Meridian provides automated compliance assessments and recommendations, not legal advice. Final compliance determinations should be reviewed by qualified legal, compliance, or security professionals where required.
Executive Summary
Applicable Controls
401
Controls determined to apply to this repository
Implemented
6
Requires Documentation
132
Requires Operational Evidence
12
Code Improvement Recommended
251
Repository Overview
In ProductionTrue
Technology Stack
1051 files · 197808 lines
Languagesjavascript, python, tsx, typescript
FrameworksFastAPI, Next.js, React, Starlette
Data & InfrastructureRedis, SQL (via SQLAlchemy)
CI/CD & IaCDocker, Docker Compose, GitHub Actions
Business Signals
Stores personal dataTrue
Uses AITrue
Primary jurisdictionUnited States
Processes paymentsTrue
Regulated financial entityFalse
What Meridian Understood
This repository primarily focuses on AI capabilities using both language models and vector databases, integrated into a web application or service. The backend is primarily implemented using FastAPI and Starlette, with a front-end utilizing React and Next.js technologies. The application uses Docker for containerization and GitHub Actions for continuous integration and deployment.
Architecture: AI-driven web application
Compliance Scope
Applicable Regulations
EU AI ActAI Governance & Responsible AI
Your repository deploys AI models or AI-powered systems.
Required: matched on ai_usage.
PCI DSSPayments & Financial Security
Your application processes payments or handles cardholder data.
Required: matched on processes_payments.
SOC 2 Trust Services CriteriaTrust & Assurance
Your application is in production and handles customer data requiring independent assurance.
Optional: base condition met, but no additional signal beyond production.
Not Applicable Regulations
DPDPA 2023Privacy & Data Protection
Excluded: 'primary_jurisdiction' does not match the condition required for this framework.
DPDPA Rules, 2025Privacy & Data Protection
Excluded: 'primary_jurisdiction' does not match the condition required for this framework.
GDPRPrivacy & Data Protection
Excluded: 'primary_jurisdiction' does not match the condition required for this framework.
RBI FREE-AI FrameworkAI Governance & Responsible AI
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
SEBI AI/ML GuidelinesAI Governance & Responsible AI
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
RBI Digital Payment Security ControlsPayments & Financial Security
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
RBI IT Governance & Risk ControlsCybersecurity & Operational Security
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
RBI NBFC IT FrameworkFinancial Sector Regulations
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
Access Control (CRITICAL) — Can the organization (as a third-country provider) demonstrate that it has appointed an authorised representative in the Union and that the representative fulfils all required tasks?
Improves compliance posture for: EU AI Act, PCI DSS, SOC 2 Trust Services Criteria.
Authentication (CRITICAL) — Can the multi-tenant service provider demonstrate logical separation between provider and customer environments with authorization controls?
Encryption In Transit (CRITICAL) — Can the designated entity demonstrate that response procedures are in place for cleartext PAN found outside the CDE?
Can the organization (as a third-country provider) demonstrate that it has appointed an authorised representative in the Union and that the representative fulfils all required tasks?
Improves compliance posture for: EU AI Act, PCI DSS, SOC 2 Trust Services Criteria.
Authentication (CRITICAL)
Can the multi-tenant service provider demonstrate logical separation between provider and customer environments with authorization controls?
Can the organization demonstrate that it has implemented appropriate data governance and management practices for training, validation, and testing data sets of high-risk AI systems?
Improves compliance posture for: EU AI Act.
Consent Management (HIGH)
Can the organization demonstrate that it has implemented appropriate safeguards when processing special categories of personal data for bias detection and correction?
Improves compliance posture for: EU AI Act, SOC 2 Trust Services Criteria.
Audit Logging (HIGH)
Can the organization demonstrate that high-risk AI systems have logging capabilities for automatic event recording throughout their lifetime?
Improves compliance posture for: EU AI Act, PCI DSS, SOC 2 Trust Services Criteria.
Privileged Access Management (HIGH)
Can the organization demonstrate that high-risk AI systems are designed for effective human oversight throughout their use?
