NewExpert Review for the EU AI Act, GDPR and DORA Metrics

Evidence on demand. Audits in hours, not weeks.

PulseCheck turns the work already happening in Jira, GitHub, GitLab, Linear and Azure DevOps into DORA metrics, GO/NO-GO compliance gates and signed audit evidence. No new dashboard to babysit.

No credit card · EU-hosted · Set up in minutes

PulseCheck dashboard with DORA metrics, compliance KPIs and domain scores
14 rules pass
AI Coach ready
Solutions

The rules change. Your evidence keeps up.

Whatever you ship — SaaS, fintech, AI, healthcare — PulseCheck turns the standard that applies to you into rules that run on every commit, ticket and deploy.

Delivery performance

All four DORA metrics, computed for you.

Deployment frequency, lead time for changes, change failure rate and MTTR — calculated per team from Jira, GitHub, GitLab, Azure DevOps and Jenkins, banded Elite to Low, with drift alerts that name the exact pull requests. Never individual developer scoring.

DORA Metrics rule pack
live · synced 2m ago
  • Deployment frequency · Elite (daily)
  • Lead time for changes · 26h median
  • Change failure rate · 18% — above target
  • MTTR · 2.4h · High

New regulation? Tell us the framework — we'll scope a rule pack with you.

Your own rules

Your process is the standard. Turn it into rules.

Templates cover GDPR, the EU AI Act and DORA Metrics. For your own process, write the rules yourself or describe it to the AI assistant and review what it drafts.

Two ways to create them

Write them yourself

JQL, YAML or plain English, with a live preview before you save.

Describe it, the AI drafts them

Paste your definition of ready or incident process into the assistant. It proposes domains and rules; nothing is created until you confirm.

Teams start with

  • Definition of ready
  • Definition of done
  • Incident management
  • Release checklist
  • Code review policy

The AI drafts. The deterministic rule engine still does all the scoring.

How it works

Compliance is measured by our rule engine, not guessed by an AI.

Deterministic motor. Advisory coach. Reproducible evidence. In that order.

Deterministic

Rule Engine

JQL, YAML, plain English. Every pass/fail is reproducible by anyone, at any time.

coverage ≥ 80%
Advisor

AI Coach

Explains failures, suggests new rules, drafts fixes. Never scores compliance.

"Suggest a rule for stale PRs"
Reproducible

Auditor View

Snapshots frozen in time. Click a date, see the evidence exactly as it was.

snapshot @ 2026-04-12
Compliance Gates

Ship on Friday with a verdict everyone accepts.

Compliance Gates compile every automated check and human sign-off into a single GO / NO-GO verdict, scoped to the domains and teams that matter. Nobody has to read a Slack thread to know if you're ready.

  • Automated checks & locked sign-offs

    Foundation checks evaluate automatically; sign-offs record who confirmed what, and when. Recommended checks show, but never block.

  • Gate template library

    One-click EU AI Act, GDPR, DORA metrics, QA, SAP and SLA templates — pre-scoped rule packs for the framework that applies to you.

  • Domain & team scoping

    Every gate is scoped to the domains and teams it governs, so the verdict only reflects what that gate is actually accountable for.

  • Recurring gates

    Re-open a gate monthly, quarterly, every six months or yearly, so periodic reviews run themselves.

  • Shareable & embeddable verdict

    A read-only, expiring link for auditors — or a live embed in Confluence, Notion or any page that supports an iframe, where sign-offs are attributed to the real user.

Release gate · v4.12
Payments, Checkout, Identity domains
GO
All foundation checks14/14 ruleshard
Coverage ≥ 80%payments: 72%soft
All PRs reviewedlast 7d · 142/142hard
Rollback plan presentrunbook linkedhard
No open P1 incidentsclearsoft
Copy embed linkView gate detail
Audit-ready compliance

A tamper-proof audit log, with exports auditors can verify themselves.

Every rule evaluation, every config change, every sign-off — recorded in an append-only log the database will not let anyone edit or delete, and exportable on demand.

