Meridian provides automated compliance assessments and recommendations, not legal advice. Final compliance determinations should be reviewed by qualified legal, compliance, or security professionals where required.
Executive Summary
Applicable Controls
544
Controls determined to apply to this repository
Requires Documentation
216
Requires Operational Evidence
49
Code Improvement Recommended
208
Repository Overview
Technology Stack
3878 files · 1024474 lines
Languages go, javascript, python, tsx, typescript
Frameworks FastAPI, Flask, Next.js, React, Starlette
Data & Infrastructure MySQL, PostgreSQL, SQL (via SQLAlchemy)
CI/CD & IaC Docker, Docker Compose, GitHub Actions
Business Signals
Stores personal data True
Uses AI True
Primary jurisdiction Other
Processes payments True
Regulated financial entity False
Offers goods/services to the EU True
Monitors individuals in the EU False
Offers goods/services to India False
AI role Provider
AI output used in the EU True
High-risk AI use case indicated False
General-purpose AI model provider False
What Meridian Understood
This repository employs a complex technology stack focusing on web applications and AI functionalities. It uses multiple programming languages and frameworks to offer web services, likely integrating AI models via SDKs for enhanced functionality. It also ensures security through encrypted communications, authentication measures, and secrets management.
Architecture: Web and AI services platform
Compliance Scope
Applicable Regulations
GDPR Privacy & Data Protection Statutory law
Your application stores or processes personal data of individuals in the European Union.
Required: matched on stores_personal_data, offers_goods_services_to_eu.
In force since May 2018; applies extraterritorially to organizations offering goods or services to, or monitoring, individuals in the EU.
EU AI Act AI Governance & Responsible AI Statutory law
Your repository deploys AI models or AI-powered systems.
Required: matched on ai_usage.
In force since August 2024 with phased application — prohibited practices first, general-purpose AI and high-risk obligations phasing in later; verify current phase-in dates.
AI risk context: role: Provider; output used in the EU: yes; high-risk use case indicated: no; general-purpose model provider: no
PCI DSS Payments & Financial Security Contractual standard
Your application processes payments or handles cardholder data.
Required: matched on processes_payments.
An industry standard enforced through card-network and acquirer agreements, not a statute; applies to entities that store, process, or transmit cardholder data.
SOC 2 Trust Services Criteria Trust & Assurance Voluntary attestation
Your application is in production and handles customer data requiring independent assurance.
Optional: base condition met, but no additional signal beyond production.
A voluntary attestation framework (AICPA Trust Services Criteria) driven by customer and contractual demand, not law.
NIST AI RMF AI Governance & Responsible AI Voluntary attestation
Your application develops, deploys, or uses AI/ML systems.
Required: matched on ai_usage.
AI RMF 1.0 released January 2023 by NIST; a voluntary risk-management framework, not a binding regulation -- adopted for market trust and structured AI governance, not because it is legally required.
Not Applicable Regulations
DPDPA 2023 Privacy & Data Protection
Excluded: none of 'primary_jurisdiction', 'offers_goods_services_to_india' match the conditions required for this framework.
DPDPA Rules, 2025 Privacy & Data Protection
Excluded: none of 'primary_jurisdiction', 'offers_goods_services_to_india' match the conditions required for this framework.
RBI FREE-AI Framework AI Governance & Responsible AI
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
SEBI AI/ML Guidelines AI Governance & Responsible AI
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
RBI Digital Payment Security Controls Payments & Financial Security
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
RBI IT Governance & Risk Controls Cybersecurity & Operational Security
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
RBI NBFC IT Framework Financial Sector Regulations
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
RBI NBFC Outsourcing Directions Financial Sector Regulations
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
RBI Outsourcing Directions Financial Sector Regulations
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
RBI Payments Banks Outsourcing Directions Financial Sector Regulations
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
RBI Small Finance Banks Outsourcing Directions Financial Sector Regulations
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
SEBI Cybersecurity Framework Cybersecurity & Operational Security
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
CERT-In Directions Cybersecurity & Operational Security
Excluded: 'primary_jurisdiction' does not match the condition required for this framework.
Needs More Information
Not enough was known to confirm or rule these out — Meridian conservatively evaluates their controls below until you provide the missing details.
HIPAA Security Rule Privacy & Data Protection
Not enough information yet: handles_health_data not answered.
Compliance Readiness
Implemented
Authentication
Cross Border Transfer Controls
Data Classification
Data Lifecycle Management
Code Improvement Recommended
Access Control
Audit Logging
Consent Management
Data Retention
Encryption At Rest
Encryption In Transit
Key Management
Requires Documentation
Asset Inventory
Backup And Recovery
Business Impact Analysis
Configuration Management
Data Deletion
Data Masking
Data Protection Impact Assessment
Data Subject Request Handling
Grievance Redressal
Incident Response Plan
Information Security Policy
Log Retention
Policy Management
Privacy Impact Assessment
Records Of Processing
Requires Operational Evidence
AI Risk Assessment
Access Review
BCP And DR Testing
Bias Detection
Change Management
Data Loss Prevention
Data Quality Management
Governance Framework
Incident Detection
Maker Checker
Model Monitoring
Model Testing
Patch Management
Penetration Testing
Physical Access Control
Privileged Access Management
Regulatory Change Monitoring
Regulatory Reporting
SOC Operations
Security Awareness Training
Third Party Risk Assessment
Vendor Contract Management
Vulnerability Scanning
Enterprise Readiness
Detected
Authentication
Recommended Improvements
Access Control
Audit Logging
Encryption At Rest
Encryption In Transit
Key Management
Data Retention
Operational Requirements
Privileged Access Management
BCP And DR Testing
Penetration Testing
Third Party Risk Assessment
Vendor Contract Management
Security Awareness Training
Documentation Required
Incident Response Plan
Information Security Policy
SOC 2 Scope
The subset of the capabilities above that SOC 2's own controls actually reach.
Detected
Authentication
Recommended Improvements
Access Control
Audit Logging
Encryption At Rest
Encryption In Transit
Key Management
Data Retention
Operational Requirements
Privileged Access Management
BCP And DR Testing
Penetration Testing
Third Party Risk Assessment
Vendor Contract Management
Security Awareness Training
Documentation Required
Incident Response Plan
AI Governance
AI frameworks Anthropic SDK, LiteLLM, OpenAI SDK, LangGraph
AI infrastructure Ollama
Vector databases none detected
Notebooks 0
AI regulations evaluated EU Artificial Intelligence Act
Not mapped (no real control data available): ISO_42001, NIST_AI_RMF, OECD_AI_PRINCIPLES
Deployment Profile
Agentic / multi-agent workflows Hosted LLM usage Local/self-hosted model serving
AI Governance Posture
Replaces a bare AI maturity score with the actual capabilities checked.
Requires Operational Processes
Governance Framework
AI Risk Assessment
Model Monitoring
Model Testing
Bias Detection
Maker Checker
Penetration Testing
Code Improvement Recommended
Audit Logging
Top Priorities
Access Control (CRITICAL) — Can the organization (as a non-EU controller/processor) demonstrate that it has designated a representative in the Union?
Improves compliance posture for: GDPR, HIPAA Security Rule, NIST AI RMF, PCI DSS, SOC 2 Trust Services Criteria.
Authentication (CRITICAL) — Can the multi-tenant service provider demonstrate logical separation between provider and customer environments with authorization controls?
Improves compliance posture for: PCI DSS.
Encryption In Transit (CRITICAL) — Can the designated entity demonstrate that response procedures are in place for cleartext PAN found outside the CDE?
Improves compliance posture for: PCI DSS, SOC 2 Trust Services Criteria.
Encryption At Rest (CRITICAL) — Can the designated entity demonstrate that response procedures are in place for cleartext PAN found outside the CDE?
Improves compliance posture for: PCI DSS, SOC 2 Trust Services Criteria.
Key Management (CRITICAL) — Can the designated entity demonstrate that response procedures are in place for cleartext PAN found outside the CDE?
Improves compliance posture for: PCI DSS, SOC 2 Trust Services Criteria.
Full breakdown by effort below.
Recommended Actions
Quick Wins
Access Control (CRITICAL)Can the organization (as a non-EU controller/processor) demonstrate that it has designated a representative in the Union?
Improves compliance posture for: GDPR, HIPAA Security Rule, NIST AI RMF, PCI DSS, SOC 2 Trust Services Criteria.
Authentication (CRITICAL)Can the multi-tenant service provider demonstrate logical separation between provider and customer environments with authorization controls?
Improves compliance posture for: PCI DSS.
Encryption In Transit (CRITICAL)Can the designated entity demonstrate that response procedures are in place for cleartext PAN found outside the CDE?
Improves compliance posture for: PCI DSS, SOC 2 Trust Services Criteria.
Encryption At Rest (CRITICAL)Can the designated entity demonstrate that response procedures are in place for cleartext PAN found outside the CDE?