Improves compliance posture for: EU AI Act, SOC 2 Trust Services Criteria.
Backup And Recovery (HIGH)
Can the organization demonstrate that high-risk AI systems are resilient to errors and have measures to address feedback loops?
Improves compliance posture for: EU AI Act, SOC 2 Trust Services Criteria.
Data Retention (HIGH)
Can the organization demonstrate that it retains automatically generated logs for at least six months (or as otherwise required) for high-risk AI systems?
Improves compliance posture for: EU AI Act, PCI DSS, SOC 2 Trust Services Criteria.
Incident Response Plan (HIGH)
Can the organization demonstrate that it authorizes, designs, implements, maintains, and monitors environmental protections, backup processes, and recovery infrastructure?
Can the organization demonstrate that it has drawn up and maintains up-to-date technical documentation for high-risk AI systems as required by Annex IV?
Improves compliance posture for: EU AI Act, PCI DSS, SOC 2 Trust Services Criteria.
Maker Checker (MEDIUM)
Can the organization demonstrate that high-risk AI systems are designed for effective human oversight throughout their use?
Improves compliance posture for: EU AI Act, SOC 2 Trust Services Criteria.
Model Testing (MEDIUM)
Can the organization demonstrate that high-risk AI systems achieve appropriate levels of accuracy, robustness, and cybersecurity throughout their lifecycle?
Improves compliance posture for: EU AI Act.
Business Impact Analysis (MEDIUM)
Can the organization demonstrate that high-risk AI systems are resilient to errors and have measures to address feedback loops?
Improves compliance posture for: EU AI Act, PCI DSS, SOC 2 Trust Services Criteria.
Data Lifecycle Management (MEDIUM)
Can the organization demonstrate that it retains all required documentation for 10 years after placing a high-risk AI system on the market?
Improves compliance posture for: EU AI Act, PCI DSS, SOC 2 Trust Services Criteria.
Grievance Redressal (MEDIUM)
Can the organization demonstrate that it has procedures to handle complaints regarding infringement of the AI Act?
Improves compliance posture for: EU AI Act.
Data Masking (MEDIUM)
Can the entity demonstrate that POS POI terminals using SSL/early TLS are not susceptible to known exploits?
Can the organization demonstrate that it has implemented appropriate data governance and management practices for training, validation, and testing data sets of high-risk AI systems?
Improves compliance posture for: EU AI Act, PCI DSS, SOC 2 Trust Services Criteria.
Security Awareness Training (LOW)
Can the organization demonstrate that high-risk AI systems are designed for effective human oversight throughout their use?
Improves compliance posture for: EU AI Act, SOC 2 Trust Services Criteria.
Data Quality Management (INFORMATIONAL)
Can the organization demonstrate that high-risk AI systems achieve appropriate levels of accuracy, robustness, and cybersecurity throughout their lifecycle?
Improves compliance posture for: EU AI Act.
Strategic Initiatives
AI Risk Assessment (HIGH)
Can the organization demonstrate that high-risk AI systems are designed for effective human oversight throughout their use?
Improves compliance posture for: EU AI Act, SOC 2 Trust Services Criteria.
Bias Detection (HIGH)
Can the organization demonstrate that high-risk AI systems achieve appropriate levels of accuracy, robustness, and cybersecurity throughout their lifecycle?
Improves compliance posture for: EU AI Act.
Data Loss Prevention (HIGH)
Can the organization demonstrate that high-risk AI systems achieve appropriate levels of accuracy, robustness, and cybersecurity throughout their lifecycle?
Improves compliance posture for: EU AI Act.
Privacy Impact Assessment (HIGH)
Can the organization demonstrate that it has established, implemented, documented, and maintained a risk management system for high-risk AI systems throughout their lifecycle?
Improves compliance posture for: EU AI Act, PCI DSS, SOC 2 Trust Services Criteria.
Data Protection Impact Assessment (HIGH)
Can the organization demonstrate that it has established, implemented, documented, and maintained a risk management system for high-risk AI systems throughout their lifecycle?
