Quillmark Open Source

A careful first pass on RIA website marketing copy.

Compliance Flag is an open-source Python CLI that helps qualified reviewers examine public URLs and local content files for potential SEC Marketing Rule issues. It preserves the evidence, drafts rule-grounded findings, and leaves final judgment with the people responsible for the review.

Apache-2.0 Python CLI alpha Human review required

Focused on ordinary website language that can raise review questions.

Compliance Flag does not try to automate marketing judgment. It keeps the evidence, the rule text, and the draft interpretation separate enough that a reviewer can challenge each part honestly.
SEC Marketing Rule questions

General prohibitions, testimonials, endorsements, third-party ratings, performance advertising, misleading implications, and benefit claims that may need more risk context.

Evidence before conclusions

Each draft finding points back to the reviewed content, names the relevant authority, explains the concern, and offers possible remediation language for review.

Open-source workflow

The repository is the source of truth for installation, scope, issues, roadmap discussion, and documentation as the project develops.

Website copy can create regulatory questions even when it sounds ordinary.

Advisor home pages, service pages, bios, blog posts, and market commentary can all raise Marketing Rule issues. A useful first pass should not pretend to settle those questions by itself. It should preserve the page, identify the concern, cite the authority, and make the reviewer's job more concrete.
01

Preserve what was reviewed

Captured content gives reviewers something concrete to inspect instead of a memory or loose description of a page.

02

Tie concerns to authority

The workflow is designed around rule-grounded findings, not generic best-practice advice.

03

Keep final judgment with people

Outputs are drafts for compliance, legal, supervisory, or editorial review before anyone treats them as operational guidance.

From public page to a reviewable draft.

1

Capture

Fetch the public page or load the local file selected for review, then preserve the raw source artifact.

2

Draft

Generate a structured report with potential issues, citations, reasoning, and possible remediation language.

3

Review

Have qualified personnel challenge, revise, approve, reject, or archive the draft findings.

Common questions.

What is Compliance Flag?

Compliance Flag is an open-source Python CLI from Quillmark. It helps reviewers examine public URLs and local content files for potential SEC Marketing Rule issues without hiding the reasoning.

Does it provide legal or compliance advice?

No. Compliance Flag is review-support infrastructure. Its outputs are informational drafts. Qualified personnel still need to evaluate the facts, the authority, the context, and the final decision.

Is there a Codex plugin?

The current public release is a Python CLI alpha. A Codex plugin that wraps the CLI workflow for repository-local scans, report generation, and reviewer handoff is the next planned milestone.

What does the current workflow focus on?

The current workflow focuses on SEC Marketing Rule review for public RIA website content. Related sources can inform the context, but the repository should be treated as the source of truth for current scope.

Why is there a sample report before full documentation?

The sample report shows the output standard while installation and contributor documentation are still being prepared. It makes the intended reasoning, citation, and remediation style visible before the rest of the documentation is complete.

Compliance Flag and Quillmark LLC are not law firms and do not provide legal, compliance, regulatory, investment, tax, accounting, or financial advice. The project, workflow outputs, articles, and examples are for informational and operational use only. They should be reviewed by qualified personnel before use. Compliance Flag and Quillmark LLC do not determine that any communication meets all applicable requirements and are not affiliated with, endorsed by, or acting on behalf of the SEC or any other regulator. Regulatory and enforcement references are based on public sources and may not reflect later developments.

Compliance Flag is an independent open-source project. Compliance Flag is not endorsed by, sponsored by, or affiliated with OpenAI, Anthropic, or any model provider.