Meridian provides automated compliance assessments and recommendations, not legal advice. Final compliance determinations should be reviewed by qualified legal, compliance, or security professionals where required.
Executive Summary
Applicable Controls
173
Controls determined to apply to this repository
Requires Documentation
80
Requires Operational Evidence
5
Code Improvement Recommended
66
Repository Overview
Technology Stack
3068 files · 656203 lines
Languages go, javascript, terraform, tsx, typescript
Frameworks React
CI/CD & IaC Docker, Docker Compose, GitHub Actions, Kubernetes
Business Signals
Stores personal data True
Uses AI False
Primary jurisdiction United States
Processes payments False
Regulated financial entity False
Offers goods/services to the EU True
Monitors individuals in the EU False
Offers goods/services to India False
What Meridian Understood
This repository consists of a web application developed using Go and TypeScript, incorporating the React framework for its frontend. It is configured to run in Docker containers and is orchestrated using Kubernetes, managed through GitHub Actions for CI/CD pipelines.
Architecture: Web application
Compliance Scope
Applicable Regulations
GDPR Privacy & Data Protection Statutory law
Your application stores or processes personal data of individuals in the European Union.
Required: matched on stores_personal_data, offers_goods_services_to_eu.
In force since May 2018; applies extraterritorially to organizations offering goods or services to, or monitoring, individuals in the EU.
SOC 2 Trust Services Criteria Trust & Assurance Voluntary attestation
Your application is in production and handles customer data requiring independent assurance.
Optional: base condition met, but no additional signal beyond production.
A voluntary attestation framework (AICPA Trust Services Criteria) driven by customer and contractual demand, not law.
Not Applicable Regulations
DPDPA 2023 Privacy & Data Protection
Excluded: none of 'primary_jurisdiction', 'offers_goods_services_to_india' match the conditions required for this framework.
DPDPA Rules, 2025 Privacy & Data Protection
Excluded: none of 'primary_jurisdiction', 'offers_goods_services_to_india' match the conditions required for this framework.
EU AI Act AI Governance & Responsible AI
Excluded: 'ai_usage' does not match the condition required for this framework.
RBI FREE-AI Framework AI Governance & Responsible AI
Excluded: 'ai_usage' does not match the condition required for this framework.
SEBI AI/ML Guidelines AI Governance & Responsible AI
Excluded: 'ai_usage' does not match the condition required for this framework.
RBI Digital Payment Security Controls Payments & Financial Security
Excluded: 'processes_payments' does not match the condition required for this framework.
PCI DSS Payments & Financial Security
Excluded: 'processes_payments' does not match the condition required for this framework.
RBI IT Governance & Risk Controls Cybersecurity & Operational Security
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
RBI NBFC IT Framework Financial Sector Regulations
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
RBI NBFC Outsourcing Directions Financial Sector Regulations
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
RBI Outsourcing Directions Financial Sector Regulations
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
RBI Payments Banks Outsourcing Directions Financial Sector Regulations
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
RBI Small Finance Banks Outsourcing Directions Financial Sector Regulations
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
SEBI Cybersecurity Framework Cybersecurity & Operational Security
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
CERT-In Directions Cybersecurity & Operational Security
Excluded: 'primary_jurisdiction' does not match the condition required for this framework.
NIST AI RMF AI Governance & Responsible AI
Excluded: 'ai_usage' does not match the condition required for this framework.
Needs More Information
Not enough was known to confirm or rule these out — Meridian conservatively evaluates their controls below until you provide the missing details.
HIPAA Security Rule Privacy & Data Protection
Not enough information yet: handles_health_data not answered.
