meridian scan chatwoot

chatwoot

Open-source customer support and engagement platform — github.com/chatwoot/chatwoot

Applicable Controls
265
Implemented
0
Files Scanned
1055
Regulations Applicable
4
01 — Repository Overview

What Meridian scanned

chatwoot — 1,055 files, 119,446 lines, across javascript, typescript.

This repository is built using JavaScript and TypeScript, primarily leveraging frontend frameworks Next.js and Vue. It appears to be structured around web development and is deploying in containers using Docker and Docker Compose orchestrated by GitHub Actions.

Architecture: Web app

Technology Stack

javascript typescript Next.js Vue Docker Docker Compose GitHub Actions

Business Signals

Stores personal data: True Uses AI: True Primary jurisdiction: United States Processes payments: False Regulated financial entity: False Offers goods/services to the EU: True Monitors individuals in the EU: False Offers goods/services to India: False AI role: Provider AI output used in the EU: True High-risk AI use case indicated: False General-purpose AI model provider: False
02 — What Meridian Detected

Compliance Readiness

Every capability Meridian evaluated, grouped by what's actually true about it — implemented in code, fixable in code, or something only documentation or an operational process can demonstrate.

Implemented (1)

  • Cross Border Transfer Controls

Code Improvement Recommended (10)

  • Access Control
  • Audit Logging
  • Authentication
  • Consent Management
  • Data Classification
  • Data Lifecycle Management
  • Data Retention
  • Encryption At Rest
  • Encryption In Transit
  • Key Management

Requires Documentation (15)

  • Asset Inventory
  • Backup And Recovery
  • Business Impact Analysis
  • Configuration Management
  • Data Deletion
  • Data Masking
  • Data Protection Impact Assessment
  • Data Subject Request Handling
  • Grievance Redressal
  • Incident Response Plan
  • Information Security Policy
  • Log Retention
  • Policy Management
  • Privacy Impact Assessment
  • Records Of Processing

Requires Operational Evidence (23)

  • AI Risk Assessment
  • Access Review
  • BCP And DR Testing
  • Bias Detection
  • Change Management
  • Data Loss Prevention
  • Data Quality Management
  • Governance Framework
  • Incident Detection
  • Maker Checker
  • Model Monitoring
  • Model Testing
  • Patch Management
  • Penetration Testing
  • Physical Access Control
  • Privileged Access Management
  • Regulatory Change Monitoring
  • Regulatory Reporting
  • SOC Operations
  • Security Awareness Training
  • Third Party Risk Assessment
  • Vendor Contract Management
  • Vulnerability Scanning
03 — Applicable Regulations

Compliance Scope

Determined from what Meridian found in the repository and the business signals above — not every one of the 17 supported frameworks, only the ones that actually apply.

GDPRStatutory lawPrivacy & Data Protection
Your application stores or processes personal data of individuals in the European Union.
Required: matched on stores_personal_data, offers_goods_services_to_eu.
In force since May 2018; applies extraterritorially to organizations offering goods or services to, or monitoring, individuals in the EU.
EU AI ActStatutory lawAI Governance & Responsible AI
Your repository deploys AI models or AI-powered systems.
Required: matched on ai_usage.
In force since August 2024 with phased application — prohibited practices first, general-purpose AI and high-risk obligations phasing in later; verify current phase-in dates. - **AI risk context:** role: Provider; output used in the EU: yes; high-risk use case indicated: no; general-purpose model provider: no
SOC 2 Trust Services CriteriaVoluntary attestationTrust & Assurance
Your application is in production and handles customer data requiring independent assurance.
Optional: base condition met, but no additional signal beyond production.
A voluntary attestation framework (AICPA Trust Services Criteria) driven by customer and contractual demand, not law.
NIST AI RMFVoluntary attestationAI Governance & Responsible AI
Your application develops, deploys, or uses AI/ML systems.
Required: matched on ai_usage.
AI RMF 1.0 released January 2023 by NIST; a voluntary risk-management framework, not a binding regulation -- adopted for market trust and structured AI governance, not because it is legally required.

