Rtavan AI builds GovernanceHub: a registry that reads what AI vendors publish about governing their systems and scores it against a published method, and a policy router that turns an organisation’s own AI policy into a tamper-evident record. Nobody we assess pays us for anything.
Figures are read live from the registry each time this page loads.
The company at a glance
Two products, one record. The registry scores what AI vendors publish and keeps every version; the router applies an organisation’s own policy before any model is called and writes each decision to a log anyone can verify. The router is available to evaluate and has not yet carried production traffic.
What we build
The registry
Model cards, safety frameworks, evaluation reports: the documents a vendor publishes, scored for what is actually there against a seven-dimension evidence scale.
Every claim carries its source URL and the date it was read
Documents are fingerprinted and re-read daily, so a quiet edit is recorded
The method is public, so anyone can re-derive a score
An endpoint an organisation points its AI traffic at. It applies that organisation’s own policy before any model is called and records each decision in a hash-chained log.
Allow, reroute to an approved model, redact or block, by the organisation’s rules
Tampering with the record is detectable, and anyone can verify it
Available to evaluate today; not yet carrying production traffic
Five things can happen, and all five are recorded the same way. A refusal is evidence in exactly the way an allowed call is — same chain, same hash, same export. That is the point: you can show what the policy stopped, not only what it let through. This router has not yet carried live traffic. Every request recorded so far is simulated, a test, or a refusal, and any claim made about it should say so.
How the registry works
What this measures is the documentation, not the system. A high score means a vendor published material that answers the questions and can be checked. A low one means what is published does not answer them — not that the system is unsafe, and not that the vendor is non-compliant with anything. Every figure on this site carries the source it was read from and the date it was read, so you can disagree with it specifically.
FindLocate what a vendor has published about a system, from its own sites.
ScoreGrade each dimension by the strongest evidence found, with the source cited.
WatchRe-read watched documents daily and keep every version that changes.
CorrectAny vendor may reply for free; every review is logged in public, including the ones that changed nothing.
Who it is for
Audit and assurance firms
Bias auditors, AI governance consultancies and risk advisers who need a dated, sourced, independent view of the AI vendors their clients rely on.
Teams buying AI
Procurement, risk and compliance teams comparing what vendors actually disclose, before a contract rather than after an incident.
Researchers and regulators
Academics, journalists and public bodies who need a citable, re-derivable record of what was published, and when.
Frameworks mapped
AI Risk Management Framework 1.0 5
Colorado AI Act (not in force) 11
EU Artificial Intelligence Act (Reg. 2024/1689) 6
FFIEC BSA/AML Examination Manual 6
GDPR Article 22 7
Good Machine Learning Practice for Medical Device Development 10
HIPAA Security Rule 11
ISO/IEC 23894:2023 3
ISO/IEC 42001:2023 9
NYC Local Law 144 7
SR 26-2 4
Each control is cited to its source text. The mapping is a starting point for an assessment, not a certification, and a law not yet in force is marked as such.
Why it is independent
No assessed party pays for anything: not for a score, not for early sight of a finding, not for a right of reply. Where a relationship exists between the assessor and an assessed party, it is recorded on the assessment itself and the independence claim is withdrawn, automatically.
Named findings are currently withheld
Findings attached to a specific company are shown to clients under engagement rather than published openly. That is a decision about liability cover, not about the findings: the company is newly formed and media liability cover is not yet bound.
The company
Legal name
Rtavan AI LLC
Status
Articles of Organization filed in North Carolina, 18 September 2026; approval pending