0 of 544 applicable controls automatically verified
Deterministic, evidence-backed scan result
Meridian provides automated compliance assessments and recommendations, not legal advice. Final compliance determinations should be reviewed by qualified legal, compliance, or security professionals where required.
Meridian Compliance Report
haystack
Generated 23 July 2026, 05:25 UTC
Report 385c749e088d5c23ead437ad
Meridian provides automated compliance assessments and recommendations, not legal advice. Final compliance determinations should be reviewed by qualified legal, compliance, or security professionals where required.
This repository is used for development involving web technologies, specifically focusing on React framework with JavaScript and TypeScript. It utilizes an AI stack, the OpenAI SDK, suggesting a connection to AI-based features or interfaces. The infrastructure is managed with Docker for containerization and GitHub Actions for automation.
Architecture: Web application
Compliance Scope
Applicable Regulations
GDPRPrivacy & Data ProtectionStatutory law
Your application stores or processes personal data of individuals in the European Union.
Required: matched on stores_personal_data, offers_goods_services_to_eu.
In force since May 2018; applies extraterritorially to organizations offering goods or services to, or monitoring, individuals in the EU.
EU AI ActAI Governance & Responsible AIStatutory law
Your repository deploys AI models or AI-powered systems.
Required: matched on ai_usage.
In force since August 2024 with phased application — prohibited practices first, general-purpose AI and high-risk obligations phasing in later; verify current phase-in dates.
AI risk context: role: Provider; output used in the EU: yes; high-risk use case indicated: no; general-purpose model provider: no
PCI DSSPayments & Financial SecurityContractual standard
Your application processes payments or handles cardholder data.
Required: matched on processes_payments.
An industry standard enforced through card-network and acquirer agreements, not a statute; applies to entities that store, process, or transmit cardholder data.
Your application is in production and handles customer data requiring independent assurance.
Optional: base condition met, but no additional signal beyond production.
A voluntary attestation framework (AICPA Trust Services Criteria) driven by customer and contractual demand, not law.
NIST AI RMFAI Governance & Responsible AIVoluntary attestation
Your application develops, deploys, or uses AI/ML systems.
Required: matched on ai_usage.
AI RMF 1.0 released January 2023 by NIST; a voluntary risk-management framework, not a binding regulation -- adopted for market trust and structured AI governance, not because it is legally required.
Not Applicable Regulations
DPDPA 2023Privacy & Data Protection
Excluded: none of 'primary_jurisdiction', 'offers_goods_services_to_india' match the conditions required for this framework.
DPDPA Rules, 2025Privacy & Data Protection
Excluded: none of 'primary_jurisdiction', 'offers_goods_services_to_india' match the conditions required for this framework.
RBI FREE-AI FrameworkAI Governance & Responsible AI
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
SEBI AI/ML GuidelinesAI Governance & Responsible AI
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
RBI Digital Payment Security ControlsPayments & Financial Security
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
RBI IT Governance & Risk ControlsCybersecurity & Operational Security
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
RBI NBFC IT FrameworkFinancial Sector Regulations
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
Access Control (CRITICAL) — Can the organization demonstrate that it does not create or expand facial recognition databases through untargeted scraping?
Improves compliance posture for: EU AI Act, GDPR, HIPAA Security Rule, NIST AI RMF, PCI DSS, SOC 2 Trust Services Criteria.
Encryption In Transit (CRITICAL) — Can the organization demonstrate that it does not create or expand facial recognition databases through untargeted scraping?
Improves compliance posture for: EU AI Act, GDPR, NIST AI RMF, PCI DSS, SOC 2 Trust Services Criteria.
Encryption At Rest (CRITICAL) — Can the organization demonstrate that it does not create or expand facial recognition databases through untargeted scraping?
Improves compliance posture for: EU AI Act, GDPR, NIST AI RMF, PCI DSS, SOC 2 Trust Services Criteria.