Not Applicable (14)

DPDPA 2023
Excluded: none of 'primary_jurisdiction', 'offers_goods_services_to_india' match the conditions required for this framework.
DPDPA Rules, 2025
Excluded: none of 'primary_jurisdiction', 'offers_goods_services_to_india' match the conditions required for this framework.
RBI FREE-AI Framework
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
SEBI AI/ML Guidelines
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
RBI Digital Payment Security Controls
Excluded: 'processes_payments' does not match the condition required for this framework.
PCI DSS
Excluded: 'processes_payments' does not match the condition required for this framework.

+ 8 more in the full report.

04 — Enterprise Readiness

What an enterprise security review would ask about first

Recommended Improvements (7)

  • Authentication
  • Access Control
  • Audit Logging
  • Encryption At Rest
  • Encryption In Transit
  • Key Management
  • Data Retention

Operational Requirements (6)

  • Privileged Access Management
  • BCP And DR Testing
  • Penetration Testing
  • Third Party Risk Assessment
  • Vendor Contract Management
  • Security Awareness Training

Documentation Required (2)

  • Incident Response Plan
  • Information Security Policy
05 — Top Priorities

What matters most

  1. Encryption In TransitCRITICAL
    Can the organization demonstrate that it does not create or expand facial recognition databases through untargeted scraping?
  2. Access ControlCRITICAL
    Can the organization demonstrate that it does not create or expand facial recognition databases through untargeted scraping?
  3. Encryption At RestCRITICAL
    Can the organization demonstrate that it does not create or expand facial recognition databases through untargeted scraping?
  4. AuthenticationCRITICAL
    If the organization operates a healthcare clearinghouse within a larger entity, has it implemented policies isolating clearinghouse electronic protected health information from the rest of the organization?
  5. Key ManagementCRITICAL
    Can the organization demonstrate that it does not create or expand facial recognition databases through untargeted scraping?
06 — Recommendations

Recommended actions, by effort

Quick Wins (7)

  • Encryption In Transit
  • Access Control
  • Encryption At Rest
  • Authentication
  • Patch Management
  • Vulnerability Scanning
  • Log Retention

Medium Effort (22)

  • Key Management
  • Privileged Access Management
  • Consent Management
  • Data Subject Request Handling
  • Audit Logging
  • Incident Response Plan
  • Backup And Recovery
  • Data Retention
  • Maker Checker
  • Model Testing
  • Data Classification
  • Records Of Processing
  • Grievance Redressal
  • Business Impact Analysis
  • Configuration Management
  • Asset Inventory
  • Data Lifecycle Management
  • Data Masking
  • Information Security Policy
  • Security Awareness Training
  • Policy Management
  • Data Quality Management

Strategic Initiatives (6)

  • AI Risk Assessment
  • Bias Detection
  • Data Protection Impact Assessment
  • Privacy Impact Assessment
  • Penetration Testing
  • Model Monitoring
07 — Compliance Roadmap

Now, next, later

Now · Quick Wins
  • Encryption In Transit
  • Access Control
  • Encryption At Rest
  • Authentication
  • Patch Management
  • Vulnerability Scanning
  • Log Retention
Next · Medium Effort
  • Key Management
  • Privileged Access Management
  • Consent Management
  • Data Subject Request Handling
  • Audit Logging
  • Incident Response Plan
  • Backup And Recovery
  • Data Retention
  • Maker Checker
  • Model Testing
  • Data Classification
  • Records Of Processing
  • Grievance Redressal
  • Business Impact Analysis
  • Configuration Management
  • Asset Inventory
  • Data Lifecycle Management
  • Data Masking
  • Information Security Policy
  • Security Awareness Training
  • Policy Management
  • Data Quality Management
Later · Strategic Initiatives
  • AI Risk Assessment
  • Bias Detection
  • Data Protection Impact Assessment
  • Privacy Impact Assessment
  • Penetration Testing
  • Model Monitoring
08 — Technical Findings

Evidence, for engineers

97 critical/high findings, each with file:line evidence traced back to the exact code that was or wasn't found — not shown here by design (this page is the summary; the full report is the audit trail). Open the full report below.