3 of 217 applicable controls automatically verified
Deterministic, evidence-backed scan result
Meridian provides automated compliance assessments and recommendations, not legal advice. Final compliance determinations should be reviewed by qualified legal, compliance, or security professionals where required.
Meridian Compliance Report
supabase
Generated 23 July 2026, 05:19 UTC
Report d8f0d54b299a4f98afbe67e1
Meridian provides automated compliance assessments and recommendations, not legal advice. Final compliance determinations should be reviewed by qualified legal, compliance, or security professionals where required.
Executive Summary
Applicable Controls
217
Controls determined to apply to this repository
Implemented
3
Requires Documentation
84
Requires Operational Evidence
49
Code Improvement Recommended
81
Repository Overview
In ProductionTrue
Technology Stack
7503 files · 915657 lines
Languagesjavascript, jsx, python, tsx, typescript
FrameworksAngular, Next.js, React, Vue
CI/CD & IaCDocker, Docker Compose, GitHub Actions
Business Signals
Stores personal dataTrue
Uses AITrue
Primary jurisdictionUnited States
Processes paymentsFalse
Regulated financial entityFalse
Offers goods/services to the EUTrue
Monitors individuals in the EUFalse
Offers goods/services to IndiaFalse
AI roleProvider
AI output used in the EUTrue
High-risk AI use case indicatedFalse
General-purpose AI model providerFalse
What Meridian Understood
This repository represents a complex web-based software project utilizing a mix of modern JavaScript technologies including Angular, React, Vue, and Next.js to offer a rich interactive user experience. It interfaces with external APIs extensively and manages data securely using encryption and secrets management.
Architecture: Web application frontend and backend
Compliance Scope
Applicable Regulations
GDPRPrivacy & Data ProtectionStatutory law
Your application stores or processes personal data of individuals in the European Union.
Required: matched on stores_personal_data, offers_goods_services_to_eu.
In force since May 2018; applies extraterritorially to organizations offering goods or services to, or monitoring, individuals in the EU.
EU AI ActAI Governance & Responsible AIStatutory law
Your repository deploys AI models or AI-powered systems.
Required: matched on ai_usage.
In force since August 2024 with phased application — prohibited practices first, general-purpose AI and high-risk obligations phasing in later; verify current phase-in dates.
AI risk context: role: Provider; output used in the EU: yes; high-risk use case indicated: no; general-purpose model provider: no
Your application is in production and handles customer data requiring independent assurance.
Optional: base condition met, but no additional signal beyond production.
A voluntary attestation framework (AICPA Trust Services Criteria) driven by customer and contractual demand, not law.
NIST AI RMFAI Governance & Responsible AIVoluntary attestation
Your application develops, deploys, or uses AI/ML systems.
Required: matched on ai_usage.
AI RMF 1.0 released January 2023 by NIST; a voluntary risk-management framework, not a binding regulation -- adopted for market trust and structured AI governance, not because it is legally required.
Not Applicable Regulations
DPDPA 2023Privacy & Data Protection
Excluded: none of 'primary_jurisdiction', 'offers_goods_services_to_india' match the conditions required for this framework.
DPDPA Rules, 2025Privacy & Data Protection
Excluded: none of 'primary_jurisdiction', 'offers_goods_services_to_india' match the conditions required for this framework.
RBI FREE-AI FrameworkAI Governance & Responsible AI
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
SEBI AI/ML GuidelinesAI Governance & Responsible AI
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
RBI Digital Payment Security ControlsPayments & Financial Security
Excluded: 'processes_payments' does not match the condition required for this framework.
PCI DSSPayments & Financial Security
Excluded: 'processes_payments' does not match the condition required for this framework.
RBI IT Governance & Risk ControlsCybersecurity & Operational Security
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
RBI NBFC IT FrameworkFinancial Sector Regulations
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
Authentication (CRITICAL) — Can the organization demonstrate that it implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events?
Encryption In Transit (CRITICAL) — Can the organization demonstrate that it implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events?
Encryption At Rest (CRITICAL) — Can the organization demonstrate that it implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events?
Key Management (CRITICAL) — Can the organization demonstrate that it implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events?
Can the organization demonstrate that it implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events?
Can the organization demonstrate that it implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events?
Can the organization demonstrate that it implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events?
Can the organization demonstrate: aI system security and resilience -- as identified in the map function -- are evaluated and documented.
Improves compliance posture for: NIST AI RMF.
Vulnerability Scanning (HIGH)
Can the organization demonstrate: aI system security and resilience -- as identified in the map function -- are evaluated and documented.
Improves compliance posture for: NIST AI RMF.
Medium Effort
Key Management (CRITICAL)
Can the organization demonstrate that it implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events?
Can the organization demonstrate that it has taken measures to ensure a sufficient level of AI literacy among staff and others involved in the operation and use of AI systems?
Improves compliance posture for: EU AI Act, GDPR, NIST AI RMF, SOC 2 Trust Services Criteria.
Consent Management (HIGH)
Can the organization demonstrate that AI systems intended to interact with natural persons are designed to inform them they are interacting with an AI system?
Improves compliance posture for: EU AI Act, GDPR, SOC 2 Trust Services Criteria.
Data Subject Request Handling (HIGH)
Can the organization demonstrate that it has procedures to handle complaints regarding infringement of the AI Act?
