Executive Summary
Repository Overview
Technology Stack
5062 files · 549654 lines
Business Signals
What Meridian Understood
This repository is a web-based application using a JavaScript stack with both frontend and backend components. It incorporates user authentication, data encryption, and interfaces extensively with external APIs and manages third-party data transfers. Persistent data storage is indicated by comprehensive database access patterns.
Architecture: Full-stack web application
Compliance Scope
Applicable Regulations
Not Applicable Regulations
Needs More Information
Not enough was known to confirm or rule these out — Meridian conservatively evaluates their controls below until you provide the missing details.
Compliance Readiness
Implemented
Code Improvement Recommended
Requires Documentation
Requires Operational Evidence
Enterprise Readiness
Detected
Recommended Improvements
Operational Requirements
Documentation Required
SOC 2 Scope
The subset of the capabilities above that SOC 2's own controls actually reach.
Detected
Recommended Improvements
Operational Requirements
Documentation Required
Top Priorities
- Access Control (CRITICAL) — Can the organization (as a non-EU controller/processor) demonstrate that it has designated a representative in the Union?
Improves compliance posture for: GDPR, HIPAA Security Rule, SOC 2 Trust Services Criteria.
- Encryption In Transit (CRITICAL) — Can the organization demonstrate that it discontinues logical and physical protections over physical assets only after data and software are no longer recoverable?
Improves compliance posture for: SOC 2 Trust Services Criteria.
- Encryption At Rest (CRITICAL) — Can the organization demonstrate that it discontinues logical and physical protections over physical assets only after data and software are no longer recoverable?
Improves compliance posture for: SOC 2 Trust Services Criteria.
- Key Management (CRITICAL) — Can the organization demonstrate that it discontinues logical and physical protections over physical assets only after data and software are no longer recoverable?
Improves compliance posture for: SOC 2 Trust Services Criteria.
- Consent Management (HIGH) — Can the organization demonstrate that it provides information free of charge and has procedures for manifestly unfounded or excessive requests?
Improves compliance posture for: GDPR, SOC 2 Trust Services Criteria.
Full breakdown by effort below.
Recommended Actions
Quick Wins
- Access Control (CRITICAL)Can the organization (as a non-EU controller/processor) demonstrate that it has designated a representative in the Union?Improves compliance posture for: GDPR, HIPAA Security Rule, SOC 2 Trust Services Criteria.
- Encryption In Transit (CRITICAL)Can the organization demonstrate that it discontinues logical and physical protections over physical assets only after data and software are no longer recoverable?Improves compliance posture for: SOC 2 Trust Services Criteria.
- Encryption At Rest (CRITICAL)Can the organization demonstrate that it discontinues logical and physical protections over physical assets only after data and software are no longer recoverable?Improves compliance posture for: SOC 2 Trust Services Criteria.
- Log Retention (MEDIUM)Does the organization monitor log-in attempts to systems containing electronic protected health information and report discrepancies?Improves compliance posture for: HIPAA Security Rule.
Medium Effort
- Key Management (CRITICAL)Can the organization demonstrate that it discontinues logical and physical protections over physical assets only after data and software are no longer recoverable?Improves compliance posture for: SOC 2 Trust Services Criteria.
- Consent Management (HIGH)Can the organization demonstrate that it provides information free of charge and has procedures for manifestly unfounded or excessive requests?Improves compliance posture for: GDPR, SOC 2 Trust Services Criteria.
- Privileged Access Management (HIGH)Can the organization demonstrate that it does not make decisions based solely on automated processing that produce legal or significant effects, without appropriate safeguards?Improves compliance posture for: GDPR, SOC 2 Trust Services Criteria.
- Audit Logging (HIGH)Can the organization demonstrate that it has properly applied exceptions to breach communication to data subjects?Improves compliance posture for: GDPR, HIPAA Security Rule, SOC 2 Trust Services Criteria.
- Incident Response Plan (HIGH)Has the organization conducted and documented a risk analysis assessing threats and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information?Improves compliance posture for: HIPAA Security Rule, SOC 2 Trust Services Criteria.
- Backup And Recovery (HIGH)Does the organization maintain retrievable, exact backup copies of electronic protected health information?Improves compliance posture for: HIPAA Security Rule, SOC 2 Trust Services Criteria.
- Data Retention (HIGH)Can the organization demonstrate that it implements policies and procedures to store inputs, items in processing, and outputs completely, accurately, and timely in accordance with system specifications?Improves compliance posture for: SOC 2 Trust Services Criteria.
- Records Of Processing (MEDIUM)Can the organization demonstrate that processing of criminal conviction data is under official control or authorised by law with appropriate safeguards?Improves compliance posture for: GDPR, HIPAA Security Rule, SOC 2 Trust Services Criteria.
- Data Masking (MEDIUM)Can the organization demonstrate that processing of criminal conviction data is under official control or authorised by law with appropriate safeguards?Improves compliance posture for: GDPR, SOC 2 Trust Services Criteria.