Improves compliance posture for: PCI DSS, SOC 2 Trust Services Criteria.
Patch Management (HIGH)Can the organization demonstrate: aI system security and resilience -- as identified in the map function -- are evaluated and documented.
Improves compliance posture for: NIST AI RMF.
Vulnerability Scanning (HIGH)Can the organization demonstrate: aI system security and resilience -- as identified in the map function -- are evaluated and documented.
Improves compliance posture for: NIST AI RMF.
Log Retention (MEDIUM)Does the organization monitor log-in attempts to systems containing electronic protected health information and report discrepancies?
Improves compliance posture for: HIPAA Security Rule.
Medium Effort
Key Management (CRITICAL)Can the designated entity demonstrate that response procedures are in place for cleartext PAN found outside the CDE?
Improves compliance posture for: PCI DSS, SOC 2 Trust Services Criteria.
Privileged Access Management (HIGH)Can the organization demonstrate that it has taken measures to ensure a sufficient level of AI literacy among staff and others involved in the operation and use of AI systems?
Improves compliance posture for: EU AI Act, GDPR, NIST AI RMF, SOC 2 Trust Services Criteria.
Consent Management (HIGH)Can the organization demonstrate that AI systems intended to interact with natural persons are designed to inform them they are interacting with an AI system?
Improves compliance posture for: EU AI Act, GDPR, SOC 2 Trust Services Criteria.
Data Subject Request Handling (HIGH)Can the organization demonstrate that it has procedures to handle complaints regarding infringement of the AI Act?
Improves compliance posture for: EU AI Act, NIST AI RMF.
Audit Logging (HIGH)Can the organization demonstrate that it has properly applied exceptions to breach communication to data subjects?
Improves compliance posture for: GDPR, HIPAA Security Rule, NIST AI RMF, PCI DSS, SOC 2 Trust Services Criteria.
Incident Response Plan (HIGH)Has the organization conducted and documented a risk analysis assessing threats and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information?
Improves compliance posture for: HIPAA Security Rule, SOC 2 Trust Services Criteria.
Backup And Recovery (HIGH)Does the organization maintain retrievable, exact backup copies of electronic protected health information?
Improves compliance posture for: HIPAA Security Rule, SOC 2 Trust Services Criteria.
Data Retention (HIGH)Can the organization demonstrate that audit logs are retained for at least 12 months and the most recent 3 months are immediately available?
Improves compliance posture for: PCI DSS, SOC 2 Trust Services Criteria.
Maker Checker (MEDIUM)Can the organization demonstrate that it has taken measures to ensure a sufficient level of AI literacy among staff and others involved in the operation and use of AI systems?
Improves compliance posture for: EU AI Act, GDPR, NIST AI RMF, SOC 2 Trust Services Criteria.
Model Testing (MEDIUM)Can the organization demonstrate that it has taken measures to ensure a sufficient level of AI literacy among staff and others involved in the operation and use of AI systems?
Improves compliance posture for: EU AI Act, GDPR, NIST AI RMF.
Records Of Processing (MEDIUM)Can the organization (as a law enforcement authority) demonstrate that it notifies each use of real-time remote biometric identification to the relevant authorities and submits annual reports?
Improves compliance posture for: EU AI Act, GDPR, HIPAA Security Rule, NIST AI RMF, PCI DSS, SOC 2 Trust Services Criteria.
Grievance Redressal (MEDIUM)Can the organization demonstrate that it has procedures to handle complaints regarding infringement of the AI Act?
Improves compliance posture for: EU AI Act, NIST AI RMF.
Data Masking (MEDIUM)Can the organization demonstrate that processing of criminal conviction data is under official control or authorised by law with appropriate safeguards?
Improves compliance posture for: GDPR, PCI DSS, SOC 2 Trust Services Criteria.
Business Impact Analysis (MEDIUM)Can the organization demonstrate that it has assessed the risks to personal data when determining security measures?
Improves compliance posture for: GDPR, HIPAA Security Rule, PCI DSS, SOC 2 Trust Services Criteria.
Asset Inventory (MEDIUM)Has the organization conducted and documented a risk analysis assessing threats and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information?
Improves compliance posture for: HIPAA Security Rule.
Configuration Management (MEDIUM)Has the organization conducted and documented a risk analysis assessing threats and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information?
Improves compliance posture for: HIPAA Security Rule, PCI DSS.
Data Lifecycle Management (MEDIUM)Does the organization have documented policies for the final disposition of electronic protected health information and the media it is stored on?
Improves compliance posture for: HIPAA Security Rule, PCI DSS, SOC 2 Trust Services Criteria.
Information Security Policy (MEDIUM)Has the organization implemented documented policies and procedures reasonably designed to comply with the HIPAA Security Rule's standards and implementation specifications?
Improves compliance posture for: HIPAA Security Rule.
Data Classification (MEDIUM)Can the designated entity demonstrate that response procedures are in place for cleartext PAN found outside the CDE?
Improves compliance posture for: PCI DSS, SOC 2 Trust Services Criteria.
Security Awareness Training (LOW)Can the organization demonstrate that it has taken measures to ensure a sufficient level of AI literacy among staff and others involved in the operation and use of AI systems?
Improves compliance posture for: EU AI Act, GDPR, NIST AI RMF, SOC 2 Trust Services Criteria.
Policy Management (LOW)Can the organization (as a law enforcement authority) demonstrate that it notifies each use of real-time remote biometric identification to the relevant authorities and submits annual reports?
Improves compliance posture for: EU AI Act, GDPR, HIPAA Security Rule, NIST AI RMF, PCI DSS, SOC 2 Trust Services Criteria.
Data Quality Management (INFORMATIONAL)Can the organization demonstrate that it has taken measures to ensure a sufficient level of AI literacy among staff and others involved in the operation and use of AI systems?
Improves compliance posture for: EU AI Act, GDPR, NIST AI RMF.
Strategic Initiatives
AI Risk Assessment (HIGH)Can the organization demonstrate that it has taken measures to ensure a sufficient level of AI literacy among staff and others involved in the operation and use of AI systems?
Improves compliance posture for: EU AI Act, GDPR, NIST AI RMF, SOC 2 Trust Services Criteria.
Bias Detection (HIGH)Can the organization demonstrate that it has taken measures to ensure a sufficient level of AI literacy among staff and others involved in the operation and use of AI systems?
Improves compliance posture for: EU AI Act, GDPR, NIST AI RMF.
Data Loss Prevention (HIGH)Can the organization demonstrate that it does not create or expand facial recognition databases through untargeted scraping?
Improves compliance posture for: EU AI Act, GDPR.
Data Protection Impact Assessment (HIGH)Can the organization demonstrate that it has assessed the risks to personal data when determining security measures?
Improves compliance posture for: GDPR, PCI DSS, SOC 2 Trust Services Criteria.
Privacy Impact Assessment (HIGH)Can the organization demonstrate that it has assessed the risks to personal data when determining security measures?
Improves compliance posture for: GDPR, PCI DSS, SOC 2 Trust Services Criteria.
Penetration Testing (HIGH)Can the organization demonstrate: aI system security and resilience -- as identified in the map function -- are evaluated and documented.
Improves compliance posture for: NIST AI RMF.
Model Monitoring (MEDIUM)Can the organization demonstrate that it has taken measures to ensure a sufficient level of AI literacy among staff and others involved in the operation and use of AI systems?
Improves compliance posture for: EU AI Act, GDPR, NIST AI RMF.
Physical Access Control (MEDIUM)Can the organization demonstrate that it does not create or expand facial recognition databases through untargeted scraping?
Improves compliance posture for: EU AI Act, GDPR.
Compliance Roadmap
Now · Quick Wins
Access Control Authentication Encryption In Transit Encryption At Rest Patch Management Vulnerability Scanning Log Retention
Next · Medium Effort
Key Management Privileged Access Management Consent Management Data Subject Request Handling Audit Logging Incident Response Plan Backup And Recovery Data Retention Maker Checker Model Testing Records Of Processing Grievance Redressal Data Masking Business Impact Analysis Asset Inventory Configuration Management Data Lifecycle Management Information Security Policy Data Classification Security Awareness Training Policy Management Data Quality Management
Later · Strategic Initiatives
AI Risk Assessment Bias Detection Data Loss Prevention Data Protection Impact Assessment Privacy Impact Assessment Penetration Testing Model Monitoring Physical Access Control
Next Steps
Start with Top Priorities above, then work through the full Quick Wins/Medium Effort/Strategic Initiatives breakdown.
Technical Findings below show exactly where each gap was detected in your repository; export to PDF/HTML for a
shareable version, or JSON/SARIF to feed a CI pipeline.
Technical Findings (187)
Showing top 50 of 187, ranked by severity then confidence.
Export to JSON or SARIF for the complete list.
