Meridian Compliance Report

supabase

Generated 23 July 2026, 05:19 UTC
Report d8f0d54b299a4f98afbe67e1
3 of 217 applicable controls automatically verified Deterministic, evidence-backed scan result
Meridian provides automated compliance assessments and recommendations, not legal advice. Final compliance determinations should be reviewed by qualified legal, compliance, or security professionals where required.
Meridian Compliance Report

supabase

Generated 23 July 2026, 05:19 UTC
Report d8f0d54b299a4f98afbe67e1
Meridian provides automated compliance assessments and recommendations, not legal advice. Final compliance determinations should be reviewed by qualified legal, compliance, or security professionals where required.

Executive Summary

Applicable Controls
217
Controls determined to apply to this repository
Implemented
3
Requires Documentation
84
Requires Operational Evidence
49
Code Improvement Recommended
81

Repository Overview

In ProductionTrue

Technology Stack

7503 files · 915657 lines

Languagesjavascript, jsx, python, tsx, typescript
FrameworksAngular, Next.js, React, Vue
CI/CD & IaCDocker, Docker Compose, GitHub Actions

Business Signals

Stores personal dataTrue
Uses AITrue
Primary jurisdictionUnited States
Processes paymentsFalse
Regulated financial entityFalse
Offers goods/services to the EUTrue
Monitors individuals in the EUFalse
Offers goods/services to IndiaFalse
AI roleProvider
AI output used in the EUTrue
High-risk AI use case indicatedFalse
General-purpose AI model providerFalse

What Meridian Understood

This repository represents a complex web-based software project utilizing a mix of modern JavaScript technologies including Angular, React, Vue, and Next.js to offer a rich interactive user experience. It interfaces with external APIs extensively and manages data securely using encryption and secrets management.

Architecture: Web application frontend and backend

Compliance Scope

Applicable Regulations

GDPRPrivacy & Data ProtectionStatutory law
Your application stores or processes personal data of individuals in the European Union.
Required: matched on stores_personal_data, offers_goods_services_to_eu.
In force since May 2018; applies extraterritorially to organizations offering goods or services to, or monitoring, individuals in the EU.
EU AI ActAI Governance & Responsible AIStatutory law
Your repository deploys AI models or AI-powered systems.
Required: matched on ai_usage.
In force since August 2024 with phased application — prohibited practices first, general-purpose AI and high-risk obligations phasing in later; verify current phase-in dates.
AI risk context: role: Provider; output used in the EU: yes; high-risk use case indicated: no; general-purpose model provider: no
SOC 2 Trust Services CriteriaTrust & AssuranceVoluntary attestation
Your application is in production and handles customer data requiring independent assurance.
Optional: base condition met, but no additional signal beyond production.
A voluntary attestation framework (AICPA Trust Services Criteria) driven by customer and contractual demand, not law.
NIST AI RMFAI Governance & Responsible AIVoluntary attestation
Your application develops, deploys, or uses AI/ML systems.
Required: matched on ai_usage.
AI RMF 1.0 released January 2023 by NIST; a voluntary risk-management framework, not a binding regulation -- adopted for market trust and structured AI governance, not because it is legally required.

Not Applicable Regulations

DPDPA 2023Privacy & Data Protection
Excluded: none of 'primary_jurisdiction', 'offers_goods_services_to_india' match the conditions required for this framework.
DPDPA Rules, 2025Privacy & Data Protection
Excluded: none of 'primary_jurisdiction', 'offers_goods_services_to_india' match the conditions required for this framework.
RBI FREE-AI FrameworkAI Governance & Responsible AI
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
SEBI AI/ML GuidelinesAI Governance & Responsible AI
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
RBI Digital Payment Security ControlsPayments & Financial Security
Excluded: 'processes_payments' does not match the condition required for this framework.
PCI DSSPayments & Financial Security
Excluded: 'processes_payments' does not match the condition required for this framework.
RBI IT Governance & Risk ControlsCybersecurity & Operational Security
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
RBI NBFC IT FrameworkFinancial Sector Regulations
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
RBI NBFC Outsourcing DirectionsFinancial Sector Regulations
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
RBI Outsourcing DirectionsFinancial Sector Regulations
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
RBI Payments Banks Outsourcing DirectionsFinancial Sector Regulations
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
RBI Small Finance Banks Outsourcing DirectionsFinancial Sector Regulations
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
SEBI Cybersecurity FrameworkCybersecurity & Operational Security
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
CERT-In DirectionsCybersecurity & Operational Security
Excluded: 'primary_jurisdiction' does not match the condition required for this framework.
HIPAA Security RulePrivacy & Data Protection
Excluded: 'handles_health_data' does not match the condition required for this framework.