Improves compliance posture for: EU AI Act, NIST AI RMF.
Audit Logging (HIGH)
Can the organization demonstrate that it has properly applied exceptions to breach communication to data subjects?
Can the organization demonstrate that it maintains, monitors, and evaluates current processing capacity and use of system components to manage capacity demand?
Can the organization demonstrate that it authorizes, designs, implements, maintains, and monitors environmental protections, backup processes, and recovery infrastructure?
Can the organization demonstrate that it implements policies and procedures to store inputs, items in processing, and outputs completely, accurately, and timely in accordance with system specifications?
Can the organization demonstrate that it has taken measures to ensure a sufficient level of AI literacy among staff and others involved in the operation and use of AI systems?
Improves compliance posture for: EU AI Act, GDPR, NIST AI RMF.
Maker Checker (MEDIUM)
Can the organization demonstrate that it has taken measures to ensure a sufficient level of AI literacy among staff and others involved in the operation and use of AI systems?
Improves compliance posture for: EU AI Act, GDPR, NIST AI RMF, SOC 2 Trust Services Criteria.
Records Of Processing (MEDIUM)
Can the organization (as a law enforcement authority) demonstrate that it notifies each use of real-time remote biometric identification to the relevant authorities and submits annual reports?
Improves compliance posture for: EU AI Act, GDPR, NIST AI RMF, SOC 2 Trust Services Criteria.
Grievance Redressal (MEDIUM)
Can the organization demonstrate that it has procedures to handle complaints regarding infringement of the AI Act?
Improves compliance posture for: EU AI Act, NIST AI RMF.
Data Masking (MEDIUM)
Can the organization demonstrate that processing of criminal conviction data is under official control or authorised by law with appropriate safeguards?
Can the organization demonstrate that it implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events?
Can the organization demonstrate that it has taken measures to ensure a sufficient level of AI literacy among staff and others involved in the operation and use of AI systems?
Improves compliance posture for: EU AI Act, GDPR, NIST AI RMF, SOC 2 Trust Services Criteria.
Policy Management (LOW)
Can the organization (as a law enforcement authority) demonstrate that it notifies each use of real-time remote biometric identification to the relevant authorities and submits annual reports?
Improves compliance posture for: EU AI Act, GDPR, NIST AI RMF, SOC 2 Trust Services Criteria.
Data Quality Management (INFORMATIONAL)
Can the organization demonstrate that it has taken measures to ensure a sufficient level of AI literacy among staff and others involved in the operation and use of AI systems?
Improves compliance posture for: EU AI Act, GDPR, NIST AI RMF.
Strategic Initiatives
Bias Detection (HIGH)
Can the organization demonstrate that it has taken measures to ensure a sufficient level of AI literacy among staff and others involved in the operation and use of AI systems?
Improves compliance posture for: EU AI Act, GDPR, NIST AI RMF.
AI Risk Assessment (HIGH)
Can the organization demonstrate that it has taken measures to ensure a sufficient level of AI literacy among staff and others involved in the operation and use of AI systems?
Improves compliance posture for: EU AI Act, GDPR, NIST AI RMF, SOC 2 Trust Services Criteria.
Data Loss Prevention (HIGH)
Can the organization demonstrate that it does not create or expand facial recognition databases through untargeted scraping?
Improves compliance posture for: EU AI Act, GDPR.
Privacy Impact Assessment (HIGH)
Can the organization demonstrate that it has assessed the risks to personal data when determining security measures?
Can the organization demonstrate: aI system security and resilience -- as identified in the map function -- are evaluated and documented.
Improves compliance posture for: NIST AI RMF.
Model Monitoring (MEDIUM)
Can the organization demonstrate that it has taken measures to ensure a sufficient level of AI literacy among staff and others involved in the operation and use of AI systems?
Improves compliance posture for: EU AI Act, GDPR, NIST AI RMF.
Physical Access Control (MEDIUM)
Can the organization demonstrate that it does not create or expand facial recognition databases through untargeted scraping?
Improves compliance posture for: EU AI Act, GDPR.
Compliance Roadmap
Now · Quick Wins
Access Control
Authentication
Encryption In Transit
Encryption At Rest
Patch Management
Vulnerability Scanning
Next · Medium Effort
Key Management
Privileged Access Management
Consent Management
Data Subject Request Handling
Audit Logging
Backup And Recovery
Incident Response Plan
Data Retention
Model Testing
Maker Checker
Records Of Processing
Grievance Redressal
Data Masking
Business Impact Analysis
Data Lifecycle Management
Data Classification
Security Awareness Training
Policy Management
Data Quality Management
Later · Strategic Initiatives
Bias Detection
AI Risk Assessment
Data Loss Prevention
Privacy Impact Assessment
Data Protection Impact Assessment
Penetration Testing
Model Monitoring
Physical Access Control
Next Steps
Start with Top Priorities above, then work through the full Quick Wins/Medium Effort/Strategic Initiatives breakdown.
Technical Findings below show exactly where each gap was detected in your repository; export to PDF/HTML for a
shareable version, or JSON/SARIF to feed a CI pipeline.
Technical Findings (69)
Showing top 50 of 69, ranked by severity then confidence.
Export to JSON or SARIF for the complete list.
Raw control-level mapping (control IDs, clause text) is intentionally not inlined here — export to JSON or SARIF for the complete, machine-readable control mapping.