Governance tools that run in your browser.

Small, single-purpose tools built from the Body of Knowledge. Each one runs entirely in this page, keeps your answers in the link you copy and exports its result in an open format you can file, diff and re-import.

Indicative, not legal advice and not a conformity claim. Nothing you enter leaves your browser.

Prefer to ask in your AI assistant? Connect the MCP server and Claude, or any MCP client, answers from the same registers with the source page of every answer.

The tools

11 tools are live. Each one names the chapter it is built from, what you enter and what you get back.

How every tool works

  • In the page, nowhere else. No account and no upload: the tools make no network request with what you enter. Files you import are read by your browser.
  • State in the link. Your answers travel in the part of the address after #, the fragment, which the browser handles itself and does not send when it requests the page [4]. Copy the link to share a result or to come back to it.
  • Open formats. JSON [1], CSV [2], iCalendar [3], Markdown, SVG and PNG. A JSON export carries a kind and a version, so the tool can read it back; on import it recomputes every derived value rather than trusting the file.
  • Readable without JavaScript. Every tool renders its questions and its guide on the server, so with scripts off the page still works as a worksheet. Forms use labelled groups, errors are announced and focus moves to the result.
  • Indicative. A result is a reading for planning, not legal advice, not an audit and not a conformity claim. No tool gives a single score, a badge or a certificate.

Adding a tool

Each tool is one entry in the registry (src/data/toolkit.ts), one page wrapped in the shared ToolShell component and one client module that imports the shared helpers (public/toolkit/lib.js): link state, safe storage, downloads, the clipboard and image export. No inline scripts and no third-party code, so the site's content security policy holds unchanged.

Sources

  1. [1] RFC 8259, The JavaScript Object Notation (JSON) Data Interchange Format (STD 90; JSON exchanged between systems outside a closed ecosystem MUST be UTF-8). IETF. 2017-12. https://www.rfc-editor.org/rfc/rfc8259 (verified: primary)
  2. [2] RFC 4180, Common Format and MIME Type for Comma-Separated Values (CSV) Files (Informational; CRLF records, fields with commas, double quotes or line breaks enclosed in double quotes, inner quotes doubled; registers text/csv). IETF. 2005-10. https://www.rfc-editor.org/rfc/rfc4180 (verified: primary)
  3. [3] RFC 5545, Internet Calendaring and Scheduling Core Object Specification (iCalendar) (Proposed Standard; CRLF content lines folded at 75 octets, TEXT escaping, PRODID and VERSION per calendar, a globally unique UID and DTSTAMP per event, DATE values for all-day events, UTC date-times and display alarms for timed ones). IETF. 2009-09. https://www.rfc-editor.org/rfc/rfc5545 (verified: primary)
  4. [4] RFC 3986, Uniform Resource Identifier (URI): Generic Syntax (STD 66), section 3.5: the fragment is separated from the rest of the URI before dereference and handled by the user agent alone. IETF. 2005-01. https://www.rfc-editor.org/rfc/rfc3986#section-3.5 (verified: primary)