-
Migrated from Linear KKN-203. Original: https://linear.app/kokonut/issue/KKN-203/operational-and-data-compliance
-
Previous Value Current Value empty v1.1-hardening
-
OneDev
changed state to 'In Progress' 3 weeks ago
Previous Value Current Value Open
In Progress
-
-
-
State changed as pull request KI-103 is open
-
OneDev
changed state to 'In Review' 3 weeks ago
Previous Value Current Value In Progress
In Review
-
v1.1-hardening outcome (2026-08-25)
CI #429 green. PR KI-103 merged-ready (branch feat/ki10-compliance-hardening).
Baseline re-scan confirmed on v1.0.0: SOC2 Type I ~70%, ISO 27001 ~55% — unchanged from the original assessment (strong technical controls, ISMS layer was the gap).
This branch CLOSES that gap with no infra/schema change:
- docs/compliance/isms-policy.md (ISMS, ISO A.5-A.8)
- docs/compliance/risk-register.md (10 risks LxI)
- docs/compliance/data-handling.md — residency/retention, PREREQ for KI-8
- docs/compliance/control-mapping.md — SOC2 CC / ISO traceability, PREREQ for KI-11
- scripts/verify-platform.sh emits evidence/verify-.json: 14/14 control checks present
Net effect: readiness is now DOCUMENTED + REPRODUCIBLE (was asserted). SOC2 Type II 6-12mo observation window remains explicit out-of-scope follow-up.
KI-10 -> ready for merge. KI-11 (MiCA) and KI-8 (Replicas) now unblocked by the control/data docs above.
-
-
OneDev
changed state to 'Closed' 2 weeks ago
Previous Value Current Value In Review
Closed
-
| Type |
New Feature
|
| Priority |
Normal
|
| Assignees |
Not assigned
|
Iterations
-
v1.1-hardening Closed
Issue Votes (0)
Migrated from Linear KKN-203 (https://linear.app/kokonut/issue/KKN-203/operational-and-data-compliance)
Certification Compatibility & Readiness Assessment
Executive Summary
Based on thorough exploration of the codebase (15 compliance-relevant areas) and research into 10 certification frameworks, here are the findings:
| Standard | Relevance | Current Readiness | Effort to Achieve | | -- | -- | -- | -- | | SOC 2 Type I | High — B2B data platform, enterprise customers | 70% — Strong technical controls, missing policy docs | 3–4 months | | SOC 2 Type II | High — same as above but requires 6–12 month observation | 70% — Same controls, needs observation period | 9–15 months (6–12 mo observation + 3 mo prep) | | ISO 27001:2022 | High — International gold standard for information security | 55% — Good technical controls, missing ISMS documentation | 6–9 months | | ISO 27701:2025 | High — Privacy extension, directly relevant to farmer PII | 50% — Strong consent/privacy features, needs PIMS framework | 4–6 months (after ISO 27001) | | ISO 14001:2015 | Medium — Environmental management for regenerative ag platform | 30% — Environmental data tracked, no EMS documented | 6–9 months | | ISO 9001:2015 | Medium — Quality management for data products | 40% — Quality processes exist informally, no QMS | 4–6 months | | ISO 22000:2018 | Low-Medium — Food safety if tracking harvest data for food chain | 20% — Harvest tracking exists, no food safety management | 9–12 months | | ISO 27017:2015 | Medium — Cloud security controls for hosted infrastructure | 60% — Docker/Pin/Compose security is strong, needs documentation | 3–4 months | | ISO 27018:2019 | Medium — PII protection in cloud, relevant to farmer data | 50% — Privacy features exist, needs formal cloud PII controls | 3–4 months | | GDPR | High — EU regulation if serving EU farmers/partners | 55% — Consent/portability exist, missing DSAR automation, erasure | 3–6 months |
Detailed Readiness by Area