Critical
PCI_REQ_3_6_1 — Define and Implement Procedures to Protect Cryptographic Keys
Code Improvement Recommended
Satisfied: Data Classification
Missing: Access Control, Encryption At Rest, Encryption In Transit, Key Management
common/data_source/models.py:128-128 (data_classification)
internal/service/tenant.go:902-902 (data_classification)
internal/service/tenant.go:104-104 (data_classification)
internal/service/agent_dbcheck.go:44-44 (data_classification)
web/src/pages/user-setting/profile/hooks/use-profile.ts:17-17 (data_classification)
internal/service/tenant.go:858-858 (data_classification)
internal/admin/handler_ee.go:828-828 (data_classification)
internal/dao/user_tenant.go:132-132 (data_classification)
internal/service/user.go:74-74 (data_classification)
web/src/pages/admin/forms/change-password-form.tsx:24-24 (data_classification)
internal/admin/handler_ee.go:1726-1726 (data_classification)
internal/agent/tool/pubmed.go:57-57 (data_classification)
internal/service/user.go:91-91 (data_classification)
internal/admin/handler.go:246-246 (data_classification)
web/src/pages/admin/forms/email-form.tsx:17-17 (data_classification)
internal/service/user.go:98-98 (data_classification)
internal/admin/handler_ee.go:1780-1780 (data_classification)
internal/service/user.go:1320-1320 (data_classification)
internal/service/user.go:69-69 (data_classification)
internal/service/tenant.go:909-909 (data_classification)
internal/admin/handler.go:1010-1010 (data_classification)
internal/server/config.go:72-72 (data_classification)
internal/handler/user.go:624-624 (data_classification)
internal/agent/sandbox/ssh.go:83-83 (data_classification)
internal/utility/oauth/client.go:64-64 (data_classification)
common/data_source/interfaces.py:371-371 (data_classification)
internal/service/user.go:61-61 (data_classification)
internal/agent/tool/email.go:51-51 (data_classification)
internal/entity/user.go:26-26 (data_classification)
web/src/pages/admin/forms/user-form.tsx:32-32 (data_classification)
internal/dao/user_tenant.go:120-120 (data_classification)
internal/handler/user.go:655-655 (data_classification)
internal/service/user.go:85-85 (data_classification)
internal/admin/handler.go:1078-1078 (data_classification)
internal/cli/cli.go:53-53 (data_classification)
internal/admin/handler.go:1041-1041 (data_classification)
internal/agent/tool/exesql.go:110-110 (data_classification)
internal/handler/user.go:586-586 (data_classification)
Critical
PCI_REQ_3_6_1_2 — Store Secret and Private Keys in Secure Forms
Code Improvement Recommended
Satisfied: Data Classification
Missing: Access Control, Encryption At Rest, Encryption In Transit, Key Management
common/data_source/models.py:128-128 (data_classification)
internal/service/tenant.go:902-902 (data_classification)
internal/service/tenant.go:104-104 (data_classification)
internal/service/agent_dbcheck.go:44-44 (data_classification)
web/src/pages/user-setting/profile/hooks/use-profile.ts:17-17 (data_classification)
internal/service/tenant.go:858-858 (data_classification)
internal/admin/handler_ee.go:828-828 (data_classification)
internal/dao/user_tenant.go:132-132 (data_classification)
internal/service/user.go:74-74 (data_classification)
web/src/pages/admin/forms/change-password-form.tsx:24-24 (data_classification)
internal/admin/handler_ee.go:1726-1726 (data_classification)
internal/agent/tool/pubmed.go:57-57 (data_classification)
internal/service/user.go:91-91 (data_classification)
internal/admin/handler.go:246-246 (data_classification)
web/src/pages/admin/forms/email-form.tsx:17-17 (data_classification)
internal/service/user.go:98-98 (data_classification)
internal/admin/handler_ee.go:1780-1780 (data_classification)
internal/service/user.go:1320-1320 (data_classification)
internal/service/user.go:69-69 (data_classification)
internal/service/tenant.go:909-909 (data_classification)
internal/admin/handler.go:1010-1010 (data_classification)
internal/server/config.go:72-72 (data_classification)
internal/handler/user.go:624-624 (data_classification)
internal/agent/sandbox/ssh.go:83-83 (data_classification)
internal/utility/oauth/client.go:64-64 (data_classification)
common/data_source/interfaces.py:371-371 (data_classification)
internal/service/user.go:61-61 (data_classification)
internal/agent/tool/email.go:51-51 (data_classification)
internal/entity/user.go:26-26 (data_classification)
web/src/pages/admin/forms/user-form.tsx:32-32 (data_classification)
internal/dao/user_tenant.go:120-120 (data_classification)
internal/handler/user.go:655-655 (data_classification)
internal/service/user.go:85-85 (data_classification)
internal/admin/handler.go:1078-1078 (data_classification)
internal/cli/cli.go:53-53 (data_classification)
internal/admin/handler.go:1041-1041 (data_classification)
internal/agent/tool/exesql.go:110-110 (data_classification)
internal/handler/user.go:586-586 (data_classification)
Critical
PCI_REQ_3_7_1 — Implement Key Management for Strong Key Generation
Code Improvement Recommended
Satisfied: Data Classification
Missing: Access Control, Encryption At Rest, Encryption In Transit, Key Management
common/data_source/models.py:128-128 (data_classification)
internal/service/tenant.go:902-902 (data_classification)
internal/service/tenant.go:104-104 (data_classification)
internal/service/agent_dbcheck.go:44-44 (data_classification)
web/src/pages/user-setting/profile/hooks/use-profile.ts:17-17 (data_classification)
internal/service/tenant.go:858-858 (data_classification)
internal/admin/handler_ee.go:828-828 (data_classification)
internal/dao/user_tenant.go:132-132 (data_classification)
internal/service/user.go:74-74 (data_classification)
web/src/pages/admin/forms/change-password-form.tsx:24-24 (data_classification)
internal/admin/handler_ee.go:1726-1726 (data_classification)
internal/agent/tool/pubmed.go:57-57 (data_classification)
internal/service/user.go:91-91 (data_classification)
internal/admin/handler.go:246-246 (data_classification)
web/src/pages/admin/forms/email-form.tsx:17-17 (data_classification)
internal/service/user.go:98-98 (data_classification)
internal/admin/handler_ee.go:1780-1780 (data_classification)
internal/service/user.go:1320-1320 (data_classification)
internal/service/user.go:69-69 (data_classification)
internal/service/tenant.go:909-909 (data_classification)
internal/admin/handler.go:1010-1010 (data_classification)
internal/server/config.go:72-72 (data_classification)
internal/handler/user.go:624-624 (data_classification)
internal/agent/sandbox/ssh.go:83-83 (data_classification)
internal/utility/oauth/client.go:64-64 (data_classification)
common/data_source/interfaces.py:371-371 (data_classification)
internal/service/user.go:61-61 (data_classification)
internal/agent/tool/email.go:51-51 (data_classification)
internal/entity/user.go:26-26 (data_classification)
web/src/pages/admin/forms/user-form.tsx:32-32 (data_classification)
internal/dao/user_tenant.go:120-120 (data_classification)
internal/handler/user.go:655-655 (data_classification)
internal/service/user.go:85-85 (data_classification)
internal/admin/handler.go:1078-1078 (data_classification)
internal/cli/cli.go:53-53 (data_classification)
internal/admin/handler.go:1041-1041 (data_classification)
internal/agent/tool/exesql.go:110-110 (data_classification)
internal/handler/user.go:586-586 (data_classification)
Critical
PCI_REQ_3_7_2 — Implement Key Management for Secure Distribution
Code Improvement Recommended
Satisfied: Data Classification
Missing: Access Control, Encryption At Rest, Encryption In Transit, Key Management
common/data_source/models.py:128-128 (data_classification)
internal/service/tenant.go:902-902 (data_classification)
internal/service/tenant.go:104-104 (data_classification)
internal/service/agent_dbcheck.go:44-44 (data_classification)
web/src/pages/user-setting/profile/hooks/use-profile.ts:17-17 (data_classification)
internal/service/tenant.go:858-858 (data_classification)
internal/admin/handler_ee.go:828-828 (data_classification)
internal/dao/user_tenant.go:132-132 (data_classification)
internal/service/user.go:74-74 (data_classification)
web/src/pages/admin/forms/change-password-form.tsx:24-24 (data_classification)
internal/admin/handler_ee.go:1726-1726 (data_classification)
internal/agent/tool/pubmed.go:57-57 (data_classification)
internal/service/user.go:91-91 (data_classification)
internal/admin/handler.go:246-246 (data_classification)
web/src/pages/admin/forms/email-form.tsx:17-17 (data_classification)
