Meridian provides automated compliance assessments and recommendations, not legal advice. Final compliance determinations should be reviewed by qualified legal, compliance, or security professionals where required.
Repository Summary
Applicable Controls
122
Controls determined to apply to this repository
Automatically Verified
1
Requires Documentation
46
Requires Operational Evidence
12
Requires Code Changes
63
Security Maturity
0.04
0.0 - 1.0 scale
Risk Score
0.45
Severity-weighted violations
Business Profile
In productionTrue
Stores personal dataTrue
Uses AITrue
Primary jurisdictionUnited States
Processes paymentsFalse
Regulated financial entityFalse
Compliance Scope
Applicable Regulations
EU AI ActAI Governance & Responsible AI
Your repository deploys AI models or AI-powered systems.
Required: matched on ai_usage.
SOC 2 Trust Services CriteriaTrust & Assurance
Your application is in production and handles customer data requiring independent assurance.
Optional: base condition met, but no additional signal beyond production.
Not Applicable Regulations
DPDPA 2023Privacy & Data Protection
Excluded: 'primary_jurisdiction' does not match the condition required for this framework.
DPDPA Rules, 2025Privacy & Data Protection
Excluded: 'primary_jurisdiction' does not match the condition required for this framework.
GDPRPrivacy & Data Protection
Excluded: 'primary_jurisdiction' does not match the condition required for this framework.
RBI FREE-AI FrameworkAI Governance & Responsible AI
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
SEBI AI/ML GuidelinesAI Governance & Responsible AI
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
RBI Digital Payment Security ControlsPayments & Financial Security
Excluded: 'processes_payments' does not match the condition required for this framework.
PCI DSSPayments & Financial Security
Excluded: 'processes_payments' does not match the condition required for this framework.
RBI IT Governance & Risk ControlsCybersecurity & Operational Security
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
RBI NBFC IT FrameworkFinancial Sector Regulations
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
RBI NBFC Outsourcing DirectionsFinancial Sector Regulations
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
RBI Outsourcing DirectionsFinancial Sector Regulations
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
RBI Payments Banks Outsourcing DirectionsFinancial Sector Regulations
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
RBI Small Finance Banks Outsourcing DirectionsFinancial Sector Regulations
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
SEBI Cybersecurity FrameworkCybersecurity & Operational Security
Excluded: 'regulated_financial_entity' does not match the condition required for this framework.
CERT-In DirectionsCybersecurity & Operational Security
Excluded: 'primary_jurisdiction' does not match the condition required for this framework.
What Meridian Detected
Cross Border Transfer Controls
Data Classification
Top Priorities
- Access Control (CRITICAL) — Can the organization (as a third-country provider) demonstrate that it has appointed an authorised representative in the Union and that the representative fulfils all required tasks?
- Authentication (CRITICAL) — Can the organization demonstrate that it implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events?
- Encryption At Rest (CRITICAL) — Can the organization demonstrate that it implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events?
- Encryption In Transit (CRITICAL) — Can the organization demonstrate that it implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events?
- Key Management (CRITICAL) — Can the organization demonstrate that it implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events?
Full breakdown by effort below.
Recommended Actions
Quick Wins
- Access Control (CRITICAL)Can the organization (as a third-country provider) demonstrate that it has appointed an authorised representative in the Union and that the representative fulfils all required tasks?
- Authentication (CRITICAL)Can the organization demonstrate that it implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events?
- Encryption At Rest (CRITICAL)Can the organization demonstrate that it implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events?
- Encryption In Transit (CRITICAL)Can the organization demonstrate that it implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events?
Medium Effort
- Key Management (CRITICAL)Can the organization demonstrate that it implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events?
- Data Subject Request Handling (HIGH)Can the organization demonstrate that it has implemented appropriate data governance and management practices for training, validation, and testing data sets of high-risk AI systems?
- Consent Management (HIGH)Can the organization demonstrate that it has implemented appropriate safeguards when processing special categories of personal data for bias detection and correction?
