG assistant for K-12 districts — policies, handbooks, and schedules with chunk-level citations and a full audit trail
Hash-chained event schema + reference verifier for AI tool reads of student records. Bridges CEDS + Ed-Fi semantics to the Kinetic Gain audit-stream. Enforces tokenization, FERPA §99.32 logging consistency, COPPA school-as-agent invariants, Decision Card refs. EdTech-readiness scaffolding, not certification.
MCP server for AI Tutor Card disclosures. Six tools for procurement review, curriculum matching, and FERPA / COPPA compliance auditing of AI tutors. EdTech-flavored extension of the Kinetic Gain Protocol Suite.
AI Tutor Cards v0.1 draft. Disclosure spec for AI agents in an educational role: audience (age, grade, subjects), pedagogy (Socratic / homework_policy / assessment_policy), safety & privacy (FERPA / COPPA / mandated-reporter). Sixth spec in the Kinetic Gain Protocol Suite.
An AI agent that triages support tickets into structured, schema-validated records, plus a React dashboard to review the results and an eval harness that scores the agent against hand-labeled ground truth.
To associate your repository with the ferpa topic, visit your repo's landing page and select "manage topics."