Improves compliance posture for: EU AI Act, PCI DSS, SOC 2 Trust Services Criteria.
Physical Access Control (MEDIUM)
Can the organization demonstrate that high-risk AI systems achieve appropriate levels of accuracy, robustness, and cybersecurity throughout their lifecycle?
Improves compliance posture for: EU AI Act.
Model Monitoring (MEDIUM)
Can the organization demonstrate that high-risk AI systems achieve appropriate levels of accuracy, robustness, and cybersecurity throughout their lifecycle?
Improves compliance posture for: EU AI Act.
Compliance Roadmap
Now · Quick Wins
Access Control
Authentication
Encryption In Transit
Encryption At Rest
Next · Medium Effort
Key Management
Data Subject Request Handling
Consent Management
Audit Logging
Privileged Access Management
Backup And Recovery
Data Retention
Incident Response Plan
Records Of Processing
Maker Checker
Model Testing
Business Impact Analysis
Data Lifecycle Management
Grievance Redressal
Data Masking
Data Classification
Policy Management
Security Awareness Training
Data Quality Management
Later · Strategic Initiatives
AI Risk Assessment
Bias Detection
Data Loss Prevention
Privacy Impact Assessment
Data Protection Impact Assessment
Physical Access Control
Model Monitoring
Next Steps
Start with Top Priorities above, then work through the full Quick Wins/Medium Effort/Strategic Initiatives breakdown.
Technical Findings below show exactly where each gap was detected in your repository; export to PDF/HTML for a
shareable version, or JSON/SARIF to feed a CI pipeline.
Technical Findings (235)
Showing top 50 of 235, ranked by severity then confidence.
Export to JSON or SARIF for the complete list.
CriticalPCI_REQ_3_6_1 — Define and Implement Procedures to Protect Cryptographic KeysCode Improvement Recommended
Satisfied: Data Classification
Missing: Access Control, Encryption At Rest, Encryption In Transit, Key Management
CriticalPCI_REQ_10_2_1_2 — Audit Logs Capture All Actions by Individuals with Administrative AccessCode Improvement Recommended
Satisfied: Authentication
Missing: Access Control, Audit Logging
server/routers/auth.py:132-132 (authentication)
server/routers/auth.py:146-164 (authentication)
server/routers/auth.py:127-141 (authentication)
server/auth.py:117-117 (authentication)
server/routers/auth.py:206-206 (authentication)
server/routers/auth.py:198-213 (authentication)
server/auth.py:99-99 (authentication)
server/routers/auth.py:147-147 (authentication)
CriticalPCI_REQ_10_2_1_3 — Audit Logs Capture All Access to Audit LogsCode Improvement Recommended
Satisfied: Authentication
Missing: Access Control, Audit Logging
server/routers/auth.py:132-132 (authentication)
server/routers/auth.py:146-164 (authentication)
server/routers/auth.py:127-141 (authentication)
server/auth.py:117-117 (authentication)
server/routers/auth.py:206-206 (authentication)
server/routers/auth.py:198-213 (authentication)
server/auth.py:99-99 (authentication)
server/routers/auth.py:147-147 (authentication)
CriticalPCI_REQ_10_2_1_5 — Audit Logs Capture All Changes to Identification and Authentication CredentialsCode Improvement Recommended
Satisfied: Authentication
Missing: Access Control, Audit Logging
server/routers/auth.py:132-132 (authentication)
server/routers/auth.py:146-164 (authentication)
server/routers/auth.py:127-141 (authentication)
server/auth.py:117-117 (authentication)
server/routers/auth.py:206-206 (authentication)
server/routers/auth.py:198-213 (authentication)
server/auth.py:99-99 (authentication)
server/routers/auth.py:147-147 (authentication)
CriticalPCI_REQ_6_2_4 — Use Software Engineering Techniques to Prevent Common Software AttacksCode Improvement Recommended