- Audit Logging (HIGH)Can the organization demonstrate that high-risk AI systems have logging capabilities for automatic event recording throughout their lifetime?
- Privileged Access Management (HIGH)Can the organization demonstrate that high-risk AI systems are designed for effective human oversight throughout their use?
- Backup And Recovery (HIGH)Can the organization demonstrate that high-risk AI systems are resilient to errors and have measures to address feedback loops?
- Data Retention (HIGH)Can the organization demonstrate that it retains automatically generated logs for at least six months (or as otherwise required) for high-risk AI systems?
- Incident Response Plan (HIGH)Can the organization demonstrate that it authorizes, designs, implements, maintains, and monitors environmental protections, backup processes, and recovery infrastructure?
- Records Of Processing (MEDIUM)Can the organization demonstrate that it has drawn up and maintains up-to-date technical documentation for high-risk AI systems as required by Annex IV?
- Maker Checker (MEDIUM)Can the organization demonstrate that high-risk AI systems are designed for effective human oversight throughout their use?
- Model Testing (MEDIUM)Can the organization demonstrate that high-risk AI systems achieve appropriate levels of accuracy, robustness, and cybersecurity throughout their lifecycle?
- Business Impact Analysis (MEDIUM)Can the organization demonstrate that high-risk AI systems are resilient to errors and have measures to address feedback loops?
- Data Lifecycle Management (MEDIUM)Can the organization demonstrate that it retains all required documentation for 10 years after placing a high-risk AI system on the market?
- Grievance Redressal (MEDIUM)Can the organization demonstrate that it has procedures to handle complaints regarding infringement of the AI Act?
- Data Masking (MEDIUM)Can the organization demonstrate that it selects and develops general control activities over technology to support the achievement of objectives?
- Data Classification (MEDIUM)Can the organization demonstrate that it implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events?
- Policy Management (LOW)Can the organization demonstrate that it has implemented appropriate data governance and management practices for training, validation, and testing data sets of high-risk AI systems?
- Security Awareness Training (LOW)Can the organization demonstrate that high-risk AI systems are designed for effective human oversight throughout their use?
- Data Quality Management (INFORMATIONAL)Can the organization demonstrate that high-risk AI systems achieve appropriate levels of accuracy, robustness, and cybersecurity throughout their lifecycle?
Strategic Initiatives
- AI Risk Assessment (HIGH)Can the organization demonstrate that high-risk AI systems are designed for effective human oversight throughout their use?
- Data Loss Prevention (HIGH)Can the organization demonstrate that high-risk AI systems achieve appropriate levels of accuracy, robustness, and cybersecurity throughout their lifecycle?
- Bias Detection (HIGH)Can the organization demonstrate that high-risk AI systems achieve appropriate levels of accuracy, robustness, and cybersecurity throughout their lifecycle?
- Data Protection Impact Assessment (HIGH)Can the organization demonstrate that it has established, implemented, documented, and maintained a risk management system for high-risk AI systems throughout their lifecycle?
- Privacy Impact Assessment (HIGH)Can the organization demonstrate that it has established, implemented, documented, and maintained a risk management system for high-risk AI systems throughout their lifecycle?
- Physical Access Control (MEDIUM)Can the organization demonstrate that high-risk AI systems achieve appropriate levels of accuracy, robustness, and cybersecurity throughout their lifecycle?
- Model Monitoring (MEDIUM)Can the organization demonstrate that high-risk AI systems achieve appropriate levels of accuracy, robustness, and cybersecurity throughout their lifecycle?
