Policies, Accountability & Culture
Rigour enforces organizational AI policies as deterministic code — not documents that drift. Every quality gate is policy-as-code, version-controlled, and auditable.
Context, Risk Identification & Categorization
Rigour automatically maps the risk context of AI-generated code — identifying what type of system it is, what regulations apply, and where AI-specific risks exist.
Metrics, Monitoring & Assessment
Rigour provides continuous, deterministic measurement of AI code quality — not subjective reviews, but repeatable PASS/FAIL gates with full audit trails.
Response, Recovery & Communication
Rigour enforces bounded, recoverable AI workflows — preventing runaway agents, limiting blast radius, and providing exportable audit artifacts for compliance reporting.
Coverage Summary
| RMF Function | Rigour Capabilities | Key Features |
|---|---|---|
| GOVERN | Policy-as-code, agent governance, provenance attribution | rigour.yml, agent_team, industry presets |
| MAP | Auto-detection, risk categorization, AI-specific risk identification | Provenance tags, AI-native gates, severity scoring |
| MEASURE | Deterministic scoring, trend analysis, structured feedback | Two-score system, score trending, fix packets |
| MANAGE | Bounded workflows, blast radius limits, audit export | Supervised mode, safety gates, export-audit |
Technical Specifications
Architecture
- Runtime: 100% local — zero telemetry, no external API calls
- Integration: MCP (Model Context Protocol), CLI, GitHub App
- Languages: TypeScript, JavaScript, Python, Go, Rust, Java, C#, C/C++, PHP, Swift, Kotlin
- Analysis: Tree-sitter AST parsing — no regex pattern matching
Audit Output
- Formats: JSON (machine-readable), Markdown (human-readable)
- Scoring: 0-100 with severity-weighted deductions
- Trending: JSONL append-only history with trend classification
- Command:
rigour export-audit --format json
Get Started
Rigour is open-source and free. Install it in your project and run your first quality gate check in under 60 seconds.
$ npx @rigour-labs/cli init --preset government