Satisfied: Authentication
Missing: Access Control
server/routers/auth.py:132-132 (authentication)
server/routers/auth.py:146-164 (authentication)
server/routers/auth.py:127-141 (authentication)
server/auth.py:117-117 (authentication)
server/routers/auth.py:206-206 (authentication)
server/routers/auth.py:198-213 (authentication)
server/auth.py:99-99 (authentication)
server/routers/auth.py:147-147 (authentication)
CriticalPCI_REQ_8_2_1 — Assign Unique ID to All UsersCode Improvement Recommended
Satisfied: Authentication
Missing: Access Control
server/routers/auth.py:132-132 (authentication)
server/routers/auth.py:146-164 (authentication)
server/routers/auth.py:127-141 (authentication)
server/auth.py:117-117 (authentication)
server/routers/auth.py:206-206 (authentication)
server/routers/auth.py:198-213 (authentication)
server/auth.py:99-99 (authentication)
server/routers/auth.py:147-147 (authentication)
CriticalPCI_REQ_8_2_5 — Immediately Revoke Access for Terminated UsersCode Improvement Recommended
Satisfied: Authentication
Missing: Access Control
server/routers/auth.py:132-132 (authentication)
server/routers/auth.py:146-164 (authentication)
server/routers/auth.py:127-141 (authentication)
server/auth.py:117-117 (authentication)
server/routers/auth.py:206-206 (authentication)
server/routers/auth.py:198-213 (authentication)
server/auth.py:99-99 (authentication)
server/routers/auth.py:147-147 (authentication)
CriticalPCI_REQ_8_3_1 — Authenticate User Access with at Least One Authentication FactorCode Improvement Recommended
Satisfied: Authentication
Missing: Access Control
server/routers/auth.py:132-132 (authentication)
server/routers/auth.py:146-164 (authentication)
server/routers/auth.py:127-141 (authentication)
server/auth.py:117-117 (authentication)
server/routers/auth.py:206-206 (authentication)
server/routers/auth.py:198-213 (authentication)
server/auth.py:99-99 (authentication)
server/routers/auth.py:147-147 (authentication)
CriticalPCI_REQ_8_4_1 — Implement MFA for Non-Console Administrative Access into CDECode Improvement Recommended
Satisfied: Authentication
Missing: Access Control
server/routers/auth.py:132-132 (authentication)
server/routers/auth.py:146-164 (authentication)
server/routers/auth.py:127-141 (authentication)
server/auth.py:117-117 (authentication)
server/routers/auth.py:206-206 (authentication)
server/routers/auth.py:198-213 (authentication)
server/auth.py:99-99 (authentication)
server/routers/auth.py:147-147 (authentication)
CriticalPCI_REQ_8_4_2 — Implement MFA for All Non-Console Access into CDECode Improvement Recommended
Satisfied: Authentication
Missing: Access Control
server/routers/auth.py:132-132 (authentication)
server/routers/auth.py:146-164 (authentication)
server/routers/auth.py:127-141 (authentication)
server/auth.py:117-117 (authentication)
server/routers/auth.py:206-206 (authentication)
server/routers/auth.py:198-213 (authentication)
server/auth.py:99-99 (authentication)
server/routers/auth.py:147-147 (authentication)
CriticalPCI_REQ_8_4_3 — Implement MFA for Remote Access from Outside the NetworkCode Improvement Recommended
Satisfied: Authentication
Missing: Access Control
server/routers/auth.py:132-132 (authentication)
server/routers/auth.py:146-164 (authentication)
server/routers/auth.py:127-141 (authentication)
server/auth.py:117-117 (authentication)
server/routers/auth.py:206-206 (authentication)
server/routers/auth.py:198-213 (authentication)
server/auth.py:99-99 (authentication)
server/routers/auth.py:147-147 (authentication)
CriticalPCI_REQ_8_5_1 — Configure MFA Systems to Prevent Misuse (Resistant to Replay, Not Bypassable, Two Factors Required)Code Improvement Recommended