Compliance Roadmap
Now · Quick Wins
- Access Control
- Authentication
- Encryption At Rest
- Encryption In Transit
Next · Medium Effort
- Key Management
- Data Subject Request Handling
- Consent Management
- Audit Logging
- Privileged Access Management
- Backup And Recovery
- Data Retention
- Incident Response Plan
- Records Of Processing
- Maker Checker
- Model Testing
- Business Impact Analysis
- Data Lifecycle Management
- Grievance Redressal
- Data Masking
- Data Classification
- Policy Management
- Security Awareness Training
- Data Quality Management
Later · Strategic Initiatives
- AI Risk Assessment
- Data Loss Prevention
- Bias Detection
- Data Protection Impact Assessment
- Privacy Impact Assessment
- Physical Access Control
- Model Monitoring
Next Steps
Technical Findings (59)
Showing top 50 of 59, ranked by severity then confidence. Export to JSON or SARIF for the complete list.
Critical
SOC2_CC6_6 — External Threat Protection
Requires Code Changes
Satisfied: Data Classification
Missing: Access Control, Audit Logging, Encryption At Rest, Encryption In Transit, Key Management
packages/server/src/database/entities/Lead.ts:13-14 (data_classification)
packages/server/src/enterprise/database/entities/user.entity.ts:24-25 (data_classification)
packages/server/src/enterprise/Interface.Enterprise.ts:11-11 (data_classification)
packages/components/nodes/documentloaders/Oxylabs/Oxylabs.ts:60-60 (data_classification)
Critical
SOC2_CC6_8 — Unauthorized and Malicious Software Control
Requires Code Changes
Satisfied: Data Classification
Missing: Access Control, Audit Logging, Encryption At Rest, Encryption In Transit, Key Management
packages/server/src/database/entities/Lead.ts:13-14 (data_classification)
packages/server/src/enterprise/database/entities/user.entity.ts:24-25 (data_classification)
packages/server/src/enterprise/Interface.Enterprise.ts:11-11 (data_classification)
packages/components/nodes/documentloaders/Oxylabs/Oxylabs.ts:60-60 (data_classification)
Critical
SOC2_CC6_1 — Logical Access Security Implementation
Requires Code Changes
Satisfied: Authentication, Data Classification
Missing: Access Control, Encryption At Rest, Encryption In Transit, Key Management
packages/server/src/enterprise/sso/GoogleSSO.ts:81-83 (authentication)
packages/server/src/enterprise/sso/Auth0SSO.ts:102-104 (authentication)
packages/server/src/enterprise/utils/emailChangeJwt.util.ts:11-11 (authentication)
packages/server/src/database/entities/Lead.ts:13-14 (data_classification)
packages/server/src/enterprise/sso/Auth0SSO.ts:98-105 (authentication)
packages/server/src/enterprise/middleware/passport/index.ts:379-379 (authentication)
packages/server/src/enterprise/utils/emailChangeJwt.util.ts:19-19 (authentication)
packages/server/src/enterprise/sso/AzureSSO.ts:32-34 (authentication)
packages/server/src/enterprise/middleware/passport/index.ts:410-434 (authentication)
packages/server/src/enterprise/sso/GithubSSO.ts:68-70 (authentication)
packages/server/src/enterprise/sso/AzureSSO.ts:28-35 (authentication)
packages/server/src/IdentityManager.ts:92-94 (authentication)
packages/server/src/enterprise/middleware/passport/index.ts:239-269 (authentication)
packages/server/src/enterprise/database/entities/user.entity.ts:24-25 (data_classification)
packages/server/src/enterprise/middleware/passport/index.ts:361-361 (authentication)
packages/server/src/enterprise/middleware/passport/index.ts:438-462 (authentication)
packages/server/src/enterprise/Interface.Enterprise.ts:11-11 (data_classification)
packages/server/src/enterprise/middleware/passport/index.ts:200-233 (authentication)
packages/server/src/enterprise/sso/GoogleSSO.ts:77-84 (authentication)