Compliance Readiness

Implemented

Cross Border Transfer Controls Data Classification Data Lifecycle Management

Code Improvement Recommended

Access Control Audit Logging Authentication Consent Management Data Retention Encryption At Rest Encryption In Transit Key Management

Requires Documentation

Asset Inventory Backup And Recovery Business Impact Analysis Configuration Management Data Deletion Data Masking Data Protection Impact Assessment Data Subject Request Handling Grievance Redressal Incident Response Plan Information Security Policy Log Retention Policy Management Privacy Impact Assessment Records Of Processing

Requires Operational Evidence

AI Risk Assessment Access Review BCP And DR Testing Bias Detection Change Management Data Loss Prevention Data Quality Management Governance Framework Incident Detection Maker Checker Model Monitoring Model Testing Patch Management Penetration Testing Physical Access Control Privileged Access Management Regulatory Change Monitoring Regulatory Reporting SOC Operations Security Awareness Training Third Party Risk Assessment Vendor Contract Management Vulnerability Scanning

Enterprise Readiness

Recommended Improvements

Authentication Access Control Audit Logging Encryption At Rest Encryption In Transit Key Management Data Retention

Operational Requirements

Privileged Access Management BCP And DR Testing Penetration Testing Third Party Risk Assessment Vendor Contract Management Security Awareness Training

Documentation Required

Incident Response Plan Information Security Policy

SOC 2 Scope

The subset of the capabilities above that SOC 2's own controls actually reach.

Recommended Improvements

Authentication Access Control Audit Logging Encryption At Rest Encryption In Transit Key Management Data Retention

Operational Requirements

Privileged Access Management BCP And DR Testing Penetration Testing Third Party Risk Assessment Vendor Contract Management Security Awareness Training

Documentation Required

Incident Response Plan

AI Governance

Critical AI Findings
10
AI frameworksOpenAI SDK
AI infrastructurenone detected
Vector databasesnone detected
Notebooks4
AI regulations evaluatedEU Artificial Intelligence Act

Not mapped (no real control data available): ISO_42001, NIST_AI_RMF, OECD_AI_PRINCIPLES

Deployment Profile

Hosted LLM usage

AI Governance Posture

Replaces a bare AI maturity score with the actual capabilities checked.

Requires Operational Processes

Governance Framework AI Risk Assessment Model Monitoring Model Testing Bias Detection Maker Checker Penetration Testing

Code Improvement Recommended

Audit Logging

Top Priorities

  1. Access Control (CRITICAL) — Can the organization (as a non-EU controller/processor) demonstrate that it has designated a representative in the Union?
    Improves compliance posture for: GDPR, NIST AI RMF, SOC 2 Trust Services Criteria.
  2. Authentication (CRITICAL) — Can the organization demonstrate that it implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events?
    Improves compliance posture for: SOC 2 Trust Services Criteria.
  3. Encryption In Transit (CRITICAL) — Can the organization demonstrate that it implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events?
    Improves compliance posture for: SOC 2 Trust Services Criteria.
  4. Encryption At Rest (CRITICAL) — Can the organization demonstrate that it implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events?
    Improves compliance posture for: SOC 2 Trust Services Criteria.
  5. Key Management (CRITICAL) — Can the organization demonstrate that it implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events?
    Improves compliance posture for: SOC 2 Trust Services Criteria.

Full breakdown by effort below.

Recommended Actions

Quick Wins

  • Access Control (CRITICAL)
    Can the organization (as a non-EU controller/processor) demonstrate that it has designated a representative in the Union?
    Improves compliance posture for: GDPR, NIST AI RMF, SOC 2 Trust Services Criteria.
  • Authentication (CRITICAL)
    Can the organization demonstrate that it implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events?
    Improves compliance posture for: SOC 2 Trust Services Criteria.
  • Encryption In Transit (CRITICAL)
    Can the organization demonstrate that it implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events?
    Improves compliance posture for: SOC 2 Trust Services Criteria.
  • Encryption At Rest (CRITICAL)
    Can the organization demonstrate that it implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events?
    Improves compliance posture for: SOC 2 Trust Services Criteria.
  • Patch Management (HIGH)
    Can the organization demonstrate: aI system security and resilience -- as identified in the map function -- are evaluated and documented.
    Improves compliance posture for: NIST AI RMF.
  • Vulnerability Scanning (HIGH)
    Can the organization demonstrate: aI system security and resilience -- as identified in the map function -- are evaluated and documented.
    Improves compliance posture for: NIST AI RMF.