Satisfied: Authentication
Missing: Access Control
server/routers/auth.py:132-132 (authentication)
server/routers/auth.py:146-164 (authentication)
server/routers/auth.py:127-141 (authentication)
server/auth.py:117-117 (authentication)
server/routers/auth.py:206-206 (authentication)
server/routers/auth.py:198-213 (authentication)
server/auth.py:99-99 (authentication)
server/routers/auth.py:147-147 (authentication)
CriticalSOC2_CC6_2 — User Registration and AuthorizationCode Improvement Recommended
Satisfied: Authentication
Missing: Access Control
server/routers/auth.py:132-132 (authentication)
server/routers/auth.py:146-164 (authentication)
server/routers/auth.py:127-141 (authentication)
server/auth.py:117-117 (authentication)
server/routers/auth.py:206-206 (authentication)
server/routers/auth.py:198-213 (authentication)
server/auth.py:99-99 (authentication)
server/routers/auth.py:147-147 (authentication)
CriticalSOC2_CC6_3 — Access Authorization, Modification, and RemovalCode Improvement Recommended
Satisfied: Authentication
Missing: Access Control
server/routers/auth.py:132-132 (authentication)
server/routers/auth.py:146-164 (authentication)
server/routers/auth.py:127-141 (authentication)
server/auth.py:117-117 (authentication)
server/routers/auth.py:206-206 (authentication)
server/routers/auth.py:198-213 (authentication)
server/auth.py:99-99 (authentication)
server/routers/auth.py:147-147 (authentication)
CriticalPCI_REQ_3_2_1 — Implement Data Retention and Disposal Policies to Minimize Account Data StorageCode Improvement Recommended
Satisfied: Data Classification, Data Lifecycle Management
Missing: Access Control, Data Retention, Encryption At Rest, Encryption In Transit, Key Management
CriticalEU_AI_ART_20_001 — Corrective Actions and Duty of InformationCode Improvement Recommended
Missing: Audit Logging
CriticalEU_AI_ART_27_001 — Fundamental Rights Impact AssessmentCode Improvement Recommended
Missing: Consent Management
CriticalEU_AI_ART_5_001 — Prohibition of Subliminal Manipulative TechniquesCode Improvement Recommended
Missing: Consent Management
CriticalEU_AI_ART_5_002 — Prohibition of Exploiting VulnerabilitiesCode Improvement Recommended
Missing: Consent Management
CriticalEU_AI_ART_5_003 — Prohibition of Social ScoringCode Improvement Recommended
Missing: Consent Management
CriticalEU_AI_ART_5_004 — Prohibition of Predictive Policing Risk Assessments Based Solely on ProfilingCode Improvement Recommended
Missing: Consent Management
CriticalEU_AI_ART_5_006 — Prohibition of Emotion Recognition in Workplace and EducationCode Improvement Recommended
Missing: Consent Management
CriticalEU_AI_ART_5_007 — Prohibition of Biometric Categorisation for Sensitive CharacteristicsCode Improvement Recommended
Missing: Consent Management
CriticalEU_AI_ART_5_008 — Restrictions on Real-Time Remote Biometric Identification for Law EnforcementCode Improvement Recommended
Missing: Consent Management
CriticalEU_AI_ART_73_001 — Reporting of Serious IncidentsCode Improvement Recommended
Missing: Audit Logging
CriticalPCI_REQ_10_2_1 — Enable and Activate Audit Logs for All System ComponentsCode Improvement Recommended
Missing: Audit Logging
CriticalPCI_REQ_10_2_1_1 — Audit Logs Capture All Individual User Access to Cardholder DataCode Improvement Recommended
Missing: Audit Logging
CriticalPCI_REQ_10_2_1_6 — Audit Logs Capture Initialization, Starting, Stopping, or Pausing of Audit LogsCode Improvement Recommended
Missing: Audit Logging
Control Mapping Appendix
Raw control-level mapping (control IDs, clause text) is intentionally not inlined here — export to JSON or SARIF for the complete, machine-readable control mapping.