  • Append-only evidence store

    Updates and deletes are blocked at the database level. Each evaluation stores a fingerprint of the exact rule text it checked.

  • Signed CSV & JSON exports

    Digitally signed (ECDSA P-256) and timestamped, with verification steps bundled so an auditor can check integrity offline.

  • EU data residency

    Hosted in Frankfurt (EU). Credentials encrypted with AES-256-GCM; row-level security isolates every organization.

Every audit event is tagged by framework

EU AI Act
Regulation (EU) 2024/1689
GDPR
Art. 25 · 32 · 33 · 35
NIS2
EU cybersecurity directive
SOC 2 · ISO 27001
Control-family tagging
Expert Review
New

An independent expert's verdict, next to every rule.

Some questions a rule engine should not answer. Expert Review sends a sealed package of your rule results and evidence to an independent expert. Their verdict comes back next to each rule's automated result.

Who reviews

  1. Step 1Choose the scope

    Pick the framework and the team or AI system.

  2. Step 2Add the documents

    Upload what the rules in scope need. A link is only a hint.

  3. Step 3Seal and send

    One signed package goes to the expert.

  4. Step 4Get a verdict per rule

    The verdict and the signed opinion come back into PulseCheck.

DORA Metrics reviews are engineering reviews, not legal reviews.

Expert review
CV screening assistant
Sample

EU AI Act · assessment v3 · high risk (Annex III, point 4) · legal review

RuleAutomatedExpert verdict
Human oversight recordArt. 14FAILDisagree
Required change: add a written intervention procedure with test evidence.
Technical documentationArt. 11UNVERIFIEDAgree with conditions
Data governanceArt. 10UNVERIFIEDAgree with conditions
Risk classification rationaleArt. 6PASSAgree
Overall: Agree with conditionsPackage EXP-0930-01 · SHA-256 e41c7a90… · ECDSA P-256 · signed opinion attached
Sample data.
  • AI suggestionyour confirmation

    AI drafts need your approval and never say a requirement is met.

  • Linkdocument

    A link says nothing about the document behind it. You upload the document.

  • Automated resultexpert verdict

    The expert's verdict never overwrites the automated result.

Intelligent alerts

Drift detection that knows a rising number is sometimes good news.

Daily digest to Slack or Microsoft Teams. Three suggested next steps per alert. Noise suppressed by default — the AI Coach only interrupts when something actually changed.

Daily digestTrend-aware3 actions / alertMute by domain
#eng-releasesToday · 08:00
PulseCheckAPP08:00
Daily digest — 2 drifts, 1 improvement across DevOps.
Coverage drift · payments
80% → 72% over 14 days · rule: ci.coverage ≥ 80
Suggested next steps:
  1. Add tests for PaymentIntent.refund()
  2. Require coverage check in PR template
  3. Set soft gate at 75% to avoid release block
Deploy frequency up 18% · that's good news.
No action required. DORA metrics still in the "Elite" band.
View verdictOpen ruleMute for 24h
Platform

Everything an engineering leader needs to prove delivery and compliance.

Nine capabilities on one deterministic motor, one evidence store and one auditor view.

DORA Metrics

Deployment frequency, lead time, change failure rate and MTTR — native from Jira, GitHub, GitLab, Azure DevOps Pipelines and Jenkins, banded Elite to Low.

Deterministic Rule Engine

JQL, YAML and plain-English rules compile to a single motor, with a live preview of what a rule will match before you save it.

Compliance Gates

GO/NO-GO verdicts from automated checks and locked sign-offs, on a recurring schedule if you need one.

CI Data-Compliance Gate

A GitHub Action blocks pull requests that add personal data, hardcoded credentials or other defined signatures. Findings are masked inside your own runner.

Investment & Cost Impact

See where engineering time actually lands — features, keep-the-lights-on, toil, compliance — and what overruns cost in euros.