| Area | Maturity | SOC 2 TSC | ISO 27001:2022 Annex A | Status | | -- | -- | -- | -- | -- | | Audit & Logging | FULL | CC6.1, CC7.2 | A.8.15 | ✅ Audit log, access audit log, ingestion log, agent action log. Missing: log rotation, retention policy | | Access Control | FULL | CC6.1–CC6.3 | A.9 | ✅ RBAC, capability tokens, API keys, rate limiting, agent safety. Missing: access reviews, joiner-mover-leaver | | Data Encryption | PARTIAL | CC6.7 | A.10 | ⚠️ Backup AES-256-CBC, token hashing, Caddy TLS. Missing: DB TDE, field-level PII encryption, gRPC TLS enforced, key rotation | | Data Retention | FULL | CC6.5 | A.8.3 | ✅ Policy table, soft delete, legal hold, enforcement log. Missing: automated scheduling, hard_delete/anonymize/archive | | Incident Response | PARTIAL | CC7.3 | A.16 | ⚠️ Emergency incident table, health alerts. Missing: IRP document, severity taxonomy, escalation matrix, post-incident review | | Change Management | FULL | CC8.1 | A.12 | ✅ Checksummed migrations, drift detection, upgrade/rollback scripts. Missing: CAB approval, non-schema change log | | Risk Management | FULL | CC3.1 | A.1 | ✅ CRISP 5-dimension scoring, threatcasting, backcasting, risk mitigation register. Missing: ISO 31000-aligned risk register, treatment plan | | Business Continuity | PARTIAL | CC9.1 | A.17, A.5.30 | ⚠️ Encrypted backup/restore scripts. Missing: automated scheduling, offsite replication, RPO/RTO targets, DR testing | | Data Classification | ABSENT | CC6.1 | A.8.2 | ❌ No formal classification scheme. Need: Public/Internal/Confidential/Restricted labels, handling procedures | | Third-Party Risk | ABSENT | CC9.2 | A.15 | ❌ No vendor register, assessment, or review process. Need: vendor inventory, risk questionnaires, contractual requirements | | Privacy & Consent | FULL | P1.1 | A.18 | ✅ Consent management, portability, sharing agreements, selective disclosure, append-only logs. Missing: DSAR automation, right to erasure cascade, PIA process, DPO designation | | Monitoring & Alerting | FULL | CC7.1, CC7.2 | A.12 | ✅ Health checks, alerting, anomaly detection, data freshness. Missing: centralized monitoring dashboard, SLA/SLO tracking, log aggregation | | Evidence & Traceability | FULL | CC7.4 | A.8.10 | ✅ Evidence lineage graph, provenance, chain of custody, IRI system, RDF triples, content hashing, immutability triggers | | Governance Frameworks | FULL | CC1.1, CC2.1 | A.5 | ✅ 200+ governed collections, lifecycle enforcement, decision policies, agent safety, governance circles | | Agent Safety | FULL | CC6.1 | A.6.2 | ✅ Pre-write safety assessment, high-risk action blocking, payload hashing, execution allowlist, DB-level enforcement |
Recommended Certification Path
Based on readiness, effort, and business value:
Phase 1: SOC 2 Type I (3–4 months)
Why first: Lowest documentation overhead, highest market value for B2B sales. SOC 2 is an attestation (auditor examines controls), not a certification (formal audit against a standard). It's faster and cheaper than ISO 27001.
Gap closure required:
Already strong: Audit logging, access control, encryption (backups), change management, risk management, monitoring, evidence traceability, governance frameworks.
Phase 2: SOC 2 Type II (6–12 months observation after Phase 1)
Same controls as Type I but audited over a 6–12 month observation period. Begin observation window immediately after Type I report.
Phase 3: ISO 27001:2022 (6–9 months)
Why next: International recognition, builds on SOC 2 foundation, 93 Annex A controls across 4 themes (Organizational, People, Physical, Technological).
Gap closure required (on top of SOC 2):
Phase 4: ISO 27701:2025 (4–6 months, after ISO 27001)
Why: Directly relevant to farmer PII protection. Extends ISO 27001 with privacy controls.
Already strong: Consent management, data portability, privacy-preserving attestations, selective disclosure, append-only consent logs.
Gap closure required:
Phase 5: ISO 27017/27018 (3–4 months, can run parallel with Phase 4)
Cloud security and PII protection in cloud. Relevant because the platform runs on Docker/PostgreSQL/ClickHouse infrastructure.
Gap closure required:
Phase 6 (Optional): ISO 14001 + ISO 9001 (6–9 months)
ISO 14001: Only if the platform wants to formalize environmental management (relevant for regenerative agriculture brand).
ISO 9001: Only if the platform wants to formalize quality management for data products.
Key Decision Points
SOC 2 Type I Implementation Plan
Scope & System Boundaries
System Description: Kokonut Intelligence — a regenerative agriculture data platform processing farmer identity data, on-chain attestations, metric computation, and governance workflows.