Medium Effort

  • Key Management (CRITICAL)
    Can the organization demonstrate that it implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events?
    Improves compliance posture for: SOC 2 Trust Services Criteria.
  • Privileged Access Management (HIGH)
    Can the organization demonstrate that it has taken measures to ensure a sufficient level of AI literacy among staff and others involved in the operation and use of AI systems?
    Improves compliance posture for: EU AI Act, GDPR, NIST AI RMF, SOC 2 Trust Services Criteria.
  • Consent Management (HIGH)
    Can the organization demonstrate that AI systems intended to interact with natural persons are designed to inform them they are interacting with an AI system?
    Improves compliance posture for: EU AI Act, GDPR, SOC 2 Trust Services Criteria.
  • Data Subject Request Handling (HIGH)
    Can the organization demonstrate that it has procedures to handle complaints regarding infringement of the AI Act?
    Improves compliance posture for: EU AI Act, NIST AI RMF.
  • Audit Logging (HIGH)
    Can the organization demonstrate that it has properly applied exceptions to breach communication to data subjects?
    Improves compliance posture for: GDPR, NIST AI RMF, SOC 2 Trust Services Criteria.
  • Backup And Recovery (HIGH)
    Can the organization demonstrate that it maintains, monitors, and evaluates current processing capacity and use of system components to manage capacity demand?
    Improves compliance posture for: SOC 2 Trust Services Criteria.
  • Incident Response Plan (HIGH)
    Can the organization demonstrate that it authorizes, designs, implements, maintains, and monitors environmental protections, backup processes, and recovery infrastructure?
    Improves compliance posture for: SOC 2 Trust Services Criteria.
  • Data Retention (HIGH)
    Can the organization demonstrate that it implements policies and procedures to store inputs, items in processing, and outputs completely, accurately, and timely in accordance with system specifications?
    Improves compliance posture for: SOC 2 Trust Services Criteria.
  • Model Testing (MEDIUM)
    Can the organization demonstrate that it has taken measures to ensure a sufficient level of AI literacy among staff and others involved in the operation and use of AI systems?
    Improves compliance posture for: EU AI Act, GDPR, NIST AI RMF.
  • Maker Checker (MEDIUM)
    Can the organization demonstrate that it has taken measures to ensure a sufficient level of AI literacy among staff and others involved in the operation and use of AI systems?
    Improves compliance posture for: EU AI Act, GDPR, NIST AI RMF, SOC 2 Trust Services Criteria.
  • Records Of Processing (MEDIUM)
    Can the organization (as a law enforcement authority) demonstrate that it notifies each use of real-time remote biometric identification to the relevant authorities and submits annual reports?
    Improves compliance posture for: EU AI Act, GDPR, NIST AI RMF, SOC 2 Trust Services Criteria.
  • Grievance Redressal (MEDIUM)
    Can the organization demonstrate that it has procedures to handle complaints regarding infringement of the AI Act?
    Improves compliance posture for: EU AI Act, NIST AI RMF.
  • Data Masking (MEDIUM)
    Can the organization demonstrate that processing of criminal conviction data is under official control or authorised by law with appropriate safeguards?
    Improves compliance posture for: GDPR, SOC 2 Trust Services Criteria.
  • Business Impact Analysis (MEDIUM)
    Can the organization demonstrate that it has assessed the risks to personal data when determining security measures?
    Improves compliance posture for: GDPR, SOC 2 Trust Services Criteria.
  • Data Lifecycle Management (MEDIUM)
    Can the organization demonstrate that it disposes of confidential information to meet its objectives related to confidentiality?
    Improves compliance posture for: SOC 2 Trust Services Criteria.
  • Data Classification (MEDIUM)
    Can the organization demonstrate that it implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events?
    Improves compliance posture for: SOC 2 Trust Services Criteria.
  • Security Awareness Training (LOW)
    Can the organization demonstrate that it has taken measures to ensure a sufficient level of AI literacy among staff and others involved in the operation and use of AI systems?
    Improves compliance posture for: EU AI Act, GDPR, NIST AI RMF, SOC 2 Trust Services Criteria.
  • Policy Management (LOW)
    Can the organization (as a law enforcement authority) demonstrate that it notifies each use of real-time remote biometric identification to the relevant authorities and submits annual reports?
    Improves compliance posture for: EU AI Act, GDPR, NIST AI RMF, SOC 2 Trust Services Criteria.
  • Data Quality Management (INFORMATIONAL)
    Can the organization demonstrate that it has taken measures to ensure a sufficient level of AI literacy among staff and others involved in the operation and use of AI systems?
    Improves compliance posture for: EU AI Act, GDPR, NIST AI RMF.

