Developer Overview

LetsCompl.ai is a developer-first compliance and safety middleware gateway designed for autonomous AI agents. By intercepting agent prompts, tool parameters, and write-privileged API payloads, LetsCompl enables you to enforce regulatory rulesets and data protection standards inline and in real time.

The Redact → Evaluate → Persist Pipeline

LetsCompl enforces policy guardrails using a three-stage pipeline:

1. Redact (Local SDK): Personally Identifiable Information (PII) and Protected Health Information (PHI) matching our recognized patterns are de-identified locally inside your private network using our client-side SDK, before the payload reaches our servers or downstream LLMs. Redaction is pattern-based, not an exhaustive classifier; see Data Handling for full pattern coverage and known gaps.

2. Evaluate (Edge Gateway): Payload parameters, execution contexts, and prompts are evaluated against active compliance rulesets (like FTC spending caps, FinCEN sanctions list matching, and custom keyword lists) in less than 2ms.

3. Persist (Secure Logs): Evaluation events and verdicts (allow/block) are securely logged for audit reporting. Only the redacted payload is persisted — redaction runs unconditionally before this write, so raw values matching our documented detection patterns are never intentionally logged to disk. Redaction is pattern-based, not an exhaustive PII/PHI classifier; see Data Handling for full pattern coverage and known gaps.

Each evaluation runs under one of two enforcement modes, configured per workspace or API key: ENFORCE, or MONITOR. Under ENFORCE, a blocking policy decision stops the action. In monitor mode, a blocking policy verdict does not stop your action: the response's verdict is approved while policyVerdict is blocked. The evaluation, citation, and audit record are produced exactly as they would be under enforcement.

Check `policyVerdict`, not `verdict`, when you want to know what your policy decided. A monitor-mode response with verdict: "approved" does not mean the payload passed your policy — see SDK Integration for the full field reference.

This distinction has limits. Quota exhaustion returns HTTP 429 in both modes, and if the evaluation gateway is unreachable the SDK never learns your workspace's mode — the client's own unavailable handling (default deny) takes over instead. See Client Availability and Failure Behavior for details.

Compliance as Code

Instead of writing complex, hard-to-maintain check conditions inside your application logic, policies are declared in structured JSON rulesets. These rulesets are automatically mapped to legal requirements (such as FINRA, SOC 2, HIPAA, or the FTC Act) and evaluated atomically at the edge.