Compliance Readiness
Implemented
Authentication
Cross Border Transfer Controls
Data Classification
Data Lifecycle Management
Code Improvement Recommended
Access Control
Audit Logging
Consent Management
Data Retention
Encryption At Rest
Encryption In Transit
Key Management
Requires Documentation
Asset Inventory
Backup And Recovery
Business Impact Analysis
Configuration Management
Data Deletion
Data Masking
Data Protection Impact Assessment
Data Subject Request Handling
Grievance Redressal
Incident Response Plan
Information Security Policy
Log Retention
Policy Management
Privacy Impact Assessment
Records Of Processing
Requires Operational Evidence
AI Risk Assessment
Access Review
BCP And DR Testing
Bias Detection
Change Management
Data Loss Prevention
Data Quality Management
Governance Framework
Incident Detection
Maker Checker
Model Monitoring
Model Testing
Patch Management
Penetration Testing
Physical Access Control
Privileged Access Management
Regulatory Change Monitoring
Regulatory Reporting
SOC Operations
Security Awareness Training
Third Party Risk Assessment
Vendor Contract Management
Vulnerability Scanning
Enterprise Readiness
Detected
Authentication
Recommended Improvements
Access Control
Audit Logging
Encryption At Rest
Encryption In Transit
Key Management
Data Retention
Operational Requirements
Privileged Access Management
BCP And DR Testing
Penetration Testing
Third Party Risk Assessment
Vendor Contract Management
Security Awareness Training
Documentation Required
Incident Response Plan
Information Security Policy
SOC 2 Scope
The subset of the capabilities above that SOC 2's own controls actually reach.
Detected
Authentication
Recommended Improvements
Access Control
Audit Logging
Encryption At Rest
Encryption In Transit
Key Management
Data Retention
Operational Requirements
Privileged Access Management
BCP And DR Testing
Penetration Testing
Third Party Risk Assessment
Vendor Contract Management
Security Awareness Training
Documentation Required
Incident Response Plan
Top Priorities
Access Control (CRITICAL) — Can the organization (as a non-EU controller/processor) demonstrate that it has designated a representative in the Union?
Improves compliance posture for: GDPR, HIPAA Security Rule, SOC 2 Trust Services Criteria.
Encryption At Rest (CRITICAL) — Can the organization demonstrate that it discontinues logical and physical protections over physical assets only after data and software are no longer recoverable?
Improves compliance posture for: SOC 2 Trust Services Criteria.
Encryption In Transit (CRITICAL) — Can the organization demonstrate that it discontinues logical and physical protections over physical assets only after data and software are no longer recoverable?
Improves compliance posture for: SOC 2 Trust Services Criteria.
Key Management (CRITICAL) — Can the organization demonstrate that it discontinues logical and physical protections over physical assets only after data and software are no longer recoverable?
Improves compliance posture for: SOC 2 Trust Services Criteria.
Consent Management (HIGH) — Can the organization demonstrate that it provides information free of charge and has procedures for manifestly unfounded or excessive requests?
Improves compliance posture for: GDPR, SOC 2 Trust Services Criteria.
Full breakdown by effort below.
Recommended Actions
Quick Wins
Access Control (CRITICAL)Can the organization (as a non-EU controller/processor) demonstrate that it has designated a representative in the Union?
Improves compliance posture for: GDPR, HIPAA Security Rule, SOC 2 Trust Services Criteria.
Encryption At Rest (CRITICAL)Can the organization demonstrate that it discontinues logical and physical protections over physical assets only after data and software are no longer recoverable?
Improves compliance posture for: SOC 2 Trust Services Criteria.
Encryption In Transit (CRITICAL)Can the organization demonstrate that it discontinues logical and physical protections over physical assets only after data and software are no longer recoverable?
Improves compliance posture for: SOC 2 Trust Services Criteria.
Log Retention (MEDIUM)Does the organization monitor log-in attempts to systems containing electronic protected health information and report discrepancies?
Improves compliance posture for: HIPAA Security Rule.
Medium Effort
Key Management (CRITICAL)Can the organization demonstrate that it discontinues logical and physical protections over physical assets only after data and software are no longer recoverable?
Improves compliance posture for: SOC 2 Trust Services Criteria.
Consent Management (HIGH)Can the organization demonstrate that it provides information free of charge and has procedures for manifestly unfounded or excessive requests?
Improves compliance posture for: GDPR, SOC 2 Trust Services Criteria.
Privileged Access Management (HIGH)Can the organization demonstrate that it does not make decisions based solely on automated processing that produce legal or significant effects, without appropriate safeguards?
Improves compliance posture for: GDPR, SOC 2 Trust Services Criteria.
Audit Logging (HIGH)Can the organization demonstrate that it has properly applied exceptions to breach communication to data subjects?
Improves compliance posture for: GDPR, HIPAA Security Rule, SOC 2 Trust Services Criteria.
