Shadow Warden AI — Gateway v7.0 — Explore the API Reference
Home / Doc / Compliance

Compliance & Privacy

GDPR Art.35 DPIA, SOC 2 Type II, SLA, secrets governance — all shipped.

✓ GDPR Art. 17 & 35 ✓ SOC 2 Type II ✓ OWASP LLM Top 10 ✓ STIX 2.1 ✓ FIPS 203/204 PQC ✓ ISO 27001 (partial)
CP-01

GDPR Export & Purge APIs

✅ Shipped

Art. 17 right-to-erasure. Export/purge endpoints. Metadata-only logging — content never stored.

All v3.0
CP-02

GDPR Art. 35 DPIA

✅ Shipped

Full Data Protection Impact Assessment. Necessity, proportionality, risk mitigation analysis documented.

All v3.5
CP-03

SOC 2 Type II Evidence

✅ Shipped

Control mapping + auditor collection procedures. Pre-built evidence bundles from MinIO. ScreencastRecorder.

Pro+ v4.0
CP-04

Secrets Governance

✅ Shipped

5 vault connectors (AWS SM, Azure KV, HashiCorp, GCP SM, Env). SQLite inventory. Expiry alerts, rotation.

Community Business+ v4.9
CP-05

Multi-tenant Auth (Fail-closed)

✅ Shipped

Per-tenant API keys. SHA-256 constant-time compare. Startup raises RuntimeError if key unset.

All v4.7
CP-22

ISO 27001 Annex A control mapping

📋 Planned

Map platform controls to ISO 27001 Annex A, providing clear evidence of compliance with international information security standards.

Enterprise
CP-23

HIPAA technical safeguards attestation (encryption, audit, access control)

📋 Planned

Attestation of HIPAA-required technical safeguards: encryption in transit and at rest, comprehensive audit logging, and role-based access control.

Enterprise
CP-24

NIS2 Directive compliance report

📋 Planned

Generate compliance reports meeting NIS2 Directive requirements for critical infrastructure and digital services — risk management, incident response, and supply chain security.

Enterprise
CP-25

Continuous compliance scoring dashboard — real-time SOC 2 / GDPR / ISO posture

📋 Planned

Real-time dashboard that continuously scores compliance posture against SOC 2, GDPR, and ISO 27001, enabling instant visibility into regulatory alignment.

Pro+
CP-26

Data retention policy enforcement — tenant-configurable per data_class

✅ Shipped

Tenant-configurable data retention policies per data_class with automatic enforcement and deletion schedules to meet compliance requirements.

Community+
TQ-01

SWFE Fake Context

✅ Shipped

Unified fake activation via mock.patch. X-Simulation-ID isolation. FakeAnthropicClient, FakeS3Storage.

All v3.0
TQ-02

Scenario DSL

✅ Shipped

ScenarioRunner + ScenarioStep with smart_retry. YAML loader. XAI causal-chain hint on failure.

All v4.11
TQ-03

Mutation Testing

✅ Shipped

mutmut on secret_redactor.py + semantic_guard.py. Threshold: 20 surviving mutants. Linux/WSL/CI only.

All v2.0
TQ-04

k6 Load Tests

✅ Shipped

Realistic traffic simulation. 1000+ RPS sustained. Latency SLO validation. CI-integrated.

All v3.5
TQ-05

Coverage Gate ≥75%

✅ Shipped

pytest --cov-fail-under=75. Matrix: Python 3.11 + 3.12. Adversarial tests informational (||true).

All v1.0
CP-30

Real-time Compliance Dashboard

✅ Shipped

Live multi-source compliance scoring (GDPR/SOC2/ISO27001/HIPAA) with automated gap detection, remediation guidance, WebSocket updates, portal self-service page, and SOVA tools for AI-assisted compliance management.

Pro+ v5.5