💡 Inspiration
Organizations constantly update business policies, but changing a policy document does not guarantee that the change has actually been implemented everywhere it matters.
A policy may say one thing while application code, forms, internal documents, support workflows, or other organizational artifacts still follow the previous rule. This creates a hidden gap between policy intent and operational reality — a gap that can be difficult to discover and even harder to prove as resolved.
RippleProof was inspired by one simple question:
How can an organization prove that a policy change was actually implemented?
Instead of treating policy updates as isolated document changes, RippleProof follows the ripple they create across an organization. It identifies affected artifacts, explains the impact, proposes evidence-backed repairs, keeps a human reviewer in control, and ultimately produces executable evidence that the updated rule is actually being enforced.
RippleProof doesn't stop at detecting change — it helps prove the change reached the systems that matter.
What it does
RippleProof is an AI-powered policy change intelligence platform that transforms business policy changes into traceable, human-reviewed, and verifiable evidence.
A user defines the previous and updated business rules, then uploads organizational artifacts that may depend on that policy.
RippleProof then:
- Converts the policy change into a structured, machine-readable contract.
- Uses semantic analysis to understand what actually changed.
- Inspects uploaded artifacts for implementations that conflict with the updated policy.
- Identifies affected artifacts and explains why they are impacted.
- Generates evidence-backed repair suggestions.
- Keeps a human reviewer in control by requiring explicit approval.
- Runs deterministic boundary tests against the updated rule.
- Preserves the analysis, approval, verification results, and event history as persistent evidence.
- Provides operational evaluation and deterministic benchmark results instead of relying solely on an LLM to claim correctness.
Example: 30 days → 14 days
In the demo, a Customer Refund Policy changes from 30 days to 14 days.
An uploaded refund.py artifact still enforces the old rule:
purchase_age_days <= 30
RippleProof detects the conflict, identifies the artifact as affected, explains the issue, and proposes:
purchase_age_days <= 14
The repair is not automatically trusted or silently applied. A human reviewer first approves it.
RippleProof then runs deterministic verification around the policy boundary and successfully passes 6/6 tests, producing machine-verifiable evidence that the new 14-day rule is correctly enforced.
The RippleProof workflow
Policy Change → Semantic Analysis → Impact Detection → Proposed Repair → Human Approval → Deterministic Verification → Persistent Evidence
How we built it
RippleProof was designed as a full-stack system with a clear separation between user experience, semantic reasoning, human oversight, deterministic verification, and persistent evidence.
Frontend
The frontend is built with Next.js and TypeScript and provides the complete user workflow:
- User authentication
- Creating policy analyses
- Uploading organizational artifacts
- Reviewing detected impacts
- Inspecting proposed repairs and diffs
- Human approval
- Running deterministic verification
- Viewing persistent run history
- Reviewing operational evaluation results
The production frontend is deployed on Vercel.
Backend
The backend is built with FastAPI and Python and provides APIs for:
- Authentication
- Policy analysis
- Run management
- Impact detection
- Repair approval
- Deterministic verification
- System status
- Evaluation and benchmarking
The production backend is deployed on Railway.
Semantic Policy Intelligence
RippleProof uses an LLM-powered semantic analysis layer to understand the relationship between the previous policy, updated policy, and uploaded organizational artifacts.
Instead of relying only on natural-language responses, RippleProof converts policy changes into structured information including:
- Subject
- Policy attribute
- Old rule
- New rule
- Operator
- Threshold
- Unit
- Change type
- Risk domain
- Boundary values
This machine-readable contract becomes the foundation for downstream impact detection, repair generation, and verification.
Human-in-the-Loop Repair
RippleProof deliberately separates detecting a problem from changing an implementation.
When an outdated artifact is discovered, the system generates a proposed repair together with its rationale and before/after diff.
The repair remains pending until a human reviewer explicitly approves it.
This architecture combines the speed of AI-assisted analysis with the accountability of human oversight.
Deterministic Verification
A core design decision behind RippleProof was simple:
An LLM should not be the final authority on whether its own suggested repair is correct.
After human approval, RippleProof evaluates the repaired implementation using deterministic tests around important policy boundaries.
For the 14-day refund example, the system evaluates:
0, 13, 14, 15, 30, 31
The expected behavior is compared directly with the actual behavior.
This transforms an AI-generated recommendation into machine-verifiable evidence.
Persistence and Auditability
PostgreSQL stores policy runs, machine-readable contracts, detected impacts, proposed patches, verification results, and event history.
An analysis therefore does not disappear after an AI response. It becomes a persistent record that can be reviewed later.