Incident Response Plan (HIGH)Has the organization conducted and documented a risk analysis assessing threats and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information?
Improves compliance posture for: HIPAA Security Rule, SOC 2 Trust Services Criteria.
Backup And Recovery (HIGH)Does the organization maintain retrievable, exact backup copies of electronic protected health information?
Improves compliance posture for: HIPAA Security Rule, SOC 2 Trust Services Criteria.
Data Retention (HIGH)Can the organization demonstrate that it implements policies and procedures to store inputs, items in processing, and outputs completely, accurately, and timely in accordance with system specifications?
Improves compliance posture for: SOC 2 Trust Services Criteria.
Records Of Processing (MEDIUM)Can the organization demonstrate that processing of criminal conviction data is under official control or authorised by law with appropriate safeguards?
Improves compliance posture for: GDPR, HIPAA Security Rule, SOC 2 Trust Services Criteria.
Data Masking (MEDIUM)Can the organization demonstrate that processing of criminal conviction data is under official control or authorised by law with appropriate safeguards?
Improves compliance posture for: GDPR, SOC 2 Trust Services Criteria.
Model Testing (MEDIUM)Can the organization demonstrate that it does not make decisions based solely on automated processing that produce legal or significant effects, without appropriate safeguards?
Improves compliance posture for: GDPR.
Maker Checker (MEDIUM)Can the organization demonstrate that it does not make decisions based solely on automated processing that produce legal or significant effects, without appropriate safeguards?
Improves compliance posture for: GDPR, SOC 2 Trust Services Criteria.
Business Impact Analysis (MEDIUM)Can the organization demonstrate that it has assessed the risks to personal data when determining security measures?
Improves compliance posture for: GDPR, HIPAA Security Rule, SOC 2 Trust Services Criteria.
Asset Inventory (MEDIUM)Has the organization conducted and documented a risk analysis assessing threats and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information?
Improves compliance posture for: HIPAA Security Rule.
Configuration Management (MEDIUM)Has the organization conducted and documented a risk analysis assessing threats and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information?
Improves compliance posture for: HIPAA Security Rule.
Data Lifecycle Management (MEDIUM)Does the organization have documented policies for the final disposition of electronic protected health information and the media it is stored on?
Improves compliance posture for: HIPAA Security Rule, SOC 2 Trust Services Criteria.
Information Security Policy (MEDIUM)Has the organization implemented documented policies and procedures reasonably designed to comply with the HIPAA Security Rule's standards and implementation specifications?
Improves compliance posture for: HIPAA Security Rule.
Data Classification (MEDIUM)Can the organization demonstrate that it discontinues logical and physical protections over physical assets only after data and software are no longer recoverable?
Improves compliance posture for: SOC 2 Trust Services Criteria.
Policy Management (LOW)Can the organization demonstrate that processing of criminal conviction data is under official control or authorised by law with appropriate safeguards?
Improves compliance posture for: GDPR, HIPAA Security Rule, SOC 2 Trust Services Criteria.
Security Awareness Training (LOW)Can the organization demonstrate that it does not make decisions based solely on automated processing that produce legal or significant effects, without appropriate safeguards?
Improves compliance posture for: GDPR, SOC 2 Trust Services Criteria.
Data Quality Management (INFORMATIONAL)Can the organization demonstrate that it does not make decisions based solely on automated processing that produce legal or significant effects, without appropriate safeguards?
Improves compliance posture for: GDPR.
Strategic Initiatives
AI Risk Assessment (HIGH)Can the organization demonstrate that it does not make decisions based solely on automated processing that produce legal or significant effects, without appropriate safeguards?
Improves compliance posture for: GDPR, SOC 2 Trust Services Criteria.
Bias Detection (HIGH)Can the organization demonstrate that it does not make decisions based solely on automated processing that produce legal or significant effects, without appropriate safeguards?
Improves compliance posture for: GDPR.
Data Loss Prevention (HIGH)Can the organization demonstrate that automated decision-making based on special category data is only done with explicit consent or substantial public interest and appropriate safeguards?
Improves compliance posture for: GDPR.
Data Protection Impact Assessment (HIGH)Can the organization demonstrate that it has assessed the risks to personal data when determining security measures?