Authentication (CRITICAL) — If the organization operates a healthcare clearinghouse within a larger entity, has it implemented policies isolating clearinghouse electronic protected health information from the rest of the organization?
Key Management (CRITICAL) — Can the organization demonstrate that it does not create or expand facial recognition databases through untargeted scraping?
Improves compliance posture for: EU AI Act, GDPR, NIST AI RMF, PCI DSS, SOC 2 Trust Services Criteria.
Full breakdown by effort below.
Recommended Actions
Quick Wins
Access Control (CRITICAL)
Can the organization demonstrate that it does not create or expand facial recognition databases through untargeted scraping?
Improves compliance posture for: EU AI Act, GDPR, HIPAA Security Rule, NIST AI RMF, PCI DSS, SOC 2 Trust Services Criteria.
Encryption In Transit (CRITICAL)
Can the organization demonstrate that it does not create or expand facial recognition databases through untargeted scraping?
Improves compliance posture for: EU AI Act, GDPR, NIST AI RMF, PCI DSS, SOC 2 Trust Services Criteria.
Encryption At Rest (CRITICAL)
Can the organization demonstrate that it does not create or expand facial recognition databases through untargeted scraping?
Improves compliance posture for: EU AI Act, GDPR, NIST AI RMF, PCI DSS, SOC 2 Trust Services Criteria.
Authentication (CRITICAL)
If the organization operates a healthcare clearinghouse within a larger entity, has it implemented policies isolating clearinghouse electronic protected health information from the rest of the organization?
Can the organization demonstrate that it does not create or expand facial recognition databases through untargeted scraping?
Improves compliance posture for: EU AI Act, GDPR, NIST AI RMF, PCI DSS, SOC 2 Trust Services Criteria.
Privileged Access Management (HIGH)
Can the organization demonstrate that it has taken measures to ensure a sufficient level of AI literacy among staff and others involved in the operation and use of AI systems?
Improves compliance posture for: EU AI Act, GDPR, NIST AI RMF, SOC 2 Trust Services Criteria.
Consent Management (HIGH)
Can the organization demonstrate that AI systems intended to interact with natural persons are designed to inform them they are interacting with an AI system?
Improves compliance posture for: EU AI Act, GDPR, SOC 2 Trust Services Criteria.
Data Subject Request Handling (HIGH)
Can the organization demonstrate that it has procedures to handle complaints regarding infringement of the AI Act?
Improves compliance posture for: EU AI Act, NIST AI RMF.
Audit Logging (HIGH)
Can the organization demonstrate that it has properly applied exceptions to breach communication to data subjects?
Has the organization conducted and documented a risk analysis assessing threats and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information?
Can the organization demonstrate that it has taken measures to ensure a sufficient level of AI literacy among staff and others involved in the operation and use of AI systems?
Improves compliance posture for: EU AI Act, GDPR, NIST AI RMF, SOC 2 Trust Services Criteria.
Model Testing (MEDIUM)
Can the organization demonstrate that it has taken measures to ensure a sufficient level of AI literacy among staff and others involved in the operation and use of AI systems?
Improves compliance posture for: EU AI Act, GDPR, NIST AI RMF.
Data Classification (MEDIUM)
Can the organization demonstrate that it does not create or expand facial recognition databases through untargeted scraping?
Improves compliance posture for: EU AI Act, GDPR, NIST AI RMF, PCI DSS, SOC 2 Trust Services Criteria.
Records Of Processing (MEDIUM)
Can the organization (as a law enforcement authority) demonstrate that it notifies each use of real-time remote biometric identification to the relevant authorities and submits annual reports?
Improves compliance posture for: EU AI Act, GDPR, HIPAA Security Rule, NIST AI RMF, PCI DSS, SOC 2 Trust Services Criteria.
Grievance Redressal (MEDIUM)
Can the organization demonstrate that it has procedures to handle complaints regarding infringement of the AI Act?
Improves compliance posture for: EU AI Act, NIST AI RMF.