- Maker Checker (MEDIUM)Can the organization demonstrate that it does not make decisions based solely on automated processing that produce legal or significant effects, without appropriate safeguards?Improves compliance posture for: GDPR, SOC 2 Trust Services Criteria.
- Model Testing (MEDIUM)Can the organization demonstrate that it does not make decisions based solely on automated processing that produce legal or significant effects, without appropriate safeguards?Improves compliance posture for: GDPR.
- Business Impact Analysis (MEDIUM)Can the organization demonstrate that it has assessed the risks to personal data when determining security measures?Improves compliance posture for: GDPR, HIPAA Security Rule, SOC 2 Trust Services Criteria.
- Configuration Management (MEDIUM)Has the organization conducted and documented a risk analysis assessing threats and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information?Improves compliance posture for: HIPAA Security Rule.
- Asset Inventory (MEDIUM)Has the organization conducted and documented a risk analysis assessing threats and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information?Improves compliance posture for: HIPAA Security Rule.
- Data Lifecycle Management (MEDIUM)Does the organization have documented policies for the final disposition of electronic protected health information and the media it is stored on?Improves compliance posture for: HIPAA Security Rule, SOC 2 Trust Services Criteria.
- Information Security Policy (MEDIUM)Has the organization implemented documented policies and procedures reasonably designed to comply with the HIPAA Security Rule's standards and implementation specifications?Improves compliance posture for: HIPAA Security Rule.
- Data Classification (MEDIUM)Can the organization demonstrate that it discontinues logical and physical protections over physical assets only after data and software are no longer recoverable?Improves compliance posture for: SOC 2 Trust Services Criteria.
- Policy Management (LOW)Can the organization demonstrate that processing of criminal conviction data is under official control or authorised by law with appropriate safeguards?Improves compliance posture for: GDPR, HIPAA Security Rule, SOC 2 Trust Services Criteria.
- Security Awareness Training (LOW)Can the organization demonstrate that it does not make decisions based solely on automated processing that produce legal or significant effects, without appropriate safeguards?Improves compliance posture for: GDPR, SOC 2 Trust Services Criteria.
- Data Quality Management (INFORMATIONAL)Can the organization demonstrate that it does not make decisions based solely on automated processing that produce legal or significant effects, without appropriate safeguards?Improves compliance posture for: GDPR.
Strategic Initiatives
- AI Risk Assessment (HIGH)Can the organization demonstrate that it does not make decisions based solely on automated processing that produce legal or significant effects, without appropriate safeguards?Improves compliance posture for: GDPR, SOC 2 Trust Services Criteria.
- Bias Detection (HIGH)Can the organization demonstrate that it does not make decisions based solely on automated processing that produce legal or significant effects, without appropriate safeguards?Improves compliance posture for: GDPR.
- Data Loss Prevention (HIGH)Can the organization demonstrate that automated decision-making based on special category data is only done with explicit consent or substantial public interest and appropriate safeguards?Improves compliance posture for: GDPR.
- Data Protection Impact Assessment (HIGH)Can the organization demonstrate that it has assessed the risks to personal data when determining security measures?Improves compliance posture for: GDPR, SOC 2 Trust Services Criteria.
- Privacy Impact Assessment (HIGH)Can the organization demonstrate that it has assessed the risks to personal data when determining security measures?Improves compliance posture for: GDPR, SOC 2 Trust Services Criteria.
- Model Monitoring (MEDIUM)Can the organization demonstrate that it does not make decisions based solely on automated processing that produce legal or significant effects, without appropriate safeguards?Improves compliance posture for: GDPR.
- Physical Access Control (MEDIUM)Can the organization demonstrate that automated decision-making based on special category data is only done with explicit consent or substantial public interest and appropriate safeguards?Improves compliance posture for: GDPR.
Compliance Roadmap
Now · Quick Wins
- Access Control
- Encryption In Transit
- Encryption At Rest
- Log Retention
Next · Medium Effort
- Key Management
- Consent Management
- Privileged Access Management
- Audit Logging
- Incident Response Plan
- Backup And Recovery
- Data Retention
- Records Of Processing
- Data Masking
- Maker Checker
- Model Testing
- Business Impact Analysis
- Configuration Management
- Asset Inventory
- Data Lifecycle Management
- Information Security Policy
- Data Classification
- Policy Management
- Security Awareness Training
- Data Quality Management
Later · Strategic Initiatives
- AI Risk Assessment
- Bias Detection
- Data Loss Prevention
- Data Protection Impact Assessment
- Privacy Impact Assessment
- Model Monitoring
- Physical Access Control
Next Steps
Technical Findings (59)
Showing top 50 of 59, ranked by severity then confidence. Export to JSON or SARIF for the complete list.
Control Mapping Appendix
Raw control-level mapping (control IDs, clause text) is intentionally not inlined here — export to JSON or SARIF for the complete, machine-readable control mapping.