Improves compliance posture for: GDPR, SOC 2 Trust Services Criteria.
Privacy Impact Assessment (HIGH)Can the organization demonstrate that it has assessed the risks to personal data when determining security measures?
Improves compliance posture for: GDPR, SOC 2 Trust Services Criteria.
Model Monitoring (MEDIUM)Can the organization demonstrate that it does not make decisions based solely on automated processing that produce legal or significant effects, without appropriate safeguards?
Improves compliance posture for: GDPR.
Physical Access Control (MEDIUM)Can the organization demonstrate that automated decision-making based on special category data is only done with explicit consent or substantial public interest and appropriate safeguards?
Improves compliance posture for: GDPR.
Compliance Roadmap
Now · Quick Wins
Access Control Encryption At Rest Encryption In Transit Log Retention
Next · Medium Effort
Key Management Consent Management Privileged Access Management Audit Logging Incident Response Plan Backup And Recovery Data Retention Records Of Processing Data Masking Model Testing Maker Checker Business Impact Analysis Asset Inventory Configuration Management Data Lifecycle Management Information Security Policy Data Classification Policy Management Security Awareness Training Data Quality Management
Later · Strategic Initiatives
AI Risk Assessment Bias Detection Data Loss Prevention Data Protection Impact Assessment Privacy Impact Assessment Model Monitoring Physical Access Control
Next Steps
Start with Top Priorities above, then work through the full Quick Wins/Medium Effort/Strategic Initiatives breakdown.
Technical Findings below show exactly where each gap was detected in your repository; export to PDF/HTML for a
shareable version, or JSON/SARIF to feed a CI pipeline.
Technical Findings (59)
Showing top 50 of 59, ranked by severity then confidence.
Export to JSON or SARIF for the complete list.
Critical
SOC2_CC6_6 — External Threat Protection
Code Improvement Recommended
Satisfied: Data Classification
Missing: Access Control, Audit Logging, Encryption At Rest, Encryption In Transit, Key Management
internal/builtin/database/mysql/connection_producer.go:36-36 (data_classification)
internal/builtin/logical/openldap/path_dynamic_creds.go:276-276 (data_classification)
sdk/database/dbplugin/v5/database.go:120-120 (data_classification)
sdk/database/dbplugin/v5/proto/database.pb.go:330-330 (data_classification)
api/auth/ldap/ldap.go:20-20 (data_classification)
api/auth/userpass/userpass.go:20-20 (data_classification)
internal/builtin/logical/pki/cert_template.pb.go:297-297 (data_classification)
sdk/plugin/pb/backend.pb.go:3349-3349 (data_classification)
sdk/database/dbplugin/database.pb.go:699-699 (data_classification)
internal/builtin/logical/openldap/path_static_roles.go:401-401 (data_classification)
sdk/database/dbplugin/database.pb.go:524-524 (data_classification)
internal/builtin/database/influxdb/connection_producer.go:28-28 (data_classification)
internal/builtin/database/valkey/connection_producer.go:25-25 (data_classification)
internal/builtin/database/cassandra/connection_producer.go:30-30 (data_classification)
sdk/database/dbplugin/v5/database.go:186-186 (data_classification)
sdk/database/helper/connutil/sql.go:31-31 (data_classification)
sdk/database/dbplugin/database.pb.go:856-856 (data_classification)
internal/builtin/logical/database/path_roles.go:793-793 (data_classification)
sdk/database/dbplugin/v5/proto/database.pb.go:131-131 (data_classification)
Critical
SOC2_CC6_8 — Unauthorized and Malicious Software Control
Code Improvement Recommended
Satisfied: Data Classification
Missing: Access Control, Audit Logging, Encryption At Rest, Encryption In Transit, Key Management
internal/builtin/database/mysql/connection_producer.go:36-36 (data_classification)
internal/builtin/logical/openldap/path_dynamic_creds.go:276-276 (data_classification)
