Metadata-Version: 2.4
Name: bidda-shield
Version: 0.2.0
Summary: Bidda Compliance Intelligence SDK — full MCP parity, LangChain, AutoGen, CrewAI
Home-page: https://bidda.com
Author: Bidda Intelligence
Author-email: api@bidda.com
Project-URL: Homepage, https://bidda.com
Project-URL: Documentation, https://bidda.com/developers
Project-URL: Source, https://git.bidda.com/Bidda-Ai/bidda-shield
Project-URL: Registry, https://bidda.com/intelligence
Project-URL: MCP Server, https://bidda.com/mcp
Keywords: compliance,GDPR,EU AI Act,LangChain,AutoGen,CrewAI,regulatory,legal,AI safety
Classifier: Development Status :: 4 - Beta
Classifier: Intended Audience :: Developers
Classifier: Topic :: Software Development :: Libraries :: Python Modules
Classifier: Topic :: Office/Business :: Financial :: Accounting
Classifier: License :: OSI Approved :: MIT License
Classifier: Programming Language :: Python :: 3
Classifier: Programming Language :: Python :: 3.9
Classifier: Programming Language :: Python :: 3.10
Classifier: Programming Language :: Python :: 3.11
Classifier: Programming Language :: Python :: 3.12
Requires-Python: >=3.9
Description-Content-Type: text/markdown
License-File: LICENSE
Requires-Dist: httpx>=0.24.0
Provides-Extra: langchain
Requires-Dist: langchain>=0.1.0; extra == "langchain"
Requires-Dist: langchain-core>=0.1.0; extra == "langchain"
Requires-Dist: pydantic>=2.0; extra == "langchain"
Provides-Extra: autogen
Requires-Dist: pyautogen>=0.2.0; extra == "autogen"
Provides-Extra: crewai
Requires-Dist: crewai>=0.28.0; extra == "crewai"
Requires-Dist: crewai-tools>=0.1.0; extra == "crewai"
Provides-Extra: all
Requires-Dist: langchain>=0.1.0; extra == "all"
Requires-Dist: langchain-core>=0.1.0; extra == "all"
Requires-Dist: pydantic>=2.0; extra == "all"
Requires-Dist: pyautogen>=0.2.0; extra == "all"
Requires-Dist: crewai>=0.28.0; extra == "all"
Requires-Dist: crewai-tools>=0.1.0; extra == "all"
Dynamic: author
Dynamic: author-email
Dynamic: classifier
Dynamic: description
Dynamic: description-content-type
Dynamic: home-page
Dynamic: keywords
Dynamic: license-file
Dynamic: project-url
Dynamic: provides-extra
Dynamic: requires-dist
Dynamic: requires-python
Dynamic: summary

# bidda-shield

**Verified compliance intelligence for AI agents.** Stop your LangChain, AutoGen, and CrewAI agents from hallucinating legal requirements.

```bash
pip install bidda-shield
```

---

## The problem

AI agents making decisions about hiring, credit scoring, data processing, or content moderation are operating under dozens of overlapping regulations â€” GDPR, EU AI Act, HIPAA, CCPA, Basel III. When an agent gets the legal logic wrong, it isn't just a bug. It's a regulatory liability event.

LLMs hallucinate regulations. bidda-shield doesn't.

Every compliance node in the Bidda registry traces to a specific clause of a primary legal instrument, verified against the source URL, and drift-checked weekly. No inference. No approximation.

---

## Quickstart

```python
from bidda_shield import BiddaShield

shield = BiddaShield()

# Find the compliance node most relevant to your agent's action
result = shield.check_compliance("process biometric data for access control")
print(result["title"])   # EU AI Act Article 5 â€” Prohibited AI Practices
print(result["bluf"])    # Plain-English summary of the legal obligation
```

---

## LangChain

```python
from langchain.agents import initialize_agent, AgentType
from langchain_openai import ChatOpenAI
from bidda_shield import BiddaLangChainTool

llm  = ChatOpenAI(model="gpt-4o")
tool = BiddaLangChainTool()

agent = initialize_agent(
    tools=[tool],
    llm=llm,
    agent=AgentType.ZERO_SHOT_REACT_DESCRIPTION,
    verbose=True,
)

agent.run(
    "My agent is about to make an automated credit decision. "
    "What regulations apply and what do they require?"
)
```

The tool returns the regulation title, domain, plain-English summary (BLUF), and a link to the full verified node â€” for $0.01 USDC per full unlock.

