Move fast. Break no laws.
While your AI generates your project, it can silently violate GDPR, HIPAA, or KVKK. CompliRules adds ready-made rules to Cursor and Claude Code that quietly block those risks in the background.
$
npx complirules init
One command — rules land in .cursor/rules automatically
Fixed PII Log Leaks in MedusaJS
During our audit of MedusaJS, CompliRules pinpointed raw user email leaks in migration scripts (GDPR Art. 5 / CWE-532). Our remediation was submitted as official upstream Pull Request #17137.
4 legal mistakes your AI makes
No Consentless Cookies
Blocks Google Analytics and tracking scripts from firing before the visitor gives explicit consent.
No Passwords in Logs
Stops passwords, tokens and national ID numbers from being written into server logs while debugging.
Real Account Deletion
When a user says “delete my account”, database records actually get wiped — not just hidden.
No Silent IP Leaks
Bundles fonts locally instead of external CDNs, so visitor IPs never leak abroad without notice.
How it works
-
01
INSTALL
Run
npx complirules initin your project. -
02
AUTO-DETECTED
Cursor or Claude picks the rules into context instantly.
-
03
SAFE CODING
Your AI can no longer produce code that breaks the law.
100% Free & Open Source
Zero paywalls. Every regulatory rule pack (KVKK, GDPR, EAA 2025, HIPAA, AI Act), TypeScript primitive, and CLI tool is completely free under the MIT license.
Multi-Jurisdiction Rules
Pre-built guardrails for KVKK, GDPR, EAA 2025, HIPAA, and EU AI Act.
Universal IDE Support
Auto-detected by Cursor, Claude Code, Windsurf, and GitHub Copilot.
Deterministic Linter
Instant AST terminal analysis with complirules check and report generator.
MIT Licensed & Local
No telemetry, no remote lock-in. Runs 100% offline in your own environment.
CompliRules is a static rule set tool — not legal advice or an attorney service. The software is provided "AS IS".