feat(KI-10): compliance pack scaffold + baseline re-scan #103
Merged
syntropicagent opened 3 weeks ago

KI-10 — Operational and Data Compliance (v1.1-hardening)

Status: DRAFT — scaffolding only. Baseline re-scan confirms the gap; ISMS docs next.

What this PR does now

  • Adds docs/compliance/ pack: README.md + baseline-rescan-2026-08.md
  • Re-scans 15 compliance areas on v1.0.0 (main @ c92e2ff)

Baseline verdict (unchanged from original assessment)

FrameworkReadiness
SOC 2 Type I~70% — strong technical controls, missing policy docs
ISO 27001:2022~55% — good controls, missing ISMS documentation

Technical controls verified present: SOPS secrets, gateway auth (12 tests), event/scheduler durability, checksummed migrations, nightly verified backup, carbon-credit custody, EAS attestation integrity, CI supply-chain scanning (pip-audit/semgrep/slither).

Gap this branch closes (next commits)

  1. Formal ISMS policy (isms-policy.md)
  2. Consolidated risk register (risk-register.md)
  3. Access-control matrix + data residency/retention (data-handling.md) — prereq for KI-8
  4. Control mapping SOC2 CC / ISO 27001 A.5–A.8 (control-mapping.md) — prereq for KI-11
  5. Evidence collection wired into scripts/verify-platform.sh

Out of scope

  • No new infrastructure, no schema changes
  • SOC 2 Type II 6–12mo observation window = explicit follow-up (not blockable here)

CI

Will run on push. Note: test_migration.py needs the SOPS age key (host-only) and is expected to pass in CI/staging, not local.

Refs KI-10 · iteration v1.1-hardening

Commits were merged into target branch
1/1
Submitter syntropicagent
Target main
Source feat/ki10-compliance-hardening
Jobs
Merge Strategy
Create Merge Commit
Watchers (1)
Reference
pr KI-103
Please wait...
Connection lost or session expired, reload to recover
Page is in error, reload to recover