---

## AutoGen

```python
import autogen
from bidda_shield import BiddaAutoGenTool

config_list = [{"model": "gpt-4o", "api_key": "YOUR_OPENAI_KEY"}]

bidda_tool = BiddaAutoGenTool()

assistant = autogen.AssistantAgent(
    name="compliance_assistant",
    llm_config={
        "config_list": config_list,
        "functions": [bidda_tool.function_schema],
    },
)

user_proxy = autogen.UserProxyAgent(
    name="user",
    human_input_mode="NEVER",
    function_map={"bidda_compliance_lookup": bidda_tool.execute},
)

user_proxy.initiate_chat(
    assistant,
    message="What does GDPR Article 22 require for automated decision-making?",
)
```

---

## CrewAI

```python
from crewai import Agent, Task, Crew
from bidda_shield import BiddaCrewAITool

compliance_tool = BiddaCrewAITool()

compliance_officer = Agent(
    role="Chief Compliance Officer",
    goal="Ensure all AI agent actions comply with applicable regulations",
    backstory="Expert in GDPR, EU AI Act, HIPAA, and global data protection law.",
    tools=[compliance_tool],
    verbose=True,
)

task = Task(
    description="Review the agent action 'train a model on employee performance data' and identify all applicable regulations.",
    agent=compliance_officer,
)

crew = Crew(agents=[compliance_officer], tasks=[task])
crew.kickoff()
```

---

## Direct API usage

```python
from bidda_shield import BiddaShield

shield = BiddaShield()

# Search by keyword
nodes = shield.search_nodes("automated decision making")
for n in nodes:
    print(n["node_id"], "â€”", n["title"])

# Get a specific node (free discovery tier)
node = shield.get_node("gdpr-article-22-automated-decisions")
print(node["bluf"])

# Get full vault data (requires Skyfire JWT or USDC payment â€” $0.01)
shield_paid = BiddaShield(skyfire_token="YOUR_SKYFIRE_JWT")
full_node = shield_paid.get_node("gdpr-article-22-automated-decisions", vault=True)
print(full_node["deterministic_workflow"])  # Step-by-step legal compliance logic
```

---

## Full method reference (v0.2.0 â€” MCP parity)

Every tool exposed by the `bidda.com/mcp` MCP server is available as a Python
method. Results match what an MCP client would see for the same input â€” the
SDK mirrors the same logic, just returning structured `dict` / `list` data
instead of LLM-formatted markdown.

```python
from bidda_shield import BiddaShield
shield = BiddaShield()

# 1. Browse the registry
shield.list_pillars()                              # â†’ ["AI Governance & Law", ...]
shield.search_nodes("biometric", pillar="ai-gov")  # â†’ [{"node_id", "title", ...}, ...]
shield.get_node("gdpr-article-22-automated-decisions")  # discovery (free)
shield.get_node("gdpr-article-22-automated-decisions", vault=True)  # full ($0.01)

# 2. Walk prerequisites â€” what does this rule depend on?
shield.get_dependency_chain("eu-ai-act-article-10-data-governance-training", max_depth=2)
# â†’ {"root": "...", "title": "...", "chain": [{"depth": 0, ...}, ...], "total": 8}

# 3. Cross-framework mappings â€” GDPR Art 17 â†’ CCPA right-to-delete â†’ POPIA Sec 24
shield.get_crosswalk("gdpr-article-17-right-to-erasure")
# â†’ {"node_id", "title", "dimensions": ["ccpa_equivalent", ...], "vault_url"}

# 4. Regulatory change feed â€” what moved recently
shield.get_latest_changes(days=30, pillar="Cybersecurity")
# â†’ [{"node_id", "title", "domain", "last_updated"}, ...]  (newest first, max 20)

# 5. Jurisdiction-wide rule bundle â€” everything that applies in a market
shield.get_jurisdiction_bundle("eu", limit=25)
# â†’ {"jurisdiction", "total_matches", "by_pillar": {...}, "nodes": [...]}

# 6. MITRE technique â†’ compliance mapping
shield.get_mitre_mapping("T1566")           # ATT&CK Enterprise (phishing)
shield.get_mitre_mapping("AML.T0020")       # ATLAS (AI-specific)
shield.get_mitre_mapping("D3-FIM")          # D3FEND defensive
shield.get_mitre_mapping("CAPEC-66")        # CAPEC attack pattern
# â†’ [{"node_id", "title", "bluf", "dependencies", "crosswalk_dimensions", "vault_url"}, ...]

# 7. Pre-flight compliance check â€” primary agent runtime tool
result = shield.check_action_compliance(
    "process EU resident biometric data for access control",
    jurisdiction="eu",
    limit=10,
)
# â†’ {
#     "action": "...",
#     "keywords": ["process", "biometric", "data", "access", "control"],
#     "risk_level": "HIGH",          # LOW | MODERATE | HIGH
#     "match_count": 10,
#     "matches": [
#       {"node_id", "title", "domain", "bluf", "matched_terms": [...], "score": 4},
#       ...
#     ]
#   }

if result["risk_level"] == "HIGH":
    # Halt the agent action, surface the matched regulations to a human.
    raise RuntimeError(f"Compliance gate failed: {result['match_count']} matches")
```