packages/server/src/enterprise/services/account.service.ts:117-117 (authentication)
packages/components/nodes/documentloaders/Oxylabs/Oxylabs.ts:60-60 (data_classification)
packages/server/src/enterprise/sso/GithubSSO.ts:64-71 (authentication)
Critical
SOC2_CC6_4 — Physical Access Restriction
Requires Code Changes
Satisfied: Authentication, Data Classification
Missing: Access Control, Encryption At Rest, Encryption In Transit, Key Management
packages/server/src/enterprise/sso/GoogleSSO.ts:81-83 (authentication)
packages/server/src/enterprise/sso/Auth0SSO.ts:102-104 (authentication)
packages/server/src/enterprise/utils/emailChangeJwt.util.ts:11-11 (authentication)
packages/server/src/database/entities/Lead.ts:13-14 (data_classification)
packages/server/src/enterprise/sso/Auth0SSO.ts:98-105 (authentication)
packages/server/src/enterprise/middleware/passport/index.ts:379-379 (authentication)
packages/server/src/enterprise/utils/emailChangeJwt.util.ts:19-19 (authentication)
packages/server/src/enterprise/sso/AzureSSO.ts:32-34 (authentication)
packages/server/src/enterprise/middleware/passport/index.ts:410-434 (authentication)
packages/server/src/enterprise/sso/GithubSSO.ts:68-70 (authentication)
packages/server/src/enterprise/sso/AzureSSO.ts:28-35 (authentication)
packages/server/src/IdentityManager.ts:92-94 (authentication)
packages/server/src/enterprise/middleware/passport/index.ts:239-269 (authentication)
packages/server/src/enterprise/database/entities/user.entity.ts:24-25 (data_classification)
packages/server/src/enterprise/middleware/passport/index.ts:361-361 (authentication)
packages/server/src/enterprise/middleware/passport/index.ts:438-462 (authentication)
packages/server/src/enterprise/Interface.Enterprise.ts:11-11 (data_classification)
packages/server/src/enterprise/middleware/passport/index.ts:200-233 (authentication)
packages/server/src/enterprise/sso/GoogleSSO.ts:77-84 (authentication)
packages/server/src/enterprise/services/account.service.ts:117-117 (authentication)
packages/components/nodes/documentloaders/Oxylabs/Oxylabs.ts:60-60 (data_classification)
packages/server/src/enterprise/sso/GithubSSO.ts:64-71 (authentication)
Critical
SOC2_CC6_2 — User Registration and Authorization
Requires Code Changes
Satisfied: Authentication
Missing: Access Control
packages/server/src/enterprise/sso/GoogleSSO.ts:81-83 (authentication)
packages/server/src/enterprise/sso/Auth0SSO.ts:102-104 (authentication)
packages/server/src/enterprise/utils/emailChangeJwt.util.ts:11-11 (authentication)
packages/server/src/enterprise/sso/Auth0SSO.ts:98-105 (authentication)
packages/server/src/enterprise/middleware/passport/index.ts:379-379 (authentication)
packages/server/src/enterprise/utils/emailChangeJwt.util.ts:19-19 (authentication)
packages/server/src/enterprise/sso/AzureSSO.ts:32-34 (authentication)
packages/server/src/enterprise/middleware/passport/index.ts:410-434 (authentication)
packages/server/src/enterprise/sso/GithubSSO.ts:68-70 (authentication)
packages/server/src/enterprise/sso/AzureSSO.ts:28-35 (authentication)
packages/server/src/IdentityManager.ts:92-94 (authentication)
packages/server/src/enterprise/middleware/passport/index.ts:239-269 (authentication)
packages/server/src/enterprise/middleware/passport/index.ts:361-361 (authentication)
packages/server/src/enterprise/middleware/passport/index.ts:438-462 (authentication)
packages/server/src/enterprise/middleware/passport/index.ts:200-233 (authentication)
packages/server/src/enterprise/sso/GoogleSSO.ts:77-84 (authentication)
packages/server/src/enterprise/services/account.service.ts:117-117 (authentication)
