What Meridian scanned
twenty — 21,449 files, 1,771,326 lines, across javascript, python, terraform, tsx, typescript.
This repository is a complex, multi-language web application utilizing modern frameworks and technologies primarily for web development. It is designed with robust back-end services and user-facing functionality, indicating a diverse technological ecosystem.
Architecture: Full-stack web application
Technology Stack
Business Signals
Compliance Readiness
Every capability Meridian evaluated, grouped by what's actually true about it — implemented in code, fixable in code, or something only documentation or an operational process can demonstrate.
Implemented (4)
- Authentication
- Cross Border Transfer Controls
- Data Classification
- Data Lifecycle Management
Code Improvement Recommended (7)
- Access Control
- Audit Logging
- Consent Management
- Data Retention
- Encryption At Rest
- Encryption In Transit
- Key Management
Requires Documentation (15)
- Asset Inventory
- Backup And Recovery
- Business Impact Analysis
- Configuration Management
- Data Deletion
- Data Masking
- Data Protection Impact Assessment
- Data Subject Request Handling
- Grievance Redressal
- Incident Response Plan
- Information Security Policy
- Log Retention
- Policy Management
- Privacy Impact Assessment
- Records Of Processing
Requires Operational Evidence (23)
- AI Risk Assessment
- Access Review
- BCP And DR Testing
- Bias Detection
- Change Management
- Data Loss Prevention
- Data Quality Management
- Governance Framework
- Incident Detection
- Maker Checker
- Model Monitoring
- Model Testing
- Patch Management
- Penetration Testing
- Physical Access Control
- Privileged Access Management
- Regulatory Change Monitoring
- Regulatory Reporting
- SOC Operations
- Security Awareness Training
- Third Party Risk Assessment
- Vendor Contract Management
- Vulnerability Scanning
Compliance Scope
Determined from what Meridian found in the repository and the business signals above — not every one of the 17 supported frameworks, only the ones that actually apply.
Not Applicable (16)
+ 10 more in the full report.
What an enterprise security review would ask about first
Detected (1)
- Authentication
Recommended Improvements (6)
- Access Control
- Audit Logging
- Encryption At Rest
- Encryption In Transit
- Key Management
- Data Retention
Operational Requirements (6)
- Privileged Access Management
- BCP And DR Testing
- Penetration Testing
- Third Party Risk Assessment
- Vendor Contract Management
- Security Awareness Training
Documentation Required (2)
- Incident Response Plan
- Information Security Policy
What matters most
-
Access ControlCRITICAL
Can the organization (as a non-EU controller/processor) demonstrate that it has designated a representative in the Union?
-
Encryption In TransitCRITICAL
Can the organization demonstrate that it discontinues logical and physical protections over physical assets only after data and software are no longer recoverable?
-
Encryption At RestCRITICAL
Can the organization demonstrate that it discontinues logical and physical protections over physical assets only after data and software are no longer recoverable?
-
Key ManagementCRITICAL
Can the organization demonstrate that it discontinues logical and physical protections over physical assets only after data and software are no longer recoverable?
-
Consent ManagementHIGH
Can the organization demonstrate that it provides information free of charge and has procedures for manifestly unfounded or excessive requests?
Recommended actions, by effort
Quick Wins (4)
- Access Control
- Encryption In Transit
- Encryption At Rest
- Log Retention
Medium Effort (20)
- Key Management
- Consent Management
- Privileged Access Management
- Audit Logging
- Incident Response Plan
- Backup And Recovery
- Data Retention
- Records Of Processing
- Data Masking
- Maker Checker
- Model Testing
- Business Impact Analysis
- Configuration Management
- Asset Inventory
- Data Lifecycle Management
- Information Security Policy
- Data Classification
- Policy Management
- Security Awareness Training
- Data Quality Management
Strategic Initiatives (7)
- Bias Detection
- AI Risk Assessment
- Data Loss Prevention
- Data Protection Impact Assessment
- Privacy Impact Assessment
- Model Monitoring
- Physical Access Control
Now, next, later
- Access Control
- Encryption In Transit
- Encryption At Rest
- Log Retention
- Key Management
- Consent Management
- Privileged Access Management
- Audit Logging
- Incident Response Plan
- Backup And Recovery
- Data Retention
- Records Of Processing
- Data Masking
- Maker Checker
- Model Testing
- Business Impact Analysis
- Configuration Management
- Asset Inventory
- Data Lifecycle Management
- Information Security Policy
- Data Classification
- Policy Management
- Security Awareness Training
- Data Quality Management
- Bias Detection
- AI Risk Assessment
- Data Loss Prevention
- Data Protection Impact Assessment
- Privacy Impact Assessment
- Model Monitoring
- Physical Access Control