Strategic Initiatives

  • Bias Detection (HIGH)
    Can the organization demonstrate that it has taken measures to ensure a sufficient level of AI literacy among staff and others involved in the operation and use of AI systems?
    Improves compliance posture for: EU AI Act, GDPR, NIST AI RMF.
  • AI Risk Assessment (HIGH)
    Can the organization demonstrate that it has taken measures to ensure a sufficient level of AI literacy among staff and others involved in the operation and use of AI systems?
    Improves compliance posture for: EU AI Act, GDPR, NIST AI RMF, SOC 2 Trust Services Criteria.
  • Data Loss Prevention (HIGH)
    Can the organization demonstrate that it does not create or expand facial recognition databases through untargeted scraping?
    Improves compliance posture for: EU AI Act, GDPR.
  • Privacy Impact Assessment (HIGH)
    Can the organization demonstrate that it has assessed the risks to personal data when determining security measures?
    Improves compliance posture for: GDPR, SOC 2 Trust Services Criteria.
  • Data Protection Impact Assessment (HIGH)
    Can the organization demonstrate that it has assessed the risks to personal data when determining security measures?
    Improves compliance posture for: GDPR, SOC 2 Trust Services Criteria.
  • Penetration Testing (HIGH)
    Can the organization demonstrate: aI system security and resilience -- as identified in the map function -- are evaluated and documented.
    Improves compliance posture for: NIST AI RMF.
  • Model Monitoring (MEDIUM)
    Can the organization demonstrate that it has taken measures to ensure a sufficient level of AI literacy among staff and others involved in the operation and use of AI systems?
    Improves compliance posture for: EU AI Act, GDPR, NIST AI RMF.
  • Physical Access Control (MEDIUM)
    Can the organization demonstrate that it does not create or expand facial recognition databases through untargeted scraping?
    Improves compliance posture for: EU AI Act, GDPR.

Compliance Roadmap

Now · Quick Wins

  • Access Control
  • Authentication
  • Encryption In Transit
  • Encryption At Rest
  • Patch Management
  • Vulnerability Scanning

Next · Medium Effort

  • Key Management
  • Privileged Access Management
  • Consent Management
  • Data Subject Request Handling
  • Audit Logging
  • Backup And Recovery
  • Incident Response Plan
  • Data Retention
  • Model Testing
  • Maker Checker
  • Records Of Processing
  • Grievance Redressal
  • Data Masking
  • Business Impact Analysis
  • Data Lifecycle Management
  • Data Classification
  • Security Awareness Training
  • Policy Management
  • Data Quality Management

Later · Strategic Initiatives

  • Bias Detection
  • AI Risk Assessment
  • Data Loss Prevention
  • Privacy Impact Assessment
  • Data Protection Impact Assessment
  • Penetration Testing
  • Model Monitoring
  • Physical Access Control

Next Steps

Start with Top Priorities above, then work through the full Quick Wins/Medium Effort/Strategic Initiatives breakdown. Technical Findings below show exactly where each gap was detected in your repository; export to PDF/HTML for a shareable version, or JSON/SARIF to feed a CI pipeline.

Technical Findings (69)

Showing top 50 of 69, ranked by severity then confidence. Export to JSON or SARIF for the complete list.