AI Coach (advisor)

Explains failures, drafts fixes and suggests new rules from the dashboard or in Slack and Teams. Never scores compliance itself.

MCP Connector

Ask Claude or any MCP-capable assistant about your compliance posture — read-only or read & write, organization-isolated and audited.

Live Embeds

Live KPIs, gates, DORA tiles and cost cards inside the pages your stakeholders already read — Confluence, Notion or anything that supports an iframe, in English or German.

Enterprise Identity & EU Hosting

SSO with Microsoft Entra ID, Google Workspace or SAML 2.0, organization-wide MFA enforcement, and hosting in the EU (Frankfurt).

Integrations

Connect your stack. We'll do the rest.

PulseCheck reads what's already there — no new data pipeline, no new agent on your runners.

  • Jira
  • GitHub
  • GitLab
  • Linear
  • Jenkins
  • Azure DevOpsBeta
  • Slack
  • Teams
  • Confluence · Notion
  • Claude (MCP)
  • Zapier
  • SAPEarly access

Enterprise backlog size — chunked sync auto-resumes if interrupted. Owners are alerted the moment a connection breaks.

Customers

Engineering leaders in DACH trust PulseCheck.

Quotes lifted from customer interviews conducted in Q1 2026. Company names withheld pending case-study approval.

As a DevOps engineer in fintech, compliance tracking is non-negotiable for us. The product is very powerful — it fits seamlessly into our workflows and gives us the flexibility to tailor rules to what we actually need. A colleague on our team was particularly impressed by how it handles compliance-related issues. The customizability alone sets it apart.
DevOps Engineer
Fintech scale-up, DACH
The rule engine is the point. Our auditors can rerun any evaluation against any historical snapshot — and the verdict is always the same. That's what deterministic means.
VP of Engineering
Automotive software (Tier 1)
The AI Coach is the most honest AI product I've used this year. It explains, it suggests — and it stays out of the way when the rule engine has already given us a hard answer.
CTO
Digital commerce consultancy
  • GDPR-native
  • Hosted in the EU (Frankfurt)
  • Names & e-mails masked before any AI call
  • Signed, verifiable exports
  • SSO & enforced MFA
FAQ

Questions we get from engineering leaders.

Didn't answer yours? The demo is where we actually earn the conversation.

What is PulseCheck?

PulseCheck is an engineering compliance and delivery-performance platform built by data duke, a software company in Vienna, Austria. It connects to the tools your teams already use — Jira, GitHub, GitLab, Linear, Azure DevOps and Jenkins — and turns that activity into DORA metrics, deterministic compliance checks, GO/NO-GO compliance gates and signed audit evidence. It is not related to the healthcare EMR called 'PulseCheck' or the hospitality startup 'PulseCheck AI'.

Is AI scoring our compliance?

No. Compliance is measured by a deterministic rule engine — every pass/fail is reproducible against a historical snapshot. The AI Coach is strictly advisory: it explains failures, suggests new rules and drafts fixes. It never writes a verdict.

Can I check my AI system against the EU AI Act without signing up?

Yes. The free EU AI Act check classifies your AI system in about 3 minutes. If you build AI, it then runs PulseCheck's EU AI Act rules on a Jira CSV or GitHub export of up to 50 records, or on sample data. If you only use AI, it builds a release gate of sign-offs for your duties. It runs in your browser, the file is never uploaded, and no account is needed. It is one use case: PulseCheck also covers DORA Metrics, GDPR and SAP change control.

Does PulseCheck give legal advice or decide whether we are compliant?

No. PulseCheck measures engineering evidence against deterministic rules, and its percentages are rule pass rates, not legal conclusions. For a legal judgment, Expert Review puts the question to an independent, licensed lawyer. Their verdict appears next to the automated result and never changes it.

Which DORA metrics does PulseCheck track, and from which tools?