In Scope:
services/)extensions/kokonut-hooks/)Out of Scope:
Trust Service Criteria (All 5)
| Criteria | Why Relevant | | -- | -- | | Security (Common Criteria) | Mandatory. Protects against unauthorized access, data breaches. | | Availability | Platform uptime SLAs for farmers and partners. | | Processing Integrity | Metric computation, credit issuance, governance decisions must be accurate. | | Confidentiality | Farmer PII (names, KYC, locations), financial data. | | Privacy | Farmer consent, data portability, selective disclosure. |
Gap Closure Tasks (Organized by Priority)
Phase 1: Policy Foundation (Weeks 1–4)
P1.1 — Information Security Policy
docs/policies/information-security-policy.mdP1.2 — Acceptable Use Policy
docs/policies/acceptable-use-policy.mdP1.3 — Data Classification Policy
docs/policies/data-classification-policy.mdP1.4 — Incident Response Plan
docs/policies/incident-response-plan.mdP1.5 — Change Management Policy
docs/policies/change-management-policy.mdP1.6 — Vendor/Third-Party Management Policy
docs/policies/vendor-management-policy.mdP1.7 — Acceptable Use & Security Awareness Training
docs/policies/security-awareness-training.mdP1.8 — Code of Ethics
docs/policies/code-of-ethics.mdPhase 2: Technical Controls (Weeks 2–8)
P2.1 — Data Classification Implementation
data_classificationcolumn to key tables (farmer_identity, consent_record, expense_event, revenue_event, etc.)P2.2 — Access Review Process
docs/procedures/access-review.md+ quarterly review scriptP2.3 — Log Retention Policy Enforcement
retention_policyseeds with log-specific retention periodsP2.4 — Encryption Enhancement
pgcryptoor application-level encryptionP2.5 — Centralized Logging
P2.6 — Business Continuity Plan
docs/business-continuity-plan.mdP2.7 — Backup Scheduling
config/worker/crontabto add daily encrypted backup + upload to offsite storageP2.8 — TLS for gRPC
services/grpc/server.pyandservices/grpc/cli.pyto use TLS certificatesPhase 3: Documentation & Audit Prep (Weeks 6–12)
P3.1 — SOC 2 System Description
docs/compliance/soc2-system-description.mdP3.2 — Control Evidence Matrix
docs/compliance/control-evidence-matrix.csvP3.3 — Risk Assessment Register
docs/compliance/risk-assessment.mdP3.4 — Privacy Impact Assessment (PIA)
docs/compliance/privacy-impact-assessment.mdP3.5 — DSAR (Data Subject Access Request) Process
docs/procedures/dsar-process.md+ automation scriptP3.6 — Right to Erasure Cascade
P3.7 — Secure Development Lifecycle (SDLC) Documentation
docs/policies/secure-development-policy.mdP3.8 — Vendor Risk Assessment Template
docs/compliance/vendor-risk-questionnaire.mdPhase 4: Operational Readiness (Weeks 10–16)
P4.1 — Tabletop Exercise (Incident Response)
P4.2 — DR Test
P4.3 — Access Certification
P4.4 — SOC 2 Readiness Self-Assessment
docs/compliance/soc2-readiness-self-assessment.mdP4.5 — Auditor Engagement
Timeline Summary
| Phase | Duration | Key Deliverables | | -- | -- | -- | | Phase 1: Policy Foundation | Weeks 1–4 | 8 policy documents | | Phase 2: Technical Controls | Weeks 2–8 | Data classification, encryption, logging, BCP | | Phase 3: Documentation & Audit Prep | Weeks 6–12 | System description, evidence matrix, PIA, DSAR | | Phase 4: Operational Readiness | Weeks 10–16 | Tabletop, DR test, self-assessment, auditor | | Total | 16 weeks (4 months) | SOC 2 Type I report |
Resource Requirements
| Resource | Effort | Cost | | -- | -- | -- | | Internal engineering (you) | ~200–300 hours | Existing team | | Audit firm | 4–6 weeks fieldwork | $15K–$40K | | Legal review (policies) | 2–3 days | $2K–$5K (external counsel) | | Total | \~$20K–$50K | 4 months |
Key Risks
| Risk | Mitigation | | -- | -- | | Policy documentation takes longer than estimated | Start Phase 1 immediately, use templates | | Encryption enhancement delays | Can defer field-level encryption to SOC 2 Type II | | Audit firm availability | Engage firm in Week 6, not Week 14 | | On-chain data cannot be erased (GDPR limitation) | Document in PIA as technical limitation with legal basis |
Immediate Next Steps
docs/policies/anddocs/compliance/Want me to proceed with creating the policy directory and starting with the Information Security Policy? Or would you prefer to adjust the scope (e.g., skip Privacy criteria, focus on Security + Availability only for a faster Type I)?