internal/service/user.go:98-98 (data_classification)
internal/admin/handler_ee.go:1780-1780 (data_classification)
internal/service/user.go:1320-1320 (data_classification)
internal/service/user.go:69-69 (data_classification)
internal/service/tenant.go:909-909 (data_classification)
internal/admin/handler.go:1010-1010 (data_classification)
internal/server/config.go:72-72 (data_classification)
internal/handler/user.go:624-624 (data_classification)
internal/agent/sandbox/ssh.go:83-83 (data_classification)
internal/utility/oauth/client.go:64-64 (data_classification)
common/data_source/interfaces.py:371-371 (data_classification)
internal/service/user.go:61-61 (data_classification)
internal/agent/tool/email.go:51-51 (data_classification)
internal/entity/user.go:26-26 (data_classification)
web/src/pages/admin/forms/user-form.tsx:32-32 (data_classification)
internal/dao/user_tenant.go:120-120 (data_classification)
internal/handler/user.go:655-655 (data_classification)
internal/service/user.go:85-85 (data_classification)
internal/admin/handler.go:1078-1078 (data_classification)
internal/cli/cli.go:53-53 (data_classification)
internal/admin/handler.go:1041-1041 (data_classification)
internal/agent/tool/exesql.go:110-110 (data_classification)
internal/handler/user.go:586-586 (data_classification)
Critical
PCI_REQ_3_7_3 — Implement Key Management for Secure Storage
Code Improvement Recommended
Satisfied: Data Classification
Missing: Access Control, Encryption At Rest, Encryption In Transit, Key Management
common/data_source/models.py:128-128 (data_classification)
internal/service/tenant.go:902-902 (data_classification)
internal/service/tenant.go:104-104 (data_classification)
internal/service/agent_dbcheck.go:44-44 (data_classification)
web/src/pages/user-setting/profile/hooks/use-profile.ts:17-17 (data_classification)
internal/service/tenant.go:858-858 (data_classification)
internal/admin/handler_ee.go:828-828 (data_classification)
internal/dao/user_tenant.go:132-132 (data_classification)
internal/service/user.go:74-74 (data_classification)
web/src/pages/admin/forms/change-password-form.tsx:24-24 (data_classification)
internal/admin/handler_ee.go:1726-1726 (data_classification)
internal/agent/tool/pubmed.go:57-57 (data_classification)
internal/service/user.go:91-91 (data_classification)
internal/admin/handler.go:246-246 (data_classification)
web/src/pages/admin/forms/email-form.tsx:17-17 (data_classification)
internal/service/user.go:98-98 (data_classification)
internal/admin/handler_ee.go:1780-1780 (data_classification)
internal/service/user.go:1320-1320 (data_classification)
internal/service/user.go:69-69 (data_classification)
internal/service/tenant.go:909-909 (data_classification)
internal/admin/handler.go:1010-1010 (data_classification)
internal/server/config.go:72-72 (data_classification)
internal/handler/user.go:624-624 (data_classification)
internal/agent/sandbox/ssh.go:83-83 (data_classification)
internal/utility/oauth/client.go:64-64 (data_classification)
common/data_source/interfaces.py:371-371 (data_classification)
internal/service/user.go:61-61 (data_classification)
internal/agent/tool/email.go:51-51 (data_classification)
internal/entity/user.go:26-26 (data_classification)
web/src/pages/admin/forms/user-form.tsx:32-32 (data_classification)
internal/dao/user_tenant.go:120-120 (data_classification)
internal/handler/user.go:655-655 (data_classification)
internal/service/user.go:85-85 (data_classification)
internal/admin/handler.go:1078-1078 (data_classification)
internal/cli/cli.go:53-53 (data_classification)
internal/admin/handler.go:1041-1041 (data_classification)
internal/agent/tool/exesql.go:110-110 (data_classification)
internal/handler/user.go:586-586 (data_classification)
Critical
PCI_REQ_4_2_1 — Implement Strong Cryptography and Security Protocols for PAN Transmission
Code Improvement Recommended
Satisfied: Data Classification
Missing: Access Control, Encryption At Rest, Encryption In Transit, Key Management
common/data_source/models.py:128-128 (data_classification)
internal/service/tenant.go:902-902 (data_classification)
internal/service/tenant.go:104-104 (data_classification)
internal/service/agent_dbcheck.go:44-44 (data_classification)
web/src/pages/user-setting/profile/hooks/use-profile.ts:17-17 (data_classification)
internal/service/tenant.go:858-858 (data_classification)
internal/admin/handler_ee.go:828-828 (data_classification)
internal/dao/user_tenant.go:132-132 (data_classification)
internal/service/user.go:74-74 (data_classification)
web/src/pages/admin/forms/change-password-form.tsx:24-24 (data_classification)
internal/admin/handler_ee.go:1726-1726 (data_classification)
internal/agent/tool/pubmed.go:57-57 (data_classification)
internal/service/user.go:91-91 (data_classification)
internal/admin/handler.go:246-246 (data_classification)
web/src/pages/admin/forms/email-form.tsx:17-17 (data_classification)
internal/service/user.go:98-98 (data_classification)
internal/admin/handler_ee.go:1780-1780 (data_classification)
internal/service/user.go:1320-1320 (data_classification)
internal/service/user.go:69-69 (data_classification)
internal/service/tenant.go:909-909 (data_classification)
internal/admin/handler.go:1010-1010 (data_classification)
internal/server/config.go:72-72 (data_classification)
internal/handler/user.go:624-624 (data_classification)
internal/agent/sandbox/ssh.go:83-83 (data_classification)
internal/utility/oauth/client.go:64-64 (data_classification)
common/data_source/interfaces.py:371-371 (data_classification)
internal/service/user.go:61-61 (data_classification)
internal/agent/tool/email.go:51-51 (data_classification)
internal/entity/user.go:26-26 (data_classification)
web/src/pages/admin/forms/user-form.tsx:32-32 (data_classification)
internal/dao/user_tenant.go:120-120 (data_classification)
internal/handler/user.go:655-655 (data_classification)
internal/service/user.go:85-85 (data_classification)
internal/admin/handler.go:1078-1078 (data_classification)
internal/cli/cli.go:53-53 (data_classification)
internal/admin/handler.go:1041-1041 (data_classification)
internal/agent/tool/exesql.go:110-110 (data_classification)
internal/handler/user.go:586-586 (data_classification)
Critical
SOC2_CC6_6 — External Threat Protection
Code Improvement Recommended
Satisfied: Data Classification
Missing: Access Control, Audit Logging, Encryption At Rest, Encryption In Transit, Key Management
common/data_source/models.py:128-128 (data_classification)
internal/service/tenant.go:902-902 (data_classification)
internal/service/tenant.go:104-104 (data_classification)
internal/service/agent_dbcheck.go:44-44 (data_classification)
web/src/pages/user-setting/profile/hooks/use-profile.ts:17-17 (data_classification)
internal/service/tenant.go:858-858 (data_classification)
internal/admin/handler_ee.go:828-828 (data_classification)
internal/dao/user_tenant.go:132-132 (data_classification)
internal/service/user.go:74-74 (data_classification)
web/src/pages/admin/forms/change-password-form.tsx:24-24 (data_classification)
internal/admin/handler_ee.go:1726-1726 (data_classification)
internal/agent/tool/pubmed.go:57-57 (data_classification)
internal/service/user.go:91-91 (data_classification)
internal/admin/handler.go:246-246 (data_classification)
web/src/pages/admin/forms/email-form.tsx:17-17 (data_classification)
internal/service/user.go:98-98 (data_classification)
internal/admin/handler_ee.go:1780-1780 (data_classification)
internal/service/user.go:1320-1320 (data_classification)
internal/service/user.go:69-69 (data_classification)
internal/service/tenant.go:909-909 (data_classification)
internal/admin/handler.go:1010-1010 (data_classification)
internal/server/config.go:72-72 (data_classification)
internal/handler/user.go:624-624 (data_classification)
internal/agent/sandbox/ssh.go:83-83 (data_classification)
internal/utility/oauth/client.go:64-64 (data_classification)
common/data_source/interfaces.py:371-371 (data_classification)
internal/service/user.go:61-61 (data_classification)
internal/agent/tool/email.go:51-51 (data_classification)
internal/entity/user.go:26-26 (data_classification)
web/src/pages/admin/forms/user-form.tsx:32-32 (data_classification)
internal/dao/user_tenant.go:120-120 (data_classification)
internal/handler/user.go:655-655 (data_classification)
internal/service/user.go:85-85 (data_classification)
internal/admin/handler.go:1078-1078 (data_classification)
internal/cli/cli.go:53-53 (data_classification)