Critical SOC2_CC6_1 — Logical Access Security Implementation Code Improvement Recommended
Satisfied: Data Classification
Missing: Access Control, Authentication, Encryption At Rest, Encryption In Transit, Key Management
apps/studio/components/ui/PasswordStrengthBar.tsx:9-9 (data_classification)
examples/user-management/ionic-angular-user-management/src/app/account/account.page.ts:18-18 (data_classification)
examples/user-management/ionic-angular-user-management/src/app/login/login.page.ts:11-11 (data_classification)
apps/www/lib/customerio.ts:22-22 (data_classification)
apps/www/lib/customerio.ts:6-6 (data_classification)
examples/_internal/fixtures/typescript.ts:6-6 (data_classification)
Critical SOC2_CC6_4 — Physical Access Restriction Code Improvement Recommended
Satisfied: Data Classification
Missing: Access Control, Authentication, Encryption At Rest, Encryption In Transit, Key Management
apps/studio/components/ui/PasswordStrengthBar.tsx:9-9 (data_classification)
examples/user-management/ionic-angular-user-management/src/app/account/account.page.ts:18-18 (data_classification)
examples/user-management/ionic-angular-user-management/src/app/login/login.page.ts:11-11 (data_classification)
apps/www/lib/customerio.ts:22-22 (data_classification)
apps/www/lib/customerio.ts:6-6 (data_classification)
examples/_internal/fixtures/typescript.ts:6-6 (data_classification)
Critical SOC2_CC6_6 — External Threat Protection Code Improvement Recommended
Satisfied: Data Classification
Missing: Access Control, Audit Logging, Encryption At Rest, Encryption In Transit, Key Management
apps/studio/components/ui/PasswordStrengthBar.tsx:9-9 (data_classification)
examples/user-management/ionic-angular-user-management/src/app/account/account.page.ts:18-18 (data_classification)
examples/user-management/ionic-angular-user-management/src/app/login/login.page.ts:11-11 (data_classification)
apps/www/lib/customerio.ts:22-22 (data_classification)
apps/www/lib/customerio.ts:6-6 (data_classification)
examples/_internal/fixtures/typescript.ts:6-6 (data_classification)
Critical SOC2_CC6_8 — Unauthorized and Malicious Software Control Code Improvement Recommended
Satisfied: Data Classification
Missing: Access Control, Audit Logging, Encryption At Rest, Encryption In Transit, Key Management
apps/studio/components/ui/PasswordStrengthBar.tsx:9-9 (data_classification)
examples/user-management/ionic-angular-user-management/src/app/account/account.page.ts:18-18 (data_classification)
examples/user-management/ionic-angular-user-management/src/app/login/login.page.ts:11-11 (data_classification)
apps/www/lib/customerio.ts:22-22 (data_classification)
apps/www/lib/customerio.ts:6-6 (data_classification)
examples/_internal/fixtures/typescript.ts:6-6 (data_classification)
Critical EU_AI_ART_5_001 — Prohibition of Subliminal Manipulative Techniques Code Improvement Recommended
Missing: Consent Management
Critical EU_AI_ART_5_002 — Prohibition of Exploiting Vulnerabilities Code Improvement Recommended
Missing: Consent Management
Critical EU_AI_ART_5_003 — Prohibition of Social Scoring Code Improvement Recommended
Missing: Consent Management
Critical EU_AI_ART_5_004 — Prohibition of Predictive Policing Risk Assessments Based Solely on Profiling Code Improvement Recommended
Missing: Consent Management
Critical EU_AI_ART_5_006 — Prohibition of Emotion Recognition in Workplace and Education Code Improvement Recommended
Missing: Consent Management
Critical EU_AI_ART_5_007 — Prohibition of Biometric Categorisation for Sensitive Characteristics Code Improvement Recommended
Missing: Consent Management
Critical EU_AI_ART_5_008 — Restrictions on Real-Time Remote Biometric Identification for Law Enforcement Code Improvement Recommended
Missing: Consent Management
Critical GDPR_ART_28_001 — Processor - Selection and Guarantees Code Improvement Recommended
Missing: Access Control
Critical GDPR_ART_58_002 — Supervisory Authority - Corrective Powers Code Improvement Recommended
Missing: Audit Logging
Critical GDPR_ART_5_001 — Lawfulness, Fairness and Transparency Code Improvement Recommended
Missing: Consent Management