packages/server/src/enterprise/sso/GithubSSO.ts:64-71 (authentication)
Critical
SOC2_CC6_3 — Access Authorization, Modification, and Removal
Requires Code Changes
Satisfied: Authentication
Missing: Access Control
packages/server/src/enterprise/sso/GoogleSSO.ts:81-83 (authentication)
packages/server/src/enterprise/sso/Auth0SSO.ts:102-104 (authentication)
packages/server/src/enterprise/utils/emailChangeJwt.util.ts:11-11 (authentication)
packages/server/src/enterprise/sso/Auth0SSO.ts:98-105 (authentication)
packages/server/src/enterprise/middleware/passport/index.ts:379-379 (authentication)
packages/server/src/enterprise/utils/emailChangeJwt.util.ts:19-19 (authentication)
packages/server/src/enterprise/sso/AzureSSO.ts:32-34 (authentication)
packages/server/src/enterprise/middleware/passport/index.ts:410-434 (authentication)
packages/server/src/enterprise/sso/GithubSSO.ts:68-70 (authentication)
packages/server/src/enterprise/sso/AzureSSO.ts:28-35 (authentication)
packages/server/src/IdentityManager.ts:92-94 (authentication)
packages/server/src/enterprise/middleware/passport/index.ts:239-269 (authentication)
packages/server/src/enterprise/middleware/passport/index.ts:361-361 (authentication)
packages/server/src/enterprise/middleware/passport/index.ts:438-462 (authentication)
packages/server/src/enterprise/middleware/passport/index.ts:200-233 (authentication)
packages/server/src/enterprise/sso/GoogleSSO.ts:77-84 (authentication)
packages/server/src/enterprise/services/account.service.ts:117-117 (authentication)
packages/server/src/enterprise/sso/GithubSSO.ts:64-71 (authentication)
Critical
EU_AI_ART_20_001 — Corrective Actions and Duty of Information
Requires Code Changes
Missing: Audit Logging
Critical
EU_AI_ART_27_001 — Fundamental Rights Impact Assessment
Requires Code Changes
Missing: Consent Management
Critical
EU_AI_ART_5_001 — Prohibition of Subliminal Manipulative Techniques
Requires Code Changes
Missing: Consent Management
Critical
EU_AI_ART_5_002 — Prohibition of Exploiting Vulnerabilities
Requires Code Changes
Missing: Consent Management
Critical
EU_AI_ART_5_003 — Prohibition of Social Scoring
Requires Code Changes
Missing: Consent Management
Critical
EU_AI_ART_5_004 — Prohibition of Predictive Policing Risk Assessments Based Solely on Profiling
Requires Code Changes
Missing: Consent Management
Critical
EU_AI_ART_5_006 — Prohibition of Emotion Recognition in Workplace and Education
Requires Code Changes
Missing: Consent Management
Critical
EU_AI_ART_5_007 — Prohibition of Biometric Categorisation for Sensitive Characteristics
Requires Code Changes
Missing: Consent Management
Critical
EU_AI_ART_5_008 — Restrictions on Real-Time Remote Biometric Identification for Law Enforcement
Requires Code Changes
Missing: Consent Management
Critical
EU_AI_ART_73_001 — Reporting of Serious Incidents
Requires Code Changes
Missing: Audit Logging
Critical
SOC2_CC7_3 — Security Event Evaluation
Requires Code Changes
Missing: Audit Logging
Critical
SOC2_CC7_4 — Incident Response Program Execution
Requires Code Changes
Missing: Audit Logging
Critical
SOC2_P6_6 — Notification of Breaches and Incidents
Requires Code Changes
Missing: Audit Logging, Consent Management
High
SOC2_CC6_5 — Discontinuation of Protections
Requires Code Changes
Satisfied: Data Classification
Missing: Access Control, Data Lifecycle Management, Encryption At Rest, Encryption In Transit, Key Management
packages/server/src/database/entities/Lead.ts:13-14 (data_classification)
packages/server/src/enterprise/database/entities/user.entity.ts:24-25 (data_classification)
packages/server/src/enterprise/Interface.Enterprise.ts:11-11 (data_classification)