internal/admin/handler.go:1041-1041 (data_classification)
internal/agent/tool/exesql.go:110-110 (data_classification)
internal/handler/user.go:586-586 (data_classification)
Critical
SOC2_CC6_8 — Unauthorized and Malicious Software Control
Code Improvement Recommended
Satisfied: Data Classification
Missing: Access Control, Audit Logging, Encryption At Rest, Encryption In Transit, Key Management
common/data_source/models.py:128-128 (data_classification)
internal/service/tenant.go:902-902 (data_classification)
internal/service/tenant.go:104-104 (data_classification)
internal/service/agent_dbcheck.go:44-44 (data_classification)
web/src/pages/user-setting/profile/hooks/use-profile.ts:17-17 (data_classification)
internal/service/tenant.go:858-858 (data_classification)
internal/admin/handler_ee.go:828-828 (data_classification)
internal/dao/user_tenant.go:132-132 (data_classification)
internal/service/user.go:74-74 (data_classification)
web/src/pages/admin/forms/change-password-form.tsx:24-24 (data_classification)
internal/admin/handler_ee.go:1726-1726 (data_classification)
internal/agent/tool/pubmed.go:57-57 (data_classification)
internal/service/user.go:91-91 (data_classification)
internal/admin/handler.go:246-246 (data_classification)
web/src/pages/admin/forms/email-form.tsx:17-17 (data_classification)
internal/service/user.go:98-98 (data_classification)
internal/admin/handler_ee.go:1780-1780 (data_classification)
internal/service/user.go:1320-1320 (data_classification)
internal/service/user.go:69-69 (data_classification)
internal/service/tenant.go:909-909 (data_classification)
internal/admin/handler.go:1010-1010 (data_classification)
internal/server/config.go:72-72 (data_classification)
internal/handler/user.go:624-624 (data_classification)
internal/agent/sandbox/ssh.go:83-83 (data_classification)
internal/utility/oauth/client.go:64-64 (data_classification)
common/data_source/interfaces.py:371-371 (data_classification)
internal/service/user.go:61-61 (data_classification)
internal/agent/tool/email.go:51-51 (data_classification)
internal/entity/user.go:26-26 (data_classification)
web/src/pages/admin/forms/user-form.tsx:32-32 (data_classification)
internal/dao/user_tenant.go:120-120 (data_classification)
internal/handler/user.go:655-655 (data_classification)
internal/service/user.go:85-85 (data_classification)
internal/admin/handler.go:1078-1078 (data_classification)
internal/cli/cli.go:53-53 (data_classification)
internal/admin/handler.go:1041-1041 (data_classification)
internal/agent/tool/exesql.go:110-110 (data_classification)
internal/handler/user.go:586-586 (data_classification)
Critical
PCI_REQ_10_2_1_2 — Audit Logs Capture All Actions by Individuals with Administrative Access
Code Improvement Recommended
Satisfied: Authentication
Missing: Access Control, Audit Logging
admin/server/services.py:122-122 (authentication)
api/apps/restful_apis/user_api.py:337-337 (authentication)
api/db/services/user_service.py:99-99 (authentication)
api/apps/auth/oidc.py:134-140 (authentication)
Critical
PCI_REQ_10_2_1_3 — Audit Logs Capture All Access to Audit Logs
Code Improvement Recommended
Satisfied: Authentication
Missing: Access Control, Audit Logging
admin/server/services.py:122-122 (authentication)
api/apps/restful_apis/user_api.py:337-337 (authentication)
api/db/services/user_service.py:99-99 (authentication)
api/apps/auth/oidc.py:134-140 (authentication)
Critical
PCI_REQ_10_2_1_5 — Audit Logs Capture All Changes to Identification and Authentication Credentials
Code Improvement Recommended
Satisfied: Authentication
Missing: Access Control, Audit Logging
admin/server/services.py:122-122 (authentication)
api/apps/restful_apis/user_api.py:337-337 (authentication)
api/db/services/user_service.py:99-99 (authentication)
api/apps/auth/oidc.py:134-140 (authentication)
Critical
PCI_REQ_3_2_1 — Implement Data Retention and Disposal Policies to Minimize Account Data Storage
Code Improvement Recommended
Satisfied: Data Classification, Data Lifecycle Management
Missing: Access Control, Data Retention, Encryption At Rest, Encryption In Transit, Key Management
common/data_source/models.py:128-128 (data_classification)
internal/service/tenant.go:902-902 (data_classification)
internal/service/tenant.go:104-104 (data_classification)
internal/service/agent_dbcheck.go:44-44 (data_classification)
web/src/pages/user-setting/profile/hooks/use-profile.ts:17-17 (data_classification)
internal/service/tenant.go:858-858 (data_classification)
internal/admin/handler_ee.go:828-828 (data_classification)
internal/dao/user_tenant.go:132-132 (data_classification)
internal/agent/sandbox/ssh.go:83-83 (data_minimization_module_fanin)
internal/admin/handler_ee.go:828-828 (data_minimization_module_fanin)
internal/admin/handler.go:246-246 (data_minimization_module_fanin)
internal/service/user.go:74-74 (data_classification)
web/src/pages/admin/forms/change-password-form.tsx:24-24 (data_classification)
internal/admin/handler_ee.go:1726-1726 (data_classification)
internal/agent/tool/pubmed.go:57-57 (data_classification)
internal/service/user.go:91-91 (data_classification)
internal/admin/handler.go:246-246 (data_classification)
web/src/pages/admin/forms/email-form.tsx:17-17 (data_classification)
internal/service/user.go:98-98 (data_classification)
internal/admin/handler_ee.go:1780-1780 (data_classification)
internal/service/user.go:1320-1320 (data_classification)
internal/service/user.go:69-69 (data_classification)
internal/service/tenant.go:909-909 (data_classification)
internal/admin/handler.go:1010-1010 (data_classification)
internal/server/config.go:72-72 (data_classification)
internal/handler/user.go:624-624 (data_classification)
internal/agent/sandbox/ssh.go:83-83 (data_classification)
internal/utility/oauth/client.go:64-64 (data_minimization_module_fanin)
internal/cli/cli.go:53-53 (data_minimization_module_fanin)
internal/utility/oauth/client.go:64-64 (data_classification)
web/src/pages/user-setting/profile/hooks/use-profile.ts:17-17 (data_minimization_module_fanin)
web/src/pages/admin/forms/email-form.tsx:17-17 (data_minimization_module_fanin)
common/data_source/interfaces.py:371-371 (data_classification)
internal/service/user.go:61-61 (data_classification)
internal/agent/tool/email.go:51-51 (data_classification)
internal/entity/user.go:26-26 (data_classification)
web/src/pages/admin/forms/user-form.tsx:32-32 (data_classification)
web/src/pages/admin/forms/user-form.tsx:32-32 (data_minimization_module_fanin)
internal/dao/user_tenant.go:120-120 (data_classification)
internal/handler/user.go:655-655 (data_classification)
internal/service/user.go:85-85 (data_classification)
web/src/pages/admin/forms/change-password-form.tsx:24-24 (data_minimization_module_fanin)
internal/admin/handler.go:1078-1078 (data_classification)
internal/cli/cli.go:53-53 (data_classification)
internal/admin/handler.go:1041-1041 (data_classification)
internal/agent/tool/exesql.go:110-110 (data_classification)
internal/handler/user.go:586-586 (data_classification)
Critical
PCI_REQ_3_3_1 — Do Not Store Sensitive Authentication Data After Authorization
Code Improvement Recommended
Satisfied: Data Classification, Data Lifecycle Management
Missing: Access Control, Encryption At Rest, Encryption In Transit, Key Management
common/data_source/models.py:128-128 (data_classification)
internal/service/tenant.go:902-902 (data_classification)
internal/service/tenant.go:104-104 (data_classification)
internal/service/agent_dbcheck.go:44-44 (data_classification)
web/src/pages/user-setting/profile/hooks/use-profile.ts:17-17 (data_classification)
internal/service/tenant.go:858-858 (data_classification)
internal/admin/handler_ee.go:828-828 (data_classification)
internal/dao/user_tenant.go:132-132 (data_classification)
internal/agent/sandbox/ssh.go:83-83 (data_minimization_module_fanin)
internal/admin/handler_ee.go:828-828 (data_minimization_module_fanin)
internal/admin/handler.go:246-246 (data_minimization_module_fanin)
internal/service/user.go:74-74 (data_classification)
web/src/pages/admin/forms/change-password-form.tsx:24-24 (data_classification)
internal/admin/handler_ee.go:1726-1726 (data_classification)
internal/agent/tool/pubmed.go:57-57 (data_classification)
internal/service/user.go:91-91 (data_classification)
internal/admin/handler.go:246-246 (data_classification)
web/src/pages/admin/forms/email-form.tsx:17-17 (data_classification)
internal/service/user.go:98-98 (data_classification)
internal/admin/handler_ee.go:1780-1780 (data_classification)