sdk/database/dbplugin/v5/database.go:120-120 (data_classification)
sdk/database/dbplugin/v5/proto/database.pb.go:330-330 (data_classification)
api/auth/ldap/ldap.go:20-20 (data_classification)
api/auth/userpass/userpass.go:20-20 (data_classification)
internal/builtin/logical/pki/cert_template.pb.go:297-297 (data_classification)
sdk/plugin/pb/backend.pb.go:3349-3349 (data_classification)
sdk/database/dbplugin/database.pb.go:699-699 (data_classification)
internal/builtin/logical/openldap/path_static_roles.go:401-401 (data_classification)
sdk/database/dbplugin/database.pb.go:524-524 (data_classification)
internal/builtin/database/influxdb/connection_producer.go:28-28 (data_classification)
internal/builtin/database/valkey/connection_producer.go:25-25 (data_classification)
internal/builtin/database/cassandra/connection_producer.go:30-30 (data_classification)
sdk/database/dbplugin/v5/database.go:186-186 (data_classification)
sdk/database/helper/connutil/sql.go:31-31 (data_classification)
sdk/database/dbplugin/database.pb.go:856-856 (data_classification)
internal/builtin/logical/database/path_roles.go:793-793 (data_classification)
sdk/database/dbplugin/v5/proto/database.pb.go:131-131 (data_classification)
Critical
GDPR_ART_28_001 — Processor - Selection and Guarantees
Code Improvement Recommended
Missing: Access Control
Critical
GDPR_ART_58_002 — Supervisory Authority - Corrective Powers
Code Improvement Recommended
Missing: Audit Logging
Critical
GDPR_ART_5_001 — Lawfulness, Fairness and Transparency
Code Improvement Recommended
Missing: Consent Management
Critical
GDPR_ART_6_001 — Lawful Processing - Consent
Code Improvement Recommended
Missing: Consent Management
Critical
GDPR_ART_7_001 — Demonstration of Consent
Code Improvement Recommended
Missing: Consent Management
Critical
GDPR_ART_83_001 — Administrative Fines - General Conditions
Code Improvement Recommended
Missing: Audit Logging
Critical
HIPAA_308_A6_001 — Security Incident Procedures -- Response and Reporting
Code Improvement Recommended
Missing: Audit Logging
Critical
SOC2_CC7_3 — Security Event Evaluation
Code Improvement Recommended
Missing: Audit Logging
Critical
SOC2_CC7_4 — Incident Response Program Execution
Code Improvement Recommended
Missing: Audit Logging
Critical
SOC2_P6_6 — Notification of Breaches and Incidents
Code Improvement Recommended
Missing: Audit Logging, Consent Management
High
SOC2_P3_1 — Collection of Personal Information
Code Improvement Recommended
Satisfied: Data Classification
Missing: Access Control, Consent Management, Encryption At Rest, Encryption In Transit, Key Management
internal/builtin/database/mysql/connection_producer.go:36-36 (data_classification)
internal/builtin/logical/openldap/path_dynamic_creds.go:276-276 (data_classification)
sdk/database/dbplugin/v5/database.go:120-120 (data_classification)
sdk/database/dbplugin/v5/proto/database.pb.go:330-330 (data_classification)
api/auth/ldap/ldap.go:20-20 (data_classification)
api/auth/userpass/userpass.go:20-20 (data_classification)
internal/builtin/logical/pki/cert_template.pb.go:297-297 (data_classification)
sdk/plugin/pb/backend.pb.go:3349-3349 (data_classification)
sdk/database/dbplugin/database.pb.go:699-699 (data_classification)
internal/builtin/logical/openldap/path_static_roles.go:401-401 (data_classification)
sdk/database/dbplugin/database.pb.go:524-524 (data_classification)
internal/builtin/database/influxdb/connection_producer.go:28-28 (data_classification)
internal/builtin/database/valkey/connection_producer.go:25-25 (data_classification)
internal/builtin/database/cassandra/connection_producer.go:30-30 (data_classification)
sdk/database/dbplugin/v5/database.go:186-186 (data_classification)
sdk/database/helper/connutil/sql.go:31-31 (data_classification)
sdk/database/dbplugin/database.pb.go:856-856 (data_classification)
internal/builtin/logical/database/path_roles.go:793-793 (data_classification)
sdk/database/dbplugin/v5/proto/database.pb.go:131-131 (data_classification)