packages/components/nodes/documentloaders/Oxylabs/Oxylabs.ts:60-60 (data_classification)
High
SOC2_P3_1 — Collection of Personal Information
Requires Code Changes
Satisfied: Data Classification
Missing: Access Control, Consent Management, Encryption At Rest, Encryption In Transit, Key Management
packages/server/src/database/entities/Lead.ts:13-14 (data_classification)
packages/server/src/enterprise/database/entities/user.entity.ts:24-25 (data_classification)
packages/server/src/enterprise/Interface.Enterprise.ts:11-11 (data_classification)
packages/components/nodes/documentloaders/Oxylabs/Oxylabs.ts:60-60 (data_classification)
High
SOC2_P4_1 — Limitation of Personal Information Use
Requires Code Changes
Satisfied: Data Classification
Missing: Access Control, Consent Management, Encryption At Rest, Encryption In Transit, Key Management
packages/server/src/database/entities/Lead.ts:13-14 (data_classification)
packages/server/src/enterprise/database/entities/user.entity.ts:24-25 (data_classification)
packages/server/src/enterprise/Interface.Enterprise.ts:11-11 (data_classification)
packages/components/nodes/documentloaders/Oxylabs/Oxylabs.ts:60-60 (data_classification)
High
SOC2_P5_1 — Data Subject Access to Personal Information
Requires Code Changes
Satisfied: Data Classification
Missing: Access Control, Consent Management, Encryption At Rest, Encryption In Transit, Key Management
packages/server/src/database/entities/Lead.ts:13-14 (data_classification)
packages/server/src/enterprise/database/entities/user.entity.ts:24-25 (data_classification)
packages/server/src/enterprise/Interface.Enterprise.ts:11-11 (data_classification)
packages/components/nodes/documentloaders/Oxylabs/Oxylabs.ts:60-60 (data_classification)
High
SOC2_CC6_7 — Information Transmission and Movement Restriction
Requires Code Changes
Satisfied: Authentication, Data Classification
Missing: Access Control, Encryption At Rest, Encryption In Transit, Key Management
packages/server/src/enterprise/sso/GoogleSSO.ts:81-83 (authentication)
packages/server/src/enterprise/sso/Auth0SSO.ts:102-104 (authentication)
packages/server/src/enterprise/utils/emailChangeJwt.util.ts:11-11 (authentication)
packages/server/src/database/entities/Lead.ts:13-14 (data_classification)
packages/server/src/enterprise/sso/Auth0SSO.ts:98-105 (authentication)
packages/server/src/enterprise/middleware/passport/index.ts:379-379 (authentication)
packages/server/src/enterprise/utils/emailChangeJwt.util.ts:19-19 (authentication)
packages/server/src/enterprise/sso/AzureSSO.ts:32-34 (authentication)
packages/server/src/enterprise/middleware/passport/index.ts:410-434 (authentication)
packages/server/src/enterprise/sso/GithubSSO.ts:68-70 (authentication)
packages/server/src/enterprise/sso/AzureSSO.ts:28-35 (authentication)
packages/server/src/IdentityManager.ts:92-94 (authentication)
packages/server/src/enterprise/middleware/passport/index.ts:239-269 (authentication)
packages/server/src/enterprise/database/entities/user.entity.ts:24-25 (data_classification)
packages/server/src/enterprise/middleware/passport/index.ts:361-361 (authentication)
packages/server/src/enterprise/middleware/passport/index.ts:438-462 (authentication)
packages/server/src/enterprise/Interface.Enterprise.ts:11-11 (data_classification)
packages/server/src/enterprise/middleware/passport/index.ts:200-233 (authentication)
packages/server/src/enterprise/sso/GoogleSSO.ts:77-84 (authentication)
packages/server/src/enterprise/services/account.service.ts:117-117 (authentication)
packages/components/nodes/documentloaders/Oxylabs/Oxylabs.ts:60-60 (data_classification)
packages/server/src/enterprise/sso/GithubSSO.ts:64-71 (authentication)