Business Impact Analysis (MEDIUM)
Can the organization demonstrate that it has consulted the supervisory authority where DPIA indicated high risk?
Has the organization conducted and documented a risk analysis assessing threats and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information?
Has the organization conducted and documented a risk analysis assessing threats and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information?
Has the organization implemented documented policies and procedures reasonably designed to comply with the HIPAA Security Rule's standards and implementation specifications?
Can the organization demonstrate that it has taken measures to ensure a sufficient level of AI literacy among staff and others involved in the operation and use of AI systems?
Improves compliance posture for: EU AI Act, GDPR, NIST AI RMF, SOC 2 Trust Services Criteria.
Policy Management (LOW)
Can the organization (as a law enforcement authority) demonstrate that it notifies each use of real-time remote biometric identification to the relevant authorities and submits annual reports?
Improves compliance posture for: EU AI Act, GDPR, HIPAA Security Rule, NIST AI RMF, PCI DSS, SOC 2 Trust Services Criteria.
Data Quality Management (INFORMATIONAL)
Can the organization demonstrate that it has taken measures to ensure a sufficient level of AI literacy among staff and others involved in the operation and use of AI systems?
Improves compliance posture for: EU AI Act, GDPR, NIST AI RMF.
Strategic Initiatives
AI Risk Assessment (HIGH)
Can the organization demonstrate that it has taken measures to ensure a sufficient level of AI literacy among staff and others involved in the operation and use of AI systems?
Improves compliance posture for: EU AI Act, GDPR, NIST AI RMF, SOC 2 Trust Services Criteria.
Bias Detection (HIGH)
Can the organization demonstrate that it has taken measures to ensure a sufficient level of AI literacy among staff and others involved in the operation and use of AI systems?
Improves compliance posture for: EU AI Act, GDPR, NIST AI RMF.
Privacy Impact Assessment (HIGH)
Can the organization demonstrate that it has consulted the supervisory authority where DPIA indicated high risk?
Can the organization demonstrate: aI system security and resilience -- as identified in the map function -- are evaluated and documented.
Improves compliance posture for: NIST AI RMF.
Model Monitoring (MEDIUM)
Can the organization demonstrate that it has taken measures to ensure a sufficient level of AI literacy among staff and others involved in the operation and use of AI systems?
Improves compliance posture for: EU AI Act, GDPR, NIST AI RMF.
Compliance Roadmap
Now · Quick Wins
Access Control
Encryption In Transit
Encryption At Rest
Authentication
Patch Management
Vulnerability Scanning
Log Retention
Next · Medium Effort
Key Management
Privileged Access Management
Consent Management
Data Subject Request Handling
Audit Logging
Incident Response Plan
Backup And Recovery
Data Retention
Maker Checker
Model Testing
Data Classification
Records Of Processing
Grievance Redressal
Business Impact Analysis
Asset Inventory
Configuration Management
Data Lifecycle Management
Data Masking
Information Security Policy
Security Awareness Training
Policy Management
Data Quality Management
Later · Strategic Initiatives
AI Risk Assessment
Bias Detection
Privacy Impact Assessment
Data Protection Impact Assessment
Penetration Testing
Model Monitoring
Next Steps
Start with Top Priorities above, then work through the full Quick Wins/Medium Effort/Strategic Initiatives breakdown.
Technical Findings below show exactly where each gap was detected in your repository; export to PDF/HTML for a
shareable version, or JSON/SARIF to feed a CI pipeline.
Technical Findings (287)
Showing top 50 of 287, ranked by severity then confidence.
Export to JSON or SARIF for the complete list.