Each run answers:
What changed → What was affected → What was proposed → What was approved → What was verified → Did it pass?
Challenges we ran into
One of the biggest challenges was connecting semantic AI reasoning with deterministic software verification.
LLMs are valuable for understanding policy language and discovering semantic relationships, but a production-oriented system should not rely solely on an LLM saying that an implementation is correct.
We therefore designed RippleProof so that semantic reasoning discovers and explains the problem, while deterministic verification proves measurable behavior.
Another challenge was building a reliable human-in-the-loop workflow. Proposed repairs, approval state, verification state, and event history needed to persist across multiple requests rather than existing only inside a single AI interaction.
Production persistence introduced additional challenges involving PostgreSQL integration, database configuration, authentication, and state management.
Deployment also required coordinating two separate production services — a Vercel frontend and Railway backend — while correctly configuring environment variables, API routing, authentication behavior, and database connectivity.
File-based analysis added another challenge: RippleProof needed to retain the original artifact, understand how it related to the changed policy, generate a proposed repair, and preserve both the original and updated states as evidence.
Solving these problems helped transform RippleProof from a policy-analysis prototype into a complete end-to-end system.
Accomplishments that we're proud of
The accomplishment we are most proud of is building an end-to-end policy change lifecycle instead of stopping at AI-generated analysis.
RippleProof can move from a natural-language policy change all the way to deterministic evidence that the resulting implementation follows the updated rule.
We successfully implemented:
- AI-powered semantic policy analysis
- Machine-readable policy contracts
- Artifact-level impact detection
- Severity and confidence information
- Evidence-backed explanations
- Automated repair proposals
- Human-controlled approval
- Code-level before/after diffs
- Deterministic boundary verification
- Persistent analysis history
- Detailed event trails
- Operational evaluation
- Deterministic benchmarking
- Production authentication
- PostgreSQL persistence
- Deployed Next.js frontend
- Deployed FastAPI backend
In our demonstrated refund-policy workflow, RippleProof detects the outdated 30-day implementation, proposes the required 30 → 14 day repair, receives human approval, and passes 6/6 deterministic verification tests.
Most importantly, the final result is not simply:
“The AI thinks the problem is fixed.”
It becomes:
“Here is the evidence showing what changed, what was affected, what was repaired, what was approved, and what tests prove the new behavior.”
What we learned
Building RippleProof reinforced one of the project's most important lessons:
AI reasoning and software verification solve different parts of the problem.
LLMs are powerful for interpreting unstructured policy language, identifying semantic relationships, and explaining why an organizational artifact may be affected.
Deterministic systems, however, are better suited for proving measurable conditions.
Combining these capabilities gave RippleProof a stronger architecture:
AI for understanding.
Humans for control.
Deterministic tests for proof.
We also learned how important structured outputs are when moving from an AI prototype toward a production-oriented system.
Transforming natural-language policies into machine-readable contracts made downstream impact analysis, repair generation, boundary testing, and auditability significantly more reliable.
Finally, deploying RippleProof reinforced how frontend, backend, authentication, database persistence, environment configuration, AI services, and verification logic must work together as one complete production system.
What's next for RippleProof
RippleProof currently demonstrates the complete policy-to-proof workflow, but the architecture can extend much further.
The next stage is to support larger organizational environments where a single policy change may affect many systems and artifacts simultaneously.
Future improvements include:
- Support for additional artifact formats and document types
- Repository-level codebase analysis
- Automatic dependency and policy-impact mapping
- More advanced policy contract extraction
- Organization-wide policy version tracking
- Role-based review and approval workflows
- Integration with enterprise knowledge systems
- CI/CD verification for policy-sensitive code changes
- Automated regression testing when policies change
- Richer evidence reports for compliance teams
- Drift detection for previously verified implementations
- Expanded deterministic benchmark suites
- Improved semantic evaluation across different policy domains
The long-term vision is for RippleProof to become an evidence layer between organizational policy and operational systems.
When a policy changes, organizations should not have to manually search every document, application, workflow, and implementation to determine whether that change propagated correctly.
RippleProof aims to make that process:
Detectable. Explainable. Human-controlled. Verifiable. Auditable.
🚀 From policy change to executable proof.
Built With
- ai
- compliance
- deterministic-testing
- fastapi
- generative-ai
- human-in-the-loop
- llm
- next.js
- openai
- policy-automation
- postgresql
- python
- railway
- react
- rest-api
- semantic-analysis
- typescript
- vercel

Log in or sign up for Devpost to join the conversation.