meridian scan continue

continue

Open-source AI code assistant — github.com/continuedev/continue

Applicable Controls
60
Implemented
0
Files Scanned
1874
Regulations Applicable
1
01 — Repository Overview

What Meridian scanned

continue — 1,874 files, 314,603 lines, across go, java, javascript, jsx, python, tsx, typescript.

This repository features a multi-language structure using Go, Java, JavaScript, JSX, Python, TypeScript, along with web frameworks including Express, FastAPI, Next.js, and React. It integrates AI via the OpenAI SDK, mainly destined for runtime in Dockerized environments, controlled via GitHub Actions and GitLab CI.

Architecture: Web application with AI integration

Technology Stack

go java javascript jsx python tsx typescript Express FastAPI Next.js React Docker GitHub Actions GitLab CI

Business Signals

Stores personal data: True Uses AI: True Primary jurisdiction: United States Processes payments: False Regulated financial entity: False
02 — What Meridian Detected

Compliance Readiness

Every capability Meridian evaluated, grouped by what's actually true about it — implemented in code, fixable in code, or something only documentation or an operational process can demonstrate.

Implemented (4)

  • Authentication
  • Cross Border Transfer Controls
  • Data Classification
  • Data Lifecycle Management

Code Improvement Recommended (7)

  • Access Control
  • Audit Logging
  • Consent Management
  • Data Retention
  • Encryption At Rest
  • Encryption In Transit
  • Key Management

Requires Documentation (15)

  • Asset Inventory
  • Backup And Recovery
  • Business Impact Analysis
  • Configuration Management
  • Data Deletion
  • Data Masking
  • Data Protection Impact Assessment
  • Data Subject Request Handling
  • Grievance Redressal
  • Incident Response Plan
  • Information Security Policy
  • Log Retention
  • Policy Management
  • Privacy Impact Assessment
  • Records Of Processing

Requires Operational Evidence (23)

  • AI Risk Assessment
  • Access Review
  • BCP And DR Testing
  • Bias Detection
  • Change Management
  • Data Loss Prevention
  • Data Quality Management
  • Governance Framework
  • Incident Detection
  • Maker Checker
  • Model Monitoring
  • Model Testing
  • Patch Management
  • Penetration Testing
  • Physical Access Control
  • Privileged Access Management
  • Regulatory Change Monitoring
  • Regulatory Reporting
  • SOC Operations
  • Security Awareness Training
  • Third Party Risk Assessment
  • Vendor Contract Management
  • Vulnerability Scanning
03 — Applicable Regulations

Compliance Scope

Determined from what Meridian found in the repository and the business signals above — not every one of the 17 supported frameworks, only the ones that actually apply.

EU AI ActStatutory lawAI Governance & Responsible AI
Your repository deploys AI models or AI-powered systems.
Required: matched on ai_usage.
In force since August 2024 with phased application — prohibited practices first, general-purpose AI and high-risk obligations phasing in later; verify current phase-in dates.

Not Applicable (16)

DPDPA 2023
Excluded: 'primary_jurisdiction' does not match the condition required for this framework.
DPDPA Rules, 2025
Excluded: 'primary_jurisdiction' does not match the condition required for this framework.
GDPR
Excluded: 'primary_jurisdiction' does not match the condition required for this framework.
RBI FREE-AI Framework
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
SEBI AI/ML Guidelines
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
RBI Digital Payment Security Controls
Excluded: 'processes_payments' does not match the condition required for this framework.

+ 10 more in the full report.

04 — Enterprise Readiness

What an enterprise security review would ask about first

Detected (1)

  • Authentication

Recommended Improvements (6)

  • Access Control
  • Audit Logging
  • Encryption At Rest
  • Encryption In Transit
  • Key Management
  • Data Retention

Operational Requirements (6)

  • Privileged Access Management
  • BCP And DR Testing
  • Penetration Testing
  • Third Party Risk Assessment
  • Vendor Contract Management
  • Security Awareness Training

Documentation Required (2)

  • Incident Response Plan
  • Information Security Policy
05 — Top Priorities

What matters most

  1. Access ControlCRITICAL
    Can the organization (as a third-country provider) demonstrate that it has appointed an authorised representative in the Union and that the representative fulfils all required tasks?
  2. Data Subject Request HandlingHIGH
    Can the organization demonstrate that it has implemented appropriate data governance and management practices for training, validation, and testing data sets of high-risk AI systems?
  3. Consent ManagementHIGH
    Can the organization demonstrate that it has implemented appropriate safeguards when processing special categories of personal data for bias detection and correction?
  4. Audit LoggingHIGH
    Can the organization demonstrate that high-risk AI systems have logging capabilities for automatic event recording throughout their lifetime?
  5. Privileged Access ManagementHIGH
    Can the organization demonstrate that high-risk AI systems are designed for effective human oversight throughout their use?
06 — Recommendations

Recommended actions, by effort

Quick Wins (1)

  • Access Control

Medium Effort (15)

  • Data Subject Request Handling
  • Consent Management
  • Audit Logging
  • Privileged Access Management
  • Backup And Recovery
  • Data Retention
  • Records Of Processing
  • Maker Checker
  • Model Testing
  • Business Impact Analysis
  • Data Lifecycle Management
  • Grievance Redressal
  • Policy Management
  • Security Awareness Training
  • Data Quality Management

Strategic Initiatives (7)

  • AI Risk Assessment
  • Bias Detection
  • Data Loss Prevention
  • Privacy Impact Assessment
  • Data Protection Impact Assessment
  • Physical Access Control
  • Model Monitoring
07 — Compliance Roadmap

Now, next, later

Now · Quick Wins
  • Access Control
Next · Medium Effort
  • Data Subject Request Handling
  • Consent Management
  • Audit Logging
  • Privileged Access Management
  • Backup And Recovery
  • Data Retention
  • Records Of Processing
  • Maker Checker
  • Model Testing
  • Business Impact Analysis
  • Data Lifecycle Management
  • Grievance Redressal
  • Policy Management
  • Security Awareness Training
  • Data Quality Management
Later · Strategic Initiatives
  • AI Risk Assessment
  • Bias Detection
  • Data Loss Prevention
  • Privacy Impact Assessment
  • Data Protection Impact Assessment
  • Physical Access Control
  • Model Monitoring
08 — Technical Findings

Evidence, for engineers

23 critical/high findings, each with file:line evidence traced back to the exact code that was or wasn't found — not shown here by design (this page is the summary; the full report is the audit trail). Open the full report below.