High
SOC2_P4_1 — Limitation of Personal Information Use
Code Improvement Recommended
Satisfied: Data Classification
Missing: Access Control, Consent Management, Encryption At Rest, Encryption In Transit, Key Management
internal/builtin/database/mysql/connection_producer.go:36-36 (data_classification)
internal/builtin/logical/openldap/path_dynamic_creds.go:276-276 (data_classification)
sdk/database/dbplugin/v5/database.go:120-120 (data_classification)
sdk/database/dbplugin/v5/proto/database.pb.go:330-330 (data_classification)
api/auth/ldap/ldap.go:20-20 (data_classification)
api/auth/userpass/userpass.go:20-20 (data_classification)
internal/builtin/logical/pki/cert_template.pb.go:297-297 (data_classification)
sdk/plugin/pb/backend.pb.go:3349-3349 (data_classification)
sdk/database/dbplugin/database.pb.go:699-699 (data_classification)
internal/builtin/logical/openldap/path_static_roles.go:401-401 (data_classification)
sdk/database/dbplugin/database.pb.go:524-524 (data_classification)
internal/builtin/database/influxdb/connection_producer.go:28-28 (data_classification)
internal/builtin/database/valkey/connection_producer.go:25-25 (data_classification)
internal/builtin/database/cassandra/connection_producer.go:30-30 (data_classification)
sdk/database/dbplugin/v5/database.go:186-186 (data_classification)
sdk/database/helper/connutil/sql.go:31-31 (data_classification)
sdk/database/dbplugin/database.pb.go:856-856 (data_classification)
internal/builtin/logical/database/path_roles.go:793-793 (data_classification)
sdk/database/dbplugin/v5/proto/database.pb.go:131-131 (data_classification)
High
SOC2_P5_1 — Data Subject Access to Personal Information
Code Improvement Recommended
Satisfied: Data Classification
Missing: Access Control, Consent Management, Encryption At Rest, Encryption In Transit, Key Management
internal/builtin/database/mysql/connection_producer.go:36-36 (data_classification)
internal/builtin/logical/openldap/path_dynamic_creds.go:276-276 (data_classification)
sdk/database/dbplugin/v5/database.go:120-120 (data_classification)
sdk/database/dbplugin/v5/proto/database.pb.go:330-330 (data_classification)
api/auth/ldap/ldap.go:20-20 (data_classification)
api/auth/userpass/userpass.go:20-20 (data_classification)
internal/builtin/logical/pki/cert_template.pb.go:297-297 (data_classification)
sdk/plugin/pb/backend.pb.go:3349-3349 (data_classification)
sdk/database/dbplugin/database.pb.go:699-699 (data_classification)
internal/builtin/logical/openldap/path_static_roles.go:401-401 (data_classification)
sdk/database/dbplugin/database.pb.go:524-524 (data_classification)
internal/builtin/database/influxdb/connection_producer.go:28-28 (data_classification)
internal/builtin/database/valkey/connection_producer.go:25-25 (data_classification)
internal/builtin/database/cassandra/connection_producer.go:30-30 (data_classification)
sdk/database/dbplugin/v5/database.go:186-186 (data_classification)
sdk/database/helper/connutil/sql.go:31-31 (data_classification)
sdk/database/dbplugin/database.pb.go:856-856 (data_classification)
internal/builtin/logical/database/path_roles.go:793-793 (data_classification)
sdk/database/dbplugin/v5/proto/database.pb.go:131-131 (data_classification)
High
SOC2_CC6_5 — Discontinuation of Protections
Code Improvement Recommended
Satisfied: Data Classification, Data Lifecycle Management
Missing: Access Control, Encryption At Rest, Encryption In Transit, Key Management
internal/builtin/database/mysql/connection_producer.go:36-36 (data_classification)
internal/builtin/logical/openldap/path_dynamic_creds.go:276-276 (data_classification)
sdk/database/dbplugin/v5/database.go:120-120 (data_classification)
sdk/database/dbplugin/v5/proto/database.pb.go:330-330 (data_classification)
api/auth/ldap/ldap.go:20-20 (data_classification)
api/auth/userpass/userpass.go:20-20 (data_classification)
internal/builtin/logical/pki/cert_template.pb.go:297-297 (data_classification)
