Solutions — EdTech · EU AI Act

The student data that never left the runner

How an EdTech team turned "please be careful with fixtures" into a merge check — and walked into their Annex III audit with evidence instead of promises.

Try the free EU AI Act check →

EU AI Act Annex III high-risk obligations for educational AI systems now apply from December 2, 2027. The deadline moved — the excuse to wait didn't. Start tracking compliance now.

THURSDAY, 16:42 — SPRINT 23

A developer copies a production sample into a test fixture to reproduce a grading bug. Real student emails, a consent flag, 340 lines down. The pull request collects two approvals — nobody scrolls that far on a Thursday afternoon.

THURSDAY, 16:42:07 — CI

The merge is blocked before human review even starts. The check names the file, the line number, and the consent-marker rule it tripped — showing masked evidence only. The raw diff never left the CI runner.

Nobody had to catch it. The pipeline already had.

The problem we kept living

Before the gate, there was the audit week

If you build learning software, you already know this week:

  • Student-data hygiene lived in a wiki page — last edited two re-orgs ago, read by nobody under deadline.
  • Every audit began with archaeology: which sprint did that fixture land in, who approved it, was it ever in production?
  • Code review caught what reviewers happened to read. Line 340 on a Thursday afternoon was never going to be one of them.
  • The EU AI Act put a date on it — then pushed it back to December 2, 2027. Annex III still turns "we should document this" into "show us the evidence." This team didn't wait for the new date to start proving it.

So the policy stopped being a wiki page and became a merge check.

What it does

The guided tour — from commit to evidence

01

A rule your DPO can read

Compliance rules are plain declarations — what to detect, where to look, what happens on a hit. The GDPR detective pack ships ready; your org can add its own signatures without asking us.

RULE · DC-EDU-011BLOCKS MERGE
Detectstudent identifier, unmasked
Wheretest fixtures · seeds
CitesGDPR Art. 5(1)(c), 25
02

The merge that fails politely

A hit fails the check with the file, line, and rule — and masked evidence only. The reviewer sees enough to fix it; the sensitive value itself never leaves your CI runner.

PR #1382 · CHECK RESULTFAILED
fixtures/grades_seed.json:340j***@school***.edu
RuleDC-EDU-011 · critical
Evidencemasked · runner-local
03

Drift, scored between releases

Merge-time is half the story. Hourly process rules score review coverage and documentation habits against your Jira and GitHub activity — so slipping standards show up as a trend, not a surprise.

COMPLIANCE · BY DOMAINTHIS SPRINT
Student-data handling98%
Review coverage91%
Annex III documentation86% ↘
04

Sign-off that stays locked

What needs human judgment gets a named reviewer and a locked gate — it can't be ticked until the automated checks pass. The result exports signed and timestamped: evidence, not screenshots.

RELEASE GATE · TERM LAUNCHLOCKED
CI scan — 14 reposPASSING
Risk checklist · A. Weberawaiting sign-off
Audit exportsigned · sha256:9f2c…
What changed

The same audit, one release later

Before

  • —Audit prep was a two-week archaeology dig
  • —"Is student data in any fixture?" — nobody could say
  • —Consent handling was a convention
  • —Annex III readiness was a feeling

After

  • ✓Point-in-time snapshots export signed, in one click
  • ✓Every merge since Sprint 23 was scanned — the ledger says zero
  • ✓It's a blocking check with a named rule
  • ✓It's a percentage with history
Is this for you

An honest fit check

This fits if

  • ✓You build learning software that touches minors' data
  • ✓Your team merges through pull requests on GitHub or GitLab
  • ✓Annex III applies to you from December 2, 2027 — plenty of runway if you start now
  • ✓You'd rather block a merge than write an incident report

And honestly, if

  • ·You need semantic judgment — "is this consent flow correct?" is a human's call. PulseCheck routes it to a locked, role-restricted attestation instead of pretending to detect it.
  • ·You don't merge through CI — the gate has nothing to hook into.
  • ·You want developer-level scorecards — deliberately not built, and it won't be.
NewExpert Review

Put the judgment calls to an independent lawyer

Some questions stay a human's call. With Expert Review you can also put them to an independent, licensed lawyer, and their verdict appears next to each rule.

How Expert Review works →

EdTech compliance FAQ

Can PulseCheck block a pull request?

Yes. The CI Action runs your organization's ruleset against every diff and fails the check when a defined signature (an unmasked student identifier, a hardcoded credential) is present — configure it as a required status check and the PR cannot merge.

Does PulseCheck read our source code?

The scan runs inside your own CI runner. Findings are masked before they ever leave it — PulseCheck's servers see a match/no-match result and a masked snippet, never your raw source or student data.

Does it detect missing tenant isolation or consent logic?

No — honestly. That's a judgment call, not a pattern match. PulseCheck routes it to a locked sign-off task a named reviewer must explicitly attest, with the attestation recorded in an audit-ready export. With Expert Review you can also put that question to an independent, licensed lawyer.

How does PulseCheck help with EU AI Act Annex III?

PulseCheck ships an EU AI Act rule template pack covering the Annex III risk-management and human-oversight obligations, evaluated hourly against your Jira/GitHub activity, plus a compliance gate with a locked sign-off task and a signed, timestamped export for your audit trail. Annex III high-risk obligations now apply from December 2, 2027, postponed from the original August 2026 date — reason enough to start tracking compliance now rather than wait for the new one to approach.

Which compliance frameworks ship as templates?

GDPR, EU AI Act, DORA, and a general QA/incident-management pack ship as ready-to-install rule templates — install one and PulseCheck starts scoring your existing data against it immediately.

Bring us your scariest fixture

A 20-minute walkthrough is enough to see your own repository scanned. First rule live the same day — and line 340 never ships again.