Critical GDPR_ART_6_001 — Lawful Processing - Consent Code Improvement Recommended
Missing: Consent Management
Critical GDPR_ART_7_001 — Demonstration of Consent Code Improvement Recommended
Missing: Consent Management
Critical GDPR_ART_83_001 — Administrative Fines - General Conditions Code Improvement Recommended
Missing: Audit Logging
Critical SOC2_CC6_2 — User Registration and Authorization Code Improvement Recommended
Missing: Access Control, Authentication
Critical SOC2_CC6_3 — Access Authorization, Modification, and Removal Code Improvement Recommended
Missing: Access Control, Authentication
Critical SOC2_CC7_3 — Security Event Evaluation Code Improvement Recommended
Missing: Audit Logging
Critical SOC2_CC7_4 — Incident Response Program Execution Code Improvement Recommended
Missing: Audit Logging
Critical SOC2_P6_6 — Notification of Breaches and Incidents Code Improvement Recommended
Missing: Audit Logging, Consent Management
High SOC2_CC6_7 — Information Transmission and Movement Restriction Code Improvement Recommended
Satisfied: Data Classification
Missing: Access Control, Authentication, Encryption At Rest, Encryption In Transit, Key Management
apps/studio/components/ui/PasswordStrengthBar.tsx:9-9 (data_classification)
examples/user-management/ionic-angular-user-management/src/app/account/account.page.ts:18-18 (data_classification)
examples/user-management/ionic-angular-user-management/src/app/login/login.page.ts:11-11 (data_classification)
apps/www/lib/customerio.ts:22-22 (data_classification)
apps/www/lib/customerio.ts:6-6 (data_classification)
examples/_internal/fixtures/typescript.ts:6-6 (data_classification)
High SOC2_P3_1 — Collection of Personal Information Code Improvement Recommended
Satisfied: Data Classification
Missing: Access Control, Consent Management, Encryption At Rest, Encryption In Transit, Key Management
apps/studio/components/ui/PasswordStrengthBar.tsx:9-9 (data_classification)
examples/user-management/ionic-angular-user-management/src/app/account/account.page.ts:18-18 (data_classification)
examples/user-management/ionic-angular-user-management/src/app/login/login.page.ts:11-11 (data_classification)
apps/www/lib/customerio.ts:22-22 (data_classification)
apps/www/lib/customerio.ts:6-6 (data_classification)
examples/_internal/fixtures/typescript.ts:6-6 (data_classification)
High SOC2_P4_1 — Limitation of Personal Information Use Code Improvement Recommended
Satisfied: Data Classification
Missing: Access Control, Consent Management, Encryption At Rest, Encryption In Transit, Key Management
apps/studio/components/ui/PasswordStrengthBar.tsx:9-9 (data_classification)
examples/user-management/ionic-angular-user-management/src/app/account/account.page.ts:18-18 (data_classification)
examples/user-management/ionic-angular-user-management/src/app/login/login.page.ts:11-11 (data_classification)
apps/www/lib/customerio.ts:22-22 (data_classification)
apps/www/lib/customerio.ts:6-6 (data_classification)
examples/_internal/fixtures/typescript.ts:6-6 (data_classification)
High SOC2_P5_1 — Data Subject Access to Personal Information Code Improvement Recommended
Satisfied: Data Classification
Missing: Access Control, Consent Management, Encryption At Rest, Encryption In Transit, Key Management
apps/studio/components/ui/PasswordStrengthBar.tsx:9-9 (data_classification)
examples/user-management/ionic-angular-user-management/src/app/account/account.page.ts:18-18 (data_classification)
examples/user-management/ionic-angular-user-management/src/app/login/login.page.ts:11-11 (data_classification)
apps/www/lib/customerio.ts:22-22 (data_classification)
apps/www/lib/customerio.ts:6-6 (data_classification)
examples/_internal/fixtures/typescript.ts:6-6 (data_classification)
High SOC2_CC6_5 — Discontinuation of Protections Code Improvement Recommended
Satisfied: Data Classification, Data Lifecycle Management
Missing: Access Control, Encryption At Rest, Encryption In Transit, Key Management
apps/studio/components/ui/PasswordStrengthBar.tsx:9-9 (data_classification)
examples/user-management/ionic-angular-user-management/src/app/account/account.page.ts:18-18 (data_classification)
examples/user-management/ionic-angular-user-management/src/app/login/login.page.ts:11-11 (data_classification)