internal/builtin/logical/openldap/path_static_roles.go:401-401 (data_minimization_module_fanin)
internal/builtin/database/cassandra/connection_producer.go:30-30 (data_minimization_module_fanin)
sdk/plugin/pb/backend.pb.go:3349-3349 (data_classification)
internal/builtin/database/influxdb/connection_producer.go:28-28 (data_minimization_module_fanin)
sdk/database/dbplugin/database.pb.go:699-699 (data_classification)
internal/builtin/database/valkey/connection_producer.go:25-25 (data_minimization_module_fanin)
internal/builtin/logical/openldap/path_static_roles.go:401-401 (data_classification)
sdk/database/dbplugin/database.pb.go:524-524 (data_classification)
internal/builtin/database/influxdb/connection_producer.go:28-28 (data_classification)
internal/builtin/database/valkey/connection_producer.go:25-25 (data_classification)
internal/builtin/database/cassandra/connection_producer.go:30-30 (data_classification)
sdk/database/dbplugin/v5/database.go:186-186 (data_classification)
sdk/database/helper/connutil/sql.go:31-31 (data_classification)
sdk/database/dbplugin/database.pb.go:856-856 (data_classification)
internal/builtin/logical/database/path_roles.go:793-793 (data_classification)
sdk/database/dbplugin/v5/proto/database.pb.go:131-131 (data_classification)
internal/builtin/logical/openldap/path_dynamic_creds.go:276-276 (data_minimization_module_fanin)
High
HIPAA_310_D_001 — Disposal
Code Improvement Recommended
Satisfied: Data Lifecycle Management
internal/builtin/logical/openldap/path_static_roles.go:401-401 (data_minimization_module_fanin)
internal/builtin/database/cassandra/connection_producer.go:30-30 (data_minimization_module_fanin)
internal/builtin/database/influxdb/connection_producer.go:28-28 (data_minimization_module_fanin)
internal/builtin/database/valkey/connection_producer.go:25-25 (data_minimization_module_fanin)
internal/builtin/logical/openldap/path_dynamic_creds.go:276-276 (data_minimization_module_fanin)
High
HIPAA_310_D_002 — Media Re-use
Code Improvement Recommended
Satisfied: Data Lifecycle Management
internal/builtin/logical/openldap/path_static_roles.go:401-401 (data_minimization_module_fanin)
internal/builtin/database/cassandra/connection_producer.go:30-30 (data_minimization_module_fanin)
internal/builtin/database/influxdb/connection_producer.go:28-28 (data_minimization_module_fanin)
internal/builtin/database/valkey/connection_producer.go:25-25 (data_minimization_module_fanin)
internal/builtin/logical/openldap/path_dynamic_creds.go:276-276 (data_minimization_module_fanin)
High
SOC2_C1_2 — Disposal of Confidential Information
Code Improvement Recommended
Satisfied: Data Lifecycle Management
internal/builtin/logical/openldap/path_static_roles.go:401-401 (data_minimization_module_fanin)
internal/builtin/database/cassandra/connection_producer.go:30-30 (data_minimization_module_fanin)
internal/builtin/database/influxdb/connection_producer.go:28-28 (data_minimization_module_fanin)
internal/builtin/database/valkey/connection_producer.go:25-25 (data_minimization_module_fanin)
internal/builtin/logical/openldap/path_dynamic_creds.go:276-276 (data_minimization_module_fanin)
High
SOC2_P4_2 — Retention of Personal Information
Code Improvement Recommended
Satisfied: Data Lifecycle Management
Missing: Data Retention
internal/builtin/logical/openldap/path_static_roles.go:401-401 (data_minimization_module_fanin)
internal/builtin/database/cassandra/connection_producer.go:30-30 (data_minimization_module_fanin)
internal/builtin/database/influxdb/connection_producer.go:28-28 (data_minimization_module_fanin)
internal/builtin/database/valkey/connection_producer.go:25-25 (data_minimization_module_fanin)
internal/builtin/logical/openldap/path_dynamic_creds.go:276-276 (data_minimization_module_fanin)
High
SOC2_P4_3 — Disposal of Personal Information
Code Improvement Recommended
Satisfied: Data Lifecycle Management
internal/builtin/logical/openldap/path_static_roles.go:401-401 (data_minimization_module_fanin)