CriticalEU_AI_ART_5_001 — Prohibition of Subliminal Manipulative TechniquesCode Improvement Recommended
Missing: Consent Management
CriticalEU_AI_ART_5_002 — Prohibition of Exploiting VulnerabilitiesCode Improvement Recommended
Missing: Consent Management
CriticalEU_AI_ART_5_003 — Prohibition of Social ScoringCode Improvement Recommended
Missing: Consent Management
CriticalEU_AI_ART_5_004 — Prohibition of Predictive Policing Risk Assessments Based Solely on ProfilingCode Improvement Recommended
Missing: Consent Management
CriticalEU_AI_ART_5_005 — Prohibition of Untargeted Scraping for Facial Recognition DatabasesCode Improvement Recommended
Missing: Access Control, Data Classification, Encryption At Rest, Encryption In Transit, Key Management
CriticalEU_AI_ART_5_006 — Prohibition of Emotion Recognition in Workplace and EducationCode Improvement Recommended
Missing: Consent Management
CriticalEU_AI_ART_5_007 — Prohibition of Biometric Categorisation for Sensitive CharacteristicsCode Improvement Recommended
Missing: Consent Management
CriticalEU_AI_ART_5_008 — Restrictions on Real-Time Remote Biometric Identification for Law EnforcementCode Improvement Recommended
Missing: Consent Management
CriticalGDPR_ART_10_001 — Processing of Criminal Convictions and OffencesCode Improvement Recommended
Missing: Access Control, Data Classification, Encryption At Rest, Encryption In Transit, Key Management
CriticalGDPR_ART_22_004 — Automated Decision-Making with Special Categories of DataCode Improvement Recommended
Missing: Access Control, Data Classification, Encryption At Rest, Encryption In Transit, Key Management
CriticalGDPR_ART_28_001 — Processor - Selection and GuaranteesCode Improvement Recommended
Missing: Access Control
CriticalGDPR_ART_35_001 — Data Protection Impact AssessmentCode Improvement Recommended
Missing: Access Control, Data Classification, Encryption At Rest, Encryption In Transit, Key Management
Missing: Access Control, Authentication, Data Classification, Encryption At Rest, Encryption In Transit, Key Management
CriticalPCI_REQ_2_2_7 — Encrypt All Non-Console Administrative AccessCode Improvement Recommended
Missing: Access Control, Authentication, Data Classification, Encryption At Rest, Encryption In Transit, Key Management
CriticalPCI_REQ_3_2_1 — Implement Data Retention and Disposal Policies to Minimize Account Data StorageCode Improvement Recommended
Missing: Access Control, Data Classification, Data Lifecycle Management, Data Retention, Encryption At Rest, Encryption In Transit, Key Management
CriticalPCI_REQ_3_3_1 — Do Not Store Sensitive Authentication Data After AuthorizationCode Improvement Recommended
Missing: Access Control, Data Classification, Data Lifecycle Management, Encryption At Rest, Encryption In Transit, Key Management
CriticalPCI_REQ_3_3_1_1 — Do Not Store Full Track Data After AuthorizationCode Improvement Recommended
Missing: Access Control, Data Classification, Data Lifecycle Management, Encryption At Rest, Encryption In Transit, Key Management
CriticalPCI_REQ_3_3_1_2 — Do Not Store Card Verification Code After AuthorizationCode Improvement Recommended
Missing: Access Control, Data Classification, Data Lifecycle Management, Encryption At Rest, Encryption In Transit, Key Management
CriticalPCI_REQ_3_3_1_3 — Do Not Store PIN or PIN Block After AuthorizationCode Improvement Recommended
Missing: Access Control, Data Classification, Data Lifecycle Management, Encryption At Rest, Encryption In Transit, Key Management
CriticalPCI_REQ_3_3_2 — Encrypt Electronically Stored SAD Prior to AuthorizationCode Improvement Recommended
Missing: Access Control, Data Classification, Encryption At Rest, Encryption In Transit, Key Management
CriticalPCI_REQ_3_5_1 — Render PAN Unreadable Using Approved MethodsCode Improvement Recommended
Missing: Access Control, Data Classification, Encryption At Rest, Encryption In Transit, Key Management
Control Mapping Appendix
Raw control-level mapping (control IDs, clause text) is intentionally not inlined here — export to JSON or SARIF for the complete, machine-readable control mapping.