internal/service/user.go:1320-1320 (data_classification)
internal/service/user.go:69-69 (data_classification)
internal/service/tenant.go:909-909 (data_classification)
internal/admin/handler.go:1010-1010 (data_classification)
internal/server/config.go:72-72 (data_classification)
internal/handler/user.go:624-624 (data_classification)
internal/agent/sandbox/ssh.go:83-83 (data_classification)
internal/utility/oauth/client.go:64-64 (data_minimization_module_fanin)
internal/cli/cli.go:53-53 (data_minimization_module_fanin)
internal/utility/oauth/client.go:64-64 (data_classification)
web/src/pages/user-setting/profile/hooks/use-profile.ts:17-17 (data_minimization_module_fanin)
web/src/pages/admin/forms/email-form.tsx:17-17 (data_minimization_module_fanin)
common/data_source/interfaces.py:371-371 (data_classification)
internal/service/user.go:61-61 (data_classification)
internal/agent/tool/email.go:51-51 (data_classification)
internal/entity/user.go:26-26 (data_classification)
web/src/pages/admin/forms/user-form.tsx:32-32 (data_classification)
web/src/pages/admin/forms/user-form.tsx:32-32 (data_minimization_module_fanin)
internal/dao/user_tenant.go:120-120 (data_classification)
internal/handler/user.go:655-655 (data_classification)
internal/service/user.go:85-85 (data_classification)
web/src/pages/admin/forms/change-password-form.tsx:24-24 (data_minimization_module_fanin)
internal/admin/handler.go:1078-1078 (data_classification)
internal/cli/cli.go:53-53 (data_classification)
internal/admin/handler.go:1041-1041 (data_classification)
internal/agent/tool/exesql.go:110-110 (data_classification)
internal/handler/user.go:586-586 (data_classification)
Critical
PCI_REQ_3_3_1_1 — Do Not Store Full Track Data After Authorization
Code Improvement Recommended
Satisfied: Data Classification, Data Lifecycle Management
Missing: Access Control, Encryption At Rest, Encryption In Transit, Key Management
common/data_source/models.py:128-128 (data_classification)
internal/service/tenant.go:902-902 (data_classification)
internal/service/tenant.go:104-104 (data_classification)
internal/service/agent_dbcheck.go:44-44 (data_classification)
web/src/pages/user-setting/profile/hooks/use-profile.ts:17-17 (data_classification)
internal/service/tenant.go:858-858 (data_classification)
internal/admin/handler_ee.go:828-828 (data_classification)
internal/dao/user_tenant.go:132-132 (data_classification)
internal/agent/sandbox/ssh.go:83-83 (data_minimization_module_fanin)
internal/admin/handler_ee.go:828-828 (data_minimization_module_fanin)
internal/admin/handler.go:246-246 (data_minimization_module_fanin)
internal/service/user.go:74-74 (data_classification)
web/src/pages/admin/forms/change-password-form.tsx:24-24 (data_classification)
internal/admin/handler_ee.go:1726-1726 (data_classification)
internal/agent/tool/pubmed.go:57-57 (data_classification)
internal/service/user.go:91-91 (data_classification)
internal/admin/handler.go:246-246 (data_classification)
web/src/pages/admin/forms/email-form.tsx:17-17 (data_classification)
internal/service/user.go:98-98 (data_classification)
internal/admin/handler_ee.go:1780-1780 (data_classification)
internal/service/user.go:1320-1320 (data_classification)
internal/service/user.go:69-69 (data_classification)
internal/service/tenant.go:909-909 (data_classification)
internal/admin/handler.go:1010-1010 (data_classification)
internal/server/config.go:72-72 (data_classification)
internal/handler/user.go:624-624 (data_classification)
internal/agent/sandbox/ssh.go:83-83 (data_classification)
internal/utility/oauth/client.go:64-64 (data_minimization_module_fanin)
internal/cli/cli.go:53-53 (data_minimization_module_fanin)
internal/utility/oauth/client.go:64-64 (data_classification)
web/src/pages/user-setting/profile/hooks/use-profile.ts:17-17 (data_minimization_module_fanin)
web/src/pages/admin/forms/email-form.tsx:17-17 (data_minimization_module_fanin)
common/data_source/interfaces.py:371-371 (data_classification)
internal/service/user.go:61-61 (data_classification)
internal/agent/tool/email.go:51-51 (data_classification)
internal/entity/user.go:26-26 (data_classification)
web/src/pages/admin/forms/user-form.tsx:32-32 (data_classification)
web/src/pages/admin/forms/user-form.tsx:32-32 (data_minimization_module_fanin)
internal/dao/user_tenant.go:120-120 (data_classification)
internal/handler/user.go:655-655 (data_classification)
internal/service/user.go:85-85 (data_classification)
web/src/pages/admin/forms/change-password-form.tsx:24-24 (data_minimization_module_fanin)
internal/admin/handler.go:1078-1078 (data_classification)
internal/cli/cli.go:53-53 (data_classification)
internal/admin/handler.go:1041-1041 (data_classification)
internal/agent/tool/exesql.go:110-110 (data_classification)
internal/handler/user.go:586-586 (data_classification)
Critical
PCI_REQ_3_3_1_2 — Do Not Store Card Verification Code After Authorization
Code Improvement Recommended
Satisfied: Data Classification, Data Lifecycle Management
Missing: Access Control, Encryption At Rest, Encryption In Transit, Key Management
common/data_source/models.py:128-128 (data_classification)
internal/service/tenant.go:902-902 (data_classification)
internal/service/tenant.go:104-104 (data_classification)
internal/service/agent_dbcheck.go:44-44 (data_classification)
web/src/pages/user-setting/profile/hooks/use-profile.ts:17-17 (data_classification)
internal/service/tenant.go:858-858 (data_classification)
internal/admin/handler_ee.go:828-828 (data_classification)
internal/dao/user_tenant.go:132-132 (data_classification)
internal/agent/sandbox/ssh.go:83-83 (data_minimization_module_fanin)
internal/admin/handler_ee.go:828-828 (data_minimization_module_fanin)
internal/admin/handler.go:246-246 (data_minimization_module_fanin)
internal/service/user.go:74-74 (data_classification)
web/src/pages/admin/forms/change-password-form.tsx:24-24 (data_classification)
internal/admin/handler_ee.go:1726-1726 (data_classification)
internal/agent/tool/pubmed.go:57-57 (data_classification)
internal/service/user.go:91-91 (data_classification)
internal/admin/handler.go:246-246 (data_classification)
web/src/pages/admin/forms/email-form.tsx:17-17 (data_classification)
internal/service/user.go:98-98 (data_classification)
internal/admin/handler_ee.go:1780-1780 (data_classification)
internal/service/user.go:1320-1320 (data_classification)
internal/service/user.go:69-69 (data_classification)
internal/service/tenant.go:909-909 (data_classification)
internal/admin/handler.go:1010-1010 (data_classification)
internal/server/config.go:72-72 (data_classification)
internal/handler/user.go:624-624 (data_classification)
internal/agent/sandbox/ssh.go:83-83 (data_classification)
internal/utility/oauth/client.go:64-64 (data_minimization_module_fanin)
internal/cli/cli.go:53-53 (data_minimization_module_fanin)
internal/utility/oauth/client.go:64-64 (data_classification)
web/src/pages/user-setting/profile/hooks/use-profile.ts:17-17 (data_minimization_module_fanin)
web/src/pages/admin/forms/email-form.tsx:17-17 (data_minimization_module_fanin)
common/data_source/interfaces.py:371-371 (data_classification)
internal/service/user.go:61-61 (data_classification)
internal/agent/tool/email.go:51-51 (data_classification)
internal/entity/user.go:26-26 (data_classification)
web/src/pages/admin/forms/user-form.tsx:32-32 (data_classification)
web/src/pages/admin/forms/user-form.tsx:32-32 (data_minimization_module_fanin)
internal/dao/user_tenant.go:120-120 (data_classification)
internal/handler/user.go:655-655 (data_classification)
internal/service/user.go:85-85 (data_classification)
web/src/pages/admin/forms/change-password-form.tsx:24-24 (data_minimization_module_fanin)
internal/admin/handler.go:1078-1078 (data_classification)
internal/cli/cli.go:53-53 (data_classification)
internal/admin/handler.go:1041-1041 (data_classification)
internal/agent/tool/exesql.go:110-110 (data_classification)
internal/handler/user.go:586-586 (data_classification)
Critical
PCI_REQ_3_3_1_3 — Do Not Store PIN or PIN Block After Authorization
Code Improvement Recommended
Satisfied: Data Classification, Data Lifecycle Management
Missing: Access Control, Encryption At Rest, Encryption In Transit, Key Management
common/data_source/models.py:128-128 (data_classification)
internal/service/tenant.go:902-902 (data_classification)
internal/service/tenant.go:104-104 (data_classification)
internal/service/agent_dbcheck.go:44-44 (data_classification)