examples/user-management/ionic-angular-user-management/src/app/account/account.page.ts:18-18 (data_minimization_module_fanin)
apps/www/lib/customerio.ts:22-22 (data_classification)
examples/user-management/ionic-angular-user-management/src/app/login/login.page.ts:11-11 (data_minimization_module_fanin)
apps/www/lib/customerio.ts:6-6 (data_classification)
examples/_internal/fixtures/typescript.ts:6-6 (data_classification)
High SOC2_C1_2 — Disposal of Confidential Information Code Improvement Recommended
Satisfied: Data Lifecycle Management
examples/user-management/ionic-angular-user-management/src/app/account/account.page.ts:18-18 (data_minimization_module_fanin)
examples/user-management/ionic-angular-user-management/src/app/login/login.page.ts:11-11 (data_minimization_module_fanin)
High SOC2_P4_2 — Retention of Personal Information Code Improvement Recommended
Satisfied: Data Lifecycle Management
Missing: Data Retention
examples/user-management/ionic-angular-user-management/src/app/account/account.page.ts:18-18 (data_minimization_module_fanin)
examples/user-management/ionic-angular-user-management/src/app/login/login.page.ts:11-11 (data_minimization_module_fanin)
High SOC2_P4_3 — Disposal of Personal Information Code Improvement Recommended
Satisfied: Data Lifecycle Management
examples/user-management/ionic-angular-user-management/src/app/account/account.page.ts:18-18 (data_minimization_module_fanin)
examples/user-management/ionic-angular-user-management/src/app/login/login.page.ts:11-11 (data_minimization_module_fanin)
High EU_AI_ART_50_001 — Transparency - Interaction with AI Systems Code Improvement Recommended
Missing: Consent Management
High EU_AI_ART_50_003 — Transparency - Emotion Recognition and Biometric Categorisation Code Improvement Recommended
Missing: Consent Management
High EU_AI_ART_50_004 — Disclosure of Deep Fakes and AI-Generated Text Code Improvement Recommended
Missing: Consent Management
High GDPR_ART_12_005 — Free of Charge Information and Requests Code Improvement Recommended
Missing: Consent Management
High GDPR_ART_17_002 — Obligation to Inform Other Controllers of Erasure Request Code Improvement Recommended
Missing: Consent Management
High GDPR_ART_18_002 — Processing of Restricted Data Code Improvement Recommended
Missing: Consent Management
High GDPR_ART_19_001 — Notification Obligation Regarding Rectification, Erasure, or Restriction Code Improvement Recommended
Missing: Consent Management
High GDPR_ART_20_003 — Data Portability - Limitations Code Improvement Recommended
Missing: Consent Management
High GDPR_ART_23_001 — Restrictions of Rights and Obligations Code Improvement Recommended
Missing: Consent Management
High GDPR_ART_27_001 — Representative of Controllers or Processors Not Established in the Union Code Improvement Recommended
Missing: Access Control
High GDPR_ART_27_002 — Representative - Mandate and Responsibilities Code Improvement Recommended
Missing: Access Control
High GDPR_ART_28_002 — Processor - Engagement of Sub-Processors Code Improvement Recommended
Missing: Access Control
High GDPR_ART_34_002 — Exceptions to Breach Communication to Data Subject Code Improvement Recommended
Missing: Audit Logging
High GDPR_ART_35_003 — DPIA - Content Code Improvement Recommended
Missing: Consent Management
High GDPR_ART_58_001 — Supervisory Authority - Investigative Powers Code Improvement Recommended
Missing: Audit Logging
High GDPR_ART_6_002 — Lawful Processing - Contract Code Improvement Recommended
Missing: Consent Management
High GDPR_ART_7_004 — Consent - Freely Given Assessment Code Improvement Recommended
Missing: Consent Management
High NIST_AI_RMF_MANAGE_4_1 — Manage 4.1 Code Improvement Recommended
Missing: Audit Logging
High NIST_AI_RMF_MANAGE_4_3 — Manage 4.3 Code Improvement Recommended
Missing: Audit Logging
High NIST_AI_RMF_MEASURE_2_4 — Measure 2.4 Code Improvement Recommended
Missing: Audit Logging

Control Mapping Appendix

Raw control-level mapping (control IDs, clause text) is intentionally not inlined here — export to JSON or SARIF for the complete, machine-readable control mapping.