All four: deployment frequency, lead time for changes, change failure rate and mean time to restore (MTTR). Deployments come from Jira, GitHub and GitLab events, Azure DevOps Pipelines (beta) or Jenkins; change failure rate from incident tickets and failed production deployments; lead time from pull-request and commit timestamps. Each metric is computed per team and banded Elite to Low — PulseCheck never scores individual developers. Note: these are the DevOps Research and Assessment (DORA) delivery metrics, not the EU's Digital Operational Resilience Act.

Which tools does PulseCheck integrate with?

Jira (webhooks and polling, including Jira Plans), GitHub (multi-repo), GitLab, Linear, Jenkins and Azure DevOps (beta: Boards, Repos, Pipelines and Deployments) as data sources; Slack and Microsoft Teams for alerts and the AI Coach; live embeds for Confluence, Notion or any page that supports an iframe; Zapier for outbound webhooks; and an MCP connector for Claude and other AI assistants. An SAP transport connector is available in early access.

Which compliance frameworks does PulseCheck support?

GDPR and the EU AI Act ship as ready-to-install rule and gate templates, alongside DORA metrics, QA, incident-management, SLA and engineering-investment packs. Audit events are additionally tagged for NIS2, SOC 2 and ISO 27001 control families so they can be filtered in exports. SAP change control (SOX ITGC) is available as an early-access pilot, and you can write your own rules for any internal standard. Expert Review adds an independent expert's verdict for the EU AI Act, GDPR and DORA Metrics.

Can we create our own rules and standards?

Yes. Write rules in the Rule Engine (JQL, YAML or plain English, with a live preview), or describe your process to the dashboard assistant, such as a definition of ready or incident management. It proposes domains and rules, and nothing is created until you confirm. The deterministic rule engine does all scoring.

What is Expert Review?

Expert Review is an independent expert's verdict on your evidence, rule by rule, for the EU AI Act, GDPR and DORA Metrics. EU AI Act and GDPR reviews are by a licensed lawyer. DORA Metrics reviews are by a senior engineering lead; this is an engineering review, not a legal review. The verdict appears next to each rule's automated result and never changes it. To request one, book a demo or write to we@usepulsecheck.com.

Can PulseCheck block a pull request?

Yes. The CI data-compliance gate is a GitHub Action that runs in your own runner and blocks a pull request when it adds defined signatures — personal data in fixtures or logs, hardcoded credentials and similar patterns. Findings are masked before they leave the runner, and you tune the rules yourself. Anything that needs human judgment goes to a locked, role-restricted sign-off in a compliance gate instead.

How does audit export work?

Exports are CSV or JSON bundles, digitally signed (ECDSA P-256) and timestamped, with framework tags and verification instructions included so an auditor can check integrity offline. The audit log itself is append-only: the database blocks edits and deletes, and each evaluation records a fingerprint of the rule text it checked.

Where is our data stored and how is it protected?

PulseCheck is hosted in the EU (Frankfurt). Integration credentials and bring-your-own AI keys are encrypted with AES-256-GCM, and row-level security isolates every organization. Sign-in supports Microsoft Entra ID, Google Workspace and SAML 2.0 single sign-on, and admins can enforce multi-factor authentication for the whole organization.

How much does PulseCheck cost, and is there a free trial?

PulseCheck is licensed per seat, with plans for teams of every size and a Consultant Suite for advisory firms. Pricing is provided on request — book a demo or write to we@usepulsecheck.com. You can also start a free 14-day Premium trial right away: no credit card required, and it begins as soon as you verify your email.

Can I use PulseCheck from Claude or another AI assistant?

Yes. PulseCheck ships an MCP (Model Context Protocol) connector. Add it to Claude, Cursor or any MCP-capable assistant, sign in with OAuth, and choose an organization and an access level — read-only, or read & write so the assistant can trigger syncs and update domains, gates and cost-impact items. Every call is organization-isolated and audited.

Book a demo

See a GO/NO-GO verdict on your own repos — in 30 minutes.

Bring one production repo. We'll wire up the rule engine live and walk you through the auditor view. No slides.