web/src/pages/user-setting/profile/hooks/use-profile.ts:17-17 (data_classification)
internal/service/tenant.go:858-858 (data_classification)
internal/admin/handler_ee.go:828-828 (data_classification)
internal/dao/user_tenant.go:132-132 (data_classification)
internal/agent/sandbox/ssh.go:83-83 (data_minimization_module_fanin)
internal/admin/handler_ee.go:828-828 (data_minimization_module_fanin)
internal/admin/handler.go:246-246 (data_minimization_module_fanin)
internal/service/user.go:74-74 (data_classification)
web/src/pages/admin/forms/change-password-form.tsx:24-24 (data_classification)
internal/admin/handler_ee.go:1726-1726 (data_classification)
internal/agent/tool/pubmed.go:57-57 (data_classification)
internal/service/user.go:91-91 (data_classification)
internal/admin/handler.go:246-246 (data_classification)
web/src/pages/admin/forms/email-form.tsx:17-17 (data_classification)
internal/service/user.go:98-98 (data_classification)
internal/admin/handler_ee.go:1780-1780 (data_classification)
internal/service/user.go:1320-1320 (data_classification)
internal/service/user.go:69-69 (data_classification)
internal/service/tenant.go:909-909 (data_classification)
internal/admin/handler.go:1010-1010 (data_classification)
internal/server/config.go:72-72 (data_classification)
internal/handler/user.go:624-624 (data_classification)
internal/agent/sandbox/ssh.go:83-83 (data_classification)
internal/utility/oauth/client.go:64-64 (data_minimization_module_fanin)
internal/cli/cli.go:53-53 (data_minimization_module_fanin)
internal/utility/oauth/client.go:64-64 (data_classification)
web/src/pages/user-setting/profile/hooks/use-profile.ts:17-17 (data_minimization_module_fanin)
web/src/pages/admin/forms/email-form.tsx:17-17 (data_minimization_module_fanin)
common/data_source/interfaces.py:371-371 (data_classification)
internal/service/user.go:61-61 (data_classification)
internal/agent/tool/email.go:51-51 (data_classification)
internal/entity/user.go:26-26 (data_classification)
web/src/pages/admin/forms/user-form.tsx:32-32 (data_classification)
web/src/pages/admin/forms/user-form.tsx:32-32 (data_minimization_module_fanin)
internal/dao/user_tenant.go:120-120 (data_classification)
internal/handler/user.go:655-655 (data_classification)
internal/service/user.go:85-85 (data_classification)
web/src/pages/admin/forms/change-password-form.tsx:24-24 (data_minimization_module_fanin)
internal/admin/handler.go:1078-1078 (data_classification)
internal/cli/cli.go:53-53 (data_classification)
internal/admin/handler.go:1041-1041 (data_classification)
internal/agent/tool/exesql.go:110-110 (data_classification)
internal/handler/user.go:586-586 (data_classification)
Critical
EU_AI_ART_5_001 — Prohibition of Subliminal Manipulative Techniques
Code Improvement Recommended
Missing: Consent Management
Critical
EU_AI_ART_5_002 — Prohibition of Exploiting Vulnerabilities
Code Improvement Recommended
Missing: Consent Management
Critical
EU_AI_ART_5_003 — Prohibition of Social Scoring
Code Improvement Recommended
Missing: Consent Management
Critical
EU_AI_ART_5_004 — Prohibition of Predictive Policing Risk Assessments Based Solely on Profiling
Code Improvement Recommended
Missing: Consent Management
Critical
EU_AI_ART_5_006 — Prohibition of Emotion Recognition in Workplace and Education
Code Improvement Recommended
Missing: Consent Management
Critical
EU_AI_ART_5_007 — Prohibition of Biometric Categorisation for Sensitive Characteristics
Code Improvement Recommended
Missing: Consent Management
Critical
EU_AI_ART_5_008 — Restrictions on Real-Time Remote Biometric Identification for Law Enforcement
Code Improvement Recommended
Missing: Consent Management
Critical
GDPR_ART_28_001 — Processor - Selection and Guarantees
Code Improvement Recommended
Missing: Access Control
Critical
GDPR_ART_58_002 — Supervisory Authority - Corrective Powers
Code Improvement Recommended
Missing: Audit Logging
Critical
GDPR_ART_5_001 — Lawfulness, Fairness and Transparency
Code Improvement Recommended
Missing: Consent Management
Critical
GDPR_ART_6_001 — Lawful Processing - Consent
Code Improvement Recommended
Missing: Consent Management
Critical
GDPR_ART_7_001 — Demonstration of Consent
Code Improvement Recommended
Missing: Consent Management
Critical
GDPR_ART_83_001 — Administrative Fines - General Conditions
Code Improvement Recommended
Missing: Audit Logging
Critical
HIPAA_308_A6_001 — Security Incident Procedures -- Response and Reporting
Code Improvement Recommended
Missing: Audit Logging
Critical
PCI_REQ_10_2_1 — Enable and Activate Audit Logs for All System Components
Code Improvement Recommended
Missing: Audit Logging
Critical
PCI_REQ_10_2_1_1 — Audit Logs Capture All Individual User Access to Cardholder Data
Code Improvement Recommended
Missing: Audit Logging
Critical
PCI_REQ_10_2_1_6 — Audit Logs Capture Initialization, Starting, Stopping, or Pausing of Audit Logs
Code Improvement Recommended
Missing: Audit Logging
Critical
PCI_REQ_10_2_2 — Audit Logs Record Specific Details for Each Auditable Event
Code Improvement Recommended
Missing: Audit Logging
Critical
PCI_REQ_10_3_2 — Protect Audit Logs from Modification
Code Improvement Recommended
Missing: Audit Logging
Critical
PCI_REQ_10_4_1 — Review Security Events and Logs of Critical Systems Daily
Code Improvement Recommended
Missing: Audit Logging
Critical
PCI_REQ_11_3_1 — Perform Internal Vulnerability Scans Quarterly and Resolve High-Risk/Critical Vulnerabilities
Code Improvement Recommended
Missing: Audit Logging
Critical
PCI_REQ_11_3_2 — Perform External Vulnerability Scans Quarterly by ASV and Pass
Code Improvement Recommended
Missing: Audit Logging
Critical
PCI_REQ_11_4_4 — Correct Exploitable Vulnerabilities and Security Weaknesses from Penetration Testing
Code Improvement Recommended
Missing: Audit Logging
Critical
PCI_REQ_11_5_1 — Deploy Intrusion-Detection/Prevention Techniques at CDE Perimeter and Critical Points
Code Improvement Recommended
Missing: Audit Logging
Critical
PCI_REQ_12_10_1 — Maintain Incident Response Plan with Required Elements
Code Improvement Recommended
Missing: Audit Logging
Critical
PCI_REQ_5_2_1 — Deploy Anti-Malware Solution on All System Components Except Those Evaluated Not at Risk
Code Improvement Recommended
Missing: Audit Logging
Critical
PCI_REQ_5_2_2 — Ensure Anti-Malware Detects, Removes, Blocks, or Contains All Known Malware
Code Improvement Recommended
Missing: Audit Logging
Critical
SOC2_CC7_3 — Security Event Evaluation
Code Improvement Recommended
Missing: Audit Logging
Critical
SOC2_CC7_4 — Incident Response Program Execution
Code Improvement Recommended
Missing: Audit Logging
Critical
SOC2_P6_6 — Notification of Breaches and Incidents
Code Improvement Recommended
Missing: Audit Logging, Consent Management
High
PCI_APP_A3_2_5_2 — DESV: Implement Response Procedures for Cleartext PAN Outside CDE
Code Improvement Recommended
Satisfied: Data Classification
Missing: Access Control, Audit Logging, Encryption At Rest, Encryption In Transit, Key Management
common/data_source/models.py:128-128 (data_classification)
internal/service/tenant.go:902-902 (data_classification)
internal/service/tenant.go:104-104 (data_classification)
internal/service/agent_dbcheck.go:44-44 (data_classification)
web/src/pages/user-setting/profile/hooks/use-profile.ts:17-17 (data_classification)
internal/service/tenant.go:858-858 (data_classification)
internal/admin/handler_ee.go:828-828 (data_classification)
internal/dao/user_tenant.go:132-132 (data_classification)
internal/service/user.go:74-74 (data_classification)
web/src/pages/admin/forms/change-password-form.tsx:24-24 (data_classification)
internal/admin/handler_ee.go:1726-1726 (data_classification)
internal/agent/tool/pubmed.go:57-57 (data_classification)
internal/service/user.go:91-91 (data_classification)
internal/admin/handler.go:246-246 (data_classification)
web/src/pages/admin/forms/email-form.tsx:17-17 (data_classification)
internal/service/user.go:98-98 (data_classification)
internal/admin/handler_ee.go:1780-1780 (data_classification)
internal/service/user.go:1320-1320 (data_classification)
internal/service/user.go:69-69 (data_classification)
internal/service/tenant.go:909-909 (data_classification)
internal/admin/handler.go:1010-1010 (data_classification)
internal/server/config.go:72-72 (data_classification)
internal/handler/user.go:624-624 (data_classification)
internal/agent/sandbox/ssh.go:83-83 (data_classification)
internal/utility/oauth/client.go:64-64 (data_classification)