The discovery index is cached client-side for 5 minutes after the first
call, so chained calls (e.g. `check_action_compliance` followed by
`get_dependency_chain` on the top match) reuse the same fetch.

---

## What's in a full node

Each vault-tier node contains:

- **BLUF** â€” plain-English summary of the legal obligation
- **deterministic_workflow** â€” step-by-step compliance checklist derived from the primary legal text
- **actionable_schema** â€” machine-readable compliance checkpoints
- **primary_citations** â€” exact section references to the legal instrument
- **crosswalks** â€” mappings to NIST, ISO, and peer standards
- **dependencies** â€” other regulations this one depends on or triggers
- **verification** â€” source URL, jurisdiction, instrument type, integrity hash

All content traces to a real primary legal source. No secondary commentary. No paraphrasing.

---

## Payment

- **Discovery tier** (free): node ID, title, domain, plain-English summary
- **Vault tier** ($0.01 USDC per node): full deterministic logic, citations, crosswalks, workflow

Pay with:
- **Skyfire** â€” pass a `skyfire-pay-id` bearer token (agent-native, no wallet required)
- **L402 / Base USDC** â€” send $0.01 to the Bidda Base wallet, pass the tx hash

```python
# With Skyfire
shield = BiddaShield(skyfire_token=os.getenv("BIDDA_SKYFIRE_TOKEN"))

# With Base tx hash
shield = BiddaShield(base_tx_hash="0xYOUR_TRANSACTION_HASH")
```

---

## Install options

```bash
# Core (no framework dependencies)
pip install bidda-shield

# With LangChain
pip install "bidda-shield[langchain]"

# With AutoGen
pip install "bidda-shield[autogen]"

# With CrewAI
pip install "bidda-shield[crewai]"

# Everything
pip install "bidda-shield[all]"
```

---

## Registry coverage

- **4,600+ verified nodes** across 31 regulatory pillars
- **Pillars:** AI Governance, Cybersecurity, Banking & Finance, Healthcare, Legal & IP, ESG, Workplace, Aviation & Defense, Crypto, Cloud, and 21 more
- **Jurisdictions:** EU, US, UK, Germany, Australia, Singapore, South Africa, and global instruments
- **Sources:** EU AI Act, GDPR, NIST CSF, ISO 27001, Basel III/IV, HIPAA, DORA, NIS2, FATF, and 150+ authority bodies

Full registry: [bidda.com/intelligence](https://bidda.com/intelligence)

---

## Links

- Registry: [bidda.com](https://bidda.com)
- API docs: [bidda.com/developers](https://bidda.com/developers)
- MCP server: `https://bidda.com/mcp` (Claude.ai, Claude Desktop, any MCP client)
- Source: [git.bidda.com/Bidda-Ai/bidda-shield](https://git.bidda.com/Bidda-Ai/bidda-shield)
- Support: [api@bidda.com](mailto:api@bidda.com)

---

## License

MIT â€” use freely, attribution appreciated.