internal/builtin/database/cassandra/connection_producer.go:30-30 (data_minimization_module_fanin)
internal/builtin/database/influxdb/connection_producer.go:28-28 (data_minimization_module_fanin)
internal/builtin/database/valkey/connection_producer.go:25-25 (data_minimization_module_fanin)
internal/builtin/logical/openldap/path_dynamic_creds.go:276-276 (data_minimization_module_fanin)
High
GDPR_ART_12_005 — Free of Charge Information and Requests
Code Improvement Recommended
Missing: Consent Management
High
GDPR_ART_17_002 — Obligation to Inform Other Controllers of Erasure Request
Code Improvement Recommended
Missing: Consent Management
High
GDPR_ART_18_002 — Processing of Restricted Data
Code Improvement Recommended
Missing: Consent Management
High
GDPR_ART_19_001 — Notification Obligation Regarding Rectification, Erasure, or Restriction
Code Improvement Recommended
Missing: Consent Management
High
GDPR_ART_20_003 — Data Portability - Limitations
Code Improvement Recommended
Missing: Consent Management
High
GDPR_ART_23_001 — Restrictions of Rights and Obligations
Code Improvement Recommended
Missing: Consent Management
High
GDPR_ART_27_001 — Representative of Controllers or Processors Not Established in the Union
Code Improvement Recommended
Missing: Access Control
High
GDPR_ART_27_002 — Representative - Mandate and Responsibilities
Code Improvement Recommended
Missing: Access Control
High
GDPR_ART_28_002 — Processor - Engagement of Sub-Processors
Code Improvement Recommended
Missing: Access Control
High
GDPR_ART_34_002 — Exceptions to Breach Communication to Data Subject
Code Improvement Recommended
Missing: Audit Logging
High
GDPR_ART_35_003 — DPIA - Content
Code Improvement Recommended
Missing: Consent Management
High
GDPR_ART_58_001 — Supervisory Authority - Investigative Powers
Code Improvement Recommended
Missing: Audit Logging
High
GDPR_ART_6_002 — Lawful Processing - Contract
Code Improvement Recommended
Missing: Consent Management
High
GDPR_ART_7_004 — Consent - Freely Given Assessment
Code Improvement Recommended
Missing: Consent Management
High
HIPAA_308_A1_004 — Information System Activity Review
Code Improvement Recommended
Missing: Audit Logging
High
HIPAA_308_B_001 — Business Associate Contracts and Other Arrangements
Code Improvement Recommended
Missing: Access Control
High
HIPAA_310_C_001 — Workstation Security
Code Improvement Recommended
Missing: Access Control
High
HIPAA_312_B_001 — Audit Controls
Code Improvement Recommended
Missing: Audit Logging
High
HIPAA_314_A_001 — Business Associate Contracts
Code Improvement Recommended
Missing: Access Control
High
SOC2_A1_3 — Recovery Plan Testing
Code Improvement Recommended
Missing: Audit Logging
High
SOC2_CC4_1 — Ongoing and Separate Evaluations
Code Improvement Recommended
Missing: Audit Logging
High
SOC2_CC4_2 — Evaluation and Communication of Deficiencies
Code Improvement Recommended
Missing: Audit Logging
High
SOC2_CC7_1 — Detection and Monitoring of Vulnerabilities
Code Improvement Recommended
Missing: Audit Logging
High
SOC2_CC7_2 — Anomaly Monitoring and Analysis
Code Improvement Recommended
Missing: Audit Logging
High
SOC2_CC7_5 — Recovery from Security Incidents
Code Improvement Recommended
Missing: Audit Logging
High
SOC2_CC8_1 — Change Management
Code Improvement Recommended
Missing: Audit Logging
High
SOC2_CC9_2 — Vendor and Business Partner Risk Management
Code Improvement Recommended
Missing: Access Control
High
SOC2_P1_1 — Privacy Notice to Data Subjects
Code Improvement Recommended
Missing: Consent Management
High
SOC2_P1_2 — Privacy Notice Maintenance
Code Improvement Recommended
Missing: Consent Management
Control Mapping Appendix
Raw control-level mapping (control IDs, clause text) is intentionally not inlined here — export to JSON or SARIF for the complete, machine-readable control mapping.
Meridian - Deterministic + LLM-augmented compliance scan
eb683f4bb539f6f4c3262e34