common/data_source/interfaces.py:371-371 (data_classification)
internal/service/user.go:61-61 (data_classification)
internal/agent/tool/email.go:51-51 (data_classification)
internal/entity/user.go:26-26 (data_classification)
web/src/pages/admin/forms/user-form.tsx:32-32 (data_classification)
internal/dao/user_tenant.go:120-120 (data_classification)
internal/handler/user.go:655-655 (data_classification)
internal/service/user.go:85-85 (data_classification)
internal/admin/handler.go:1078-1078 (data_classification)
internal/cli/cli.go:53-53 (data_classification)
internal/admin/handler.go:1041-1041 (data_classification)
internal/agent/tool/exesql.go:110-110 (data_classification)
internal/handler/user.go:586-586 (data_classification)
High
PCI_APP_A3_2_6 — DESV: Implement Mechanisms to Detect and Prevent Cleartext PAN Leaving CDE
Code Improvement Recommended
Satisfied: Data Classification
Missing: Access Control, Audit Logging, Encryption At Rest, Encryption In Transit, Key Management
common/data_source/models.py:128-128 (data_classification)
internal/service/tenant.go:902-902 (data_classification)
internal/service/tenant.go:104-104 (data_classification)
internal/service/agent_dbcheck.go:44-44 (data_classification)
web/src/pages/user-setting/profile/hooks/use-profile.ts:17-17 (data_classification)
internal/service/tenant.go:858-858 (data_classification)
internal/admin/handler_ee.go:828-828 (data_classification)
internal/dao/user_tenant.go:132-132 (data_classification)
internal/service/user.go:74-74 (data_classification)
web/src/pages/admin/forms/change-password-form.tsx:24-24 (data_classification)
internal/admin/handler_ee.go:1726-1726 (data_classification)
internal/agent/tool/pubmed.go:57-57 (data_classification)
internal/service/user.go:91-91 (data_classification)
internal/admin/handler.go:246-246 (data_classification)
web/src/pages/admin/forms/email-form.tsx:17-17 (data_classification)
internal/service/user.go:98-98 (data_classification)
internal/admin/handler_ee.go:1780-1780 (data_classification)
internal/service/user.go:1320-1320 (data_classification)
internal/service/user.go:69-69 (data_classification)
internal/service/tenant.go:909-909 (data_classification)
internal/admin/handler.go:1010-1010 (data_classification)
internal/server/config.go:72-72 (data_classification)
internal/handler/user.go:624-624 (data_classification)
internal/agent/sandbox/ssh.go:83-83 (data_classification)
internal/utility/oauth/client.go:64-64 (data_classification)
common/data_source/interfaces.py:371-371 (data_classification)
internal/service/user.go:61-61 (data_classification)
internal/agent/tool/email.go:51-51 (data_classification)
internal/entity/user.go:26-26 (data_classification)
web/src/pages/admin/forms/user-form.tsx:32-32 (data_classification)
internal/dao/user_tenant.go:120-120 (data_classification)
internal/handler/user.go:655-655 (data_classification)
internal/service/user.go:85-85 (data_classification)
internal/admin/handler.go:1078-1078 (data_classification)
internal/cli/cli.go:53-53 (data_classification)
internal/admin/handler.go:1041-1041 (data_classification)
internal/agent/tool/exesql.go:110-110 (data_classification)
internal/handler/user.go:586-586 (data_classification)
High
PCI_APP_A3_2_6_1 — DESV: Implement Response Procedures for Attempts to Remove Cleartext PAN
Code Improvement Recommended
Satisfied: Data Classification
Missing: Access Control, Audit Logging, Encryption At Rest, Encryption In Transit, Key Management
common/data_source/models.py:128-128 (data_classification)
internal/service/tenant.go:902-902 (data_classification)
internal/service/tenant.go:104-104 (data_classification)
internal/service/agent_dbcheck.go:44-44 (data_classification)
web/src/pages/user-setting/profile/hooks/use-profile.ts:17-17 (data_classification)
internal/service/tenant.go:858-858 (data_classification)
internal/admin/handler_ee.go:828-828 (data_classification)
internal/dao/user_tenant.go:132-132 (data_classification)
internal/service/user.go:74-74 (data_classification)
web/src/pages/admin/forms/change-password-form.tsx:24-24 (data_classification)
internal/admin/handler_ee.go:1726-1726 (data_classification)
internal/agent/tool/pubmed.go:57-57 (data_classification)
internal/service/user.go:91-91 (data_classification)
internal/admin/handler.go:246-246 (data_classification)
web/src/pages/admin/forms/email-form.tsx:17-17 (data_classification)
internal/service/user.go:98-98 (data_classification)
internal/admin/handler_ee.go:1780-1780 (data_classification)
internal/service/user.go:1320-1320 (data_classification)
internal/service/user.go:69-69 (data_classification)
internal/service/tenant.go:909-909 (data_classification)
internal/admin/handler.go:1010-1010 (data_classification)
internal/server/config.go:72-72 (data_classification)
internal/handler/user.go:624-624 (data_classification)
internal/agent/sandbox/ssh.go:83-83 (data_classification)
internal/utility/oauth/client.go:64-64 (data_classification)
common/data_source/interfaces.py:371-371 (data_classification)
internal/service/user.go:61-61 (data_classification)
internal/agent/tool/email.go:51-51 (data_classification)
internal/entity/user.go:26-26 (data_classification)
web/src/pages/admin/forms/user-form.tsx:32-32 (data_classification)
internal/dao/user_tenant.go:120-120 (data_classification)
internal/handler/user.go:655-655 (data_classification)
internal/service/user.go:85-85 (data_classification)
internal/admin/handler.go:1078-1078 (data_classification)
internal/cli/cli.go:53-53 (data_classification)
internal/admin/handler.go:1041-1041 (data_classification)
internal/agent/tool/exesql.go:110-110 (data_classification)
internal/handler/user.go:586-586 (data_classification)
High
PCI_REQ_12_10_7 — Establish Incident Response Procedures for Detected Stored PAN Outside Expected Location
Code Improvement Recommended
Satisfied: Data Classification
Missing: Access Control, Audit Logging, Encryption At Rest, Encryption In Transit, Key Management
common/data_source/models.py:128-128 (data_classification)
internal/service/tenant.go:902-902 (data_classification)
internal/service/tenant.go:104-104 (data_classification)
internal/service/agent_dbcheck.go:44-44 (data_classification)
web/src/pages/user-setting/profile/hooks/use-profile.ts:17-17 (data_classification)
internal/service/tenant.go:858-858 (data_classification)
internal/admin/handler_ee.go:828-828 (data_classification)
internal/dao/user_tenant.go:132-132 (data_classification)
internal/service/user.go:74-74 (data_classification)
web/src/pages/admin/forms/change-password-form.tsx:24-24 (data_classification)
internal/admin/handler_ee.go:1726-1726 (data_classification)
internal/agent/tool/pubmed.go:57-57 (data_classification)
internal/service/user.go:91-91 (data_classification)
internal/admin/handler.go:246-246 (data_classification)
web/src/pages/admin/forms/email-form.tsx:17-17 (data_classification)
internal/service/user.go:98-98 (data_classification)
internal/admin/handler_ee.go:1780-1780 (data_classification)
internal/service/user.go:1320-1320 (data_classification)
internal/service/user.go:69-69 (data_classification)
internal/service/tenant.go:909-909 (data_classification)
internal/admin/handler.go:1010-1010 (data_classification)
internal/server/config.go:72-72 (data_classification)
internal/handler/user.go:624-624 (data_classification)
internal/agent/sandbox/ssh.go:83-83 (data_classification)
internal/utility/oauth/client.go:64-64 (data_classification)
common/data_source/interfaces.py:371-371 (data_classification)
internal/service/user.go:61-61 (data_classification)
internal/agent/tool/email.go:51-51 (data_classification)
internal/entity/user.go:26-26 (data_classification)
web/src/pages/admin/forms/user-form.tsx:32-32 (data_classification)
internal/dao/user_tenant.go:120-120 (data_classification)
internal/handler/user.go:655-655 (data_classification)
internal/service/user.go:85-85 (data_classification)
internal/admin/handler.go:1078-1078 (data_classification)
internal/cli/cli.go:53-53 (data_classification)
internal/admin/handler.go:1041-1041 (data_classification)
internal/agent/tool/exesql.go:110-110 (data_classification)
internal/handler/user.go:586-586 (data_classification)
Control Mapping Appendix
Raw control-level mapping (control IDs, clause text) is intentionally not inlined here — export to JSON or SARIF for the complete, machine-readable control mapping.
Meridian - Deterministic + LLM-augmented compliance scan
4f1e276901da355805ab9e79