High
EU_AI_ART_10_003 — Processing of Special Categories of Personal Data for Bias Detection
Requires Code Changes
Missing: Consent Management
High
EU_AI_ART_12_001 — Logging Capabilities
Requires Code Changes
Missing: Audit Logging
High
EU_AI_ART_13_001 — Transparency and Instructions for Use
Requires Code Changes
Missing: Consent Management
High
EU_AI_ART_18_001 — Documentation Keeping
Requires Code Changes
Missing: Data Lifecycle Management
High
EU_AI_ART_19_001 — Retention of Automatically Generated Logs
Requires Code Changes
Missing: Audit Logging, Data Lifecycle Management, Data Retention
High
EU_AI_ART_22_001 — Authorised Representative of Providers Established in Third Countries
Requires Code Changes
Missing: Access Control
High
EU_AI_ART_27_002 — Notification of Fundamental Rights Impact Assessment
Requires Code Changes
Missing: Audit Logging
High
EU_AI_ART_50_001 — Transparency - Interaction with AI Systems
Requires Code Changes
Missing: Consent Management
High
EU_AI_ART_50_003 — Transparency - Emotion Recognition and Biometric Categorisation
Requires Code Changes
Missing: Consent Management
High
EU_AI_ART_50_004 — Disclosure of Deep Fakes and AI-Generated Text
Requires Code Changes
Missing: Consent Management
High
EU_AI_ART_54_001 — Authorised Representatives of Providers of General-Purpose AI Models
Requires Code Changes
Missing: Access Control
High
EU_AI_ART_72_001 — Post-Market Monitoring System
Requires Code Changes
Missing: Audit Logging
High
EU_AI_ART_86_001 — Right to Explanation of Individual Decision-Making
Requires Code Changes
Missing: Consent Management
High
SOC2_A1_3 — Recovery Plan Testing
Requires Code Changes
Missing: Audit Logging
High
SOC2_C1_2 — Disposal of Confidential Information
Requires Code Changes
Missing: Data Lifecycle Management
High
SOC2_CC4_1 — Ongoing and Separate Evaluations
Requires Code Changes
Missing: Audit Logging
High
SOC2_CC4_2 — Evaluation and Communication of Deficiencies
Requires Code Changes
Missing: Audit Logging
High
SOC2_CC7_1 — Detection and Monitoring of Vulnerabilities
Requires Code Changes
Missing: Audit Logging
High
SOC2_CC7_2 — Anomaly Monitoring and Analysis
Requires Code Changes
Missing: Audit Logging
High
SOC2_CC7_5 — Recovery from Security Incidents
Requires Code Changes
Missing: Audit Logging
High
SOC2_CC8_1 — Change Management
Requires Code Changes
Missing: Audit Logging
High
SOC2_CC9_2 — Vendor and Business Partner Risk Management
Requires Code Changes
Missing: Access Control
High
SOC2_P1_1 — Privacy Notice to Data Subjects
Requires Code Changes
Missing: Consent Management
High
SOC2_P1_2 — Privacy Notice Maintenance
Requires Code Changes
Missing: Consent Management
High
SOC2_P2_1 — Choice and Consent Communication
Requires Code Changes
Missing: Consent Management
High
SOC2_P3_2 — Explicit Consent for Collection
Requires Code Changes
Missing: Consent Management
Repository Intelligence Profile
1851 files · 309899 lines · complexity 1.00
languagetypescript
languagejsx
languagetsx
languagejavascript
frameworkExpress
frameworkReact
authAuthentication
encryptionEncryption
loggingAudit Logging
containerDocker
iacGitHub Actions
containerDocker Compose
ai_frameworkOpenAI SDK
ai_frameworkLlamaIndex
ai_frameworkLangChain
databaseRedis
vector_databaseChromaDB
vector_databaseWeaviate
ai_infrastructureOllama
AI Governance Summary
Critical AI Findings
23
AI frameworksOpenAI SDK, LlamaIndex, LangChain
AI infrastructureOllama
Vector databasesChromaDB, Weaviate
Notebooks0
AI regulations evaluatedEU Artificial Intelligence Act
Not mapped (no real control data available): ISO_42001, NIST_AI_RMF, OECD_AI_PRINCIPLES