Announcement: Rightbrain raises a £3M seed round led by NPIF II
Use case

Automated due diligence: "compliance as code" for startups

For engineering-led startups, vendor risk assessments are a distraction, but failing SOC 2 or GDPR is not an option. Automate the discovery and analysis grunt work inside GitHub, then hand your counsel a pre-packaged decision to simply validate and sign.

GitHub × Rightbrain Compliance & risk GitHub Actions 14 Mar 2026
5 tasksdiscovery, classification, legal, security, risk
2 weeks → 1 hrcounsel review, not counsel research
Zerodedicated compliance headcount

For engineering-led startups, vendor risk assessments are a distraction, but failing SOC 2 or GDPR is not an option. This solution lets you treat compliance like code. By automating the document discovery and analysis grunt work inside GitHub, your team can handle due diligence without hiring a dedicated risk manager, and package everything so external counsel or a fractional CISO can simply "validate and sign," saving thousands in billable hours.

It is a complete compliance application orchestrated via GitHub Actions and available to clone on GitHub. The intelligence is powered by five distinct Rightbrain tasks running in the background (Discovery, Classification, Legal Analysis, Security Analysis, and Risk Reporting), each of which you can inspect, test, and refine directly in your Rightbrain dashboard.

One-time setup: train your AI risk manager

Before running your first audit, you configure the "lens" through which the AI views every vendor by editing a simple company_profile.json file:

  • Risk tolerance: e.g. "We are seed-stage; accept operational risks but block privacy risks."
  • Hard requirements: e.g. "Vendors processing PII must have SOC 2 Type II."
  • Strategy: e.g. "Legal bandwidth is low; prioritise insurance requirements over indemnity negotiation."
  • Task customisation (optional): you or your lawyer can define the specific legal risks to flag, and your CTO can map the security controls they expect from vendors into the checklist.

How it works

  1. Create an issue. Engineers submit a new vendor request via a standard GitHub Issue. No clunky procurement portals, just the tools they already use.
  2. Automated spidering & discovery. The system acts as your junior analyst. It doesn't just read the provided URL; it spiders the vendor's site to find buried DPAs, SOC 2 reports, and sub-processor lists, categorises them, flags what's missing, and attaches everything to the issue automatically.
  3. Discrete legal & security analysis. Specialised parallel tasks run: one model extracts legal liabilities (indemnities, termination rights) while another audits security controls (ISO evidence, encryption), creating a structured, factual record before any judgment is made.
  4. Synthesised risk call. A Risk Reporter task aggregates the raw findings and grades the vendor against your specific risk appetite, producing a concise executive summary that highlights only what matters.
  5. Validation & commit. Once approved, the system adds the vendor to your suppliers database and generates a permanent, version-controlled audit log in Markdown, committing the final terms directly to your repo for easy review by auditors and legal counsel.
A vendor request raised as a standard GitHub Issue.
Step 1: engineers raise a vendor request as a standard GitHub Issue.
The system discovering vendor documents and flagging missing items.
Step 2: the system spiders the vendor's site, discovers documents and flags gaps.
Parallel legal and security analysis producing a structured findings record.
Step 3: parallel legal and security tasks extract a structured, factual record.
The Risk Reporter grading the vendor and producing an executive summary.
Step 4: the Risk Reporter grades the vendor against your risk appetite.
A version-controlled Markdown audit log committed back to the repository.
Step 5: a version-controlled Markdown audit log is committed back to the repo.

Key benefits

  • Zero-headcount due diligence: automate the research phase so you don't need a full-time compliance hire.
  • Lower external counsel costs: stop paying lawyers to find documents; pay them only to validate the pre-packaged risk summary.
  • GitHub-native audit trails: keep your compliance artifacts version-controlled alongside your code.

Pro tips

  • Outsource the stamp, not the work. Use this to prepare a decision package for a fractional CISO or external counsel, turning a two-week billable project into a one-hour review.
  • Standardise the intake. Use the GitHub Issue template to force engineers to provide the right context (data types, usage) upfront.
  • Iterate on your prompts. Because the tasks are defined in code (JSON), you can tweak the system prompts instantly. Just realised you need better IP indemnities? Edit the Rightbrain task.

Ship compliance as code

We'll help you configure the risk lens and stand up the five tasks in your own GitHub repo.

Book a call