Work

Things I shipped instead of sleeping.

Some of it pays the bills. Some of it I'd rebuild from scratch tomorrow. Click anything.

more: forge pocs  ·  archive

APIQuotaTracker — Per-Customer Quota Burn + Soft/Hard Limits thumbnail
Utility
Live
2025 · Lead Builder

APIQuotaTracker — Per-Customer Quota Burn + Soft/Hard Limits

22 customers × per-tier quota usage (rps + monthly request count + concurrency). Soft-limit (90% warning), hard-limit (100% throttle). Surfaces 4 customers exceeding soft cap + 2 customers paying enterprise rates but using free-tier quotas (sales misalignment) + 1 burst-pattern customer needing different rate-limit shape.

RFC 6585OWASP API4:2023SOC2 CC6.6
ChildSafetyCheck — KOSA + COPPA + Age Appropriate Design Code Audit thumbnail
Utility
Live
2025 · Lead Builder

ChildSafetyCheck — KOSA + COPPA + Age Appropriate Design Code Audit

22 platform behaviors checked against US KOSA + COPPA, UK Age Appropriate Design Code (Children's Code), Texas SCOPE Act, EU DSA Art 28, Utah Social Media Regulation Act. Per behavior: applicable jurisdiction, current implementation, gap, mitigation. 21 of 22 compliant; 1 gap on knowledge-of-minor inferred from behavior.

COPPA 16 CFR §312KOSAUK AADC
CookieDeprecation — 3p-Cookie Sunset + Privacy Sandbox Readiness thumbnail
Utility
Live
2025 · Lead Builder

CookieDeprecation — 3p-Cookie Sunset + Privacy Sandbox Readiness

22 third-party cookie use cases × Chrome 3p-cookie deprecation + Privacy Sandbox APIs (Topics, Protected Audience, Attribution Reporting, Storage Access, FedCM, CHIPS). Per use case: current implementation, replacement API, readiness state, Safari/Firefox fallback (already blocking).

Privacy SandboxTopics APIProtected Audience
DataResidencyMap — Per-Customer Residency Commitments vs Actual Storage thumbnail
Utility
Live
2025 · Lead Builder

DataResidencyMap — Per-Customer Residency Commitments vs Actual Storage

22 customer contracts × residency commitments (EU-only / US-only / no-restriction / China-only / KSA-only / UK-only / FedRAMP) vs actual storage location across our 12 data services. Surfaces 4 customers with data leaking to non-contracted regions + 2 ambiguous contracts (no residency clause negotiated).

GDPR Art 44-49US CLOUD ActChina CSL/DSL/PIPL
DigitalGovernance — Board-Level Digital-Risk Dashboard (NIST CSF 2.0) thumbnail
Utility
Live
2025 · Lead Builder

DigitalGovernance — Board-Level Digital-Risk Dashboard (NIST CSF 2.0)

14 NIST CSF 2.0 categories scored across the 6 functions (GOVERN + IDENTIFY + PROTECT + DETECT + RESPOND + RECOVER) with 4-tier maturity model. Per category: trend vs last quarter, top finding, owner, board-action recommendation. The artifact every public-company audit committee asks for under the SEC Cyber Disclosure Rule.

NIST CSF 2.0SEC Cyber Disclosure RuleNACD Director's Handbook
ImageContentMod — CSAM Hash-Match Queue (NCMEC + IWF + Apple NeuralHash) thumbnail
Utility
Live
2025 · Lead Builder

ImageContentMod — CSAM Hash-Match Queue (NCMEC + IWF + Apple NeuralHash)

22 image-moderation hits across PhotoDNA hash-match, AI classifier, IWF list, NCMEC list, Apple NeuralHash, user reports. Per hit: source, classifier confidence, NCMEC CyberTipline reporting status (US 18 USC §2258A 24-hour reporting), false-positive triage. Surfaces verified hash-matches + GENAI synthetic-CSAM cases.

18 USC §2258AUK Online Safety Act 2023EU CSA Reg
OpenBankingScopes — PSD2 / Open Banking OAuth Scope Audit thumbnail
Utility
Live
2025 · Lead Builder

OpenBankingScopes — PSD2 / Open Banking OAuth Scope Audit

22 PSD2 / Open Banking OAuth grants audited. AISP (account info), PISP (payment init), CBPII (card-based payment instrument issuer). Per grant: scope, 90-day reconfirmation status (RTS on SCA), SCA exemptions used, FAPI 2.0 conformance. Surfaces 4 past-90d reconfirmation + 2 with insufficient SCA + 1 deprecated FAPI 1.0.

PSD2 Reg 2015/2366FAPI 2.0OBIE
PhishingSimResults — Quarterly Phishing-Sim Results per Team thumbnail
Utility
Live
2025 · Lead Builder

PhishingSimResults — Quarterly Phishing-Sim Results per Team

8 teams × 4 quarters of phishing-sim results. Per team: click-rate (target <5%), report-rate (target >50%), repeat-clicker count, supplemental training assigned. Surfaces 2 teams with chronic high click-rate (Sales + Marketing) + 1 team with declining report-rate (Marketing Q4).

NIST SP 800-50PCI-DSS Req 12.6KnowBe4 + Hoxhunt benchmarks
ServiceMeshAudit — Sidecar mTLS + Zero-Trust Network Policy Coverage thumbnail
Utility
Live
2025 · Lead Builder

ServiceMeshAudit — Sidecar mTLS + Zero-Trust Network Policy Coverage

22 services × Istio/Linkerd sidecar mTLS coverage, zero-trust NetworkPolicy presence, deny-by-default verification, JWT-on-request enforcement, mesh-version. Surfaces 4 services without mTLS in mesh + 2 with permissive NetworkPolicy + 1 with mesh outdated (Istio 1.18 EOL).

NIST SP 800-207 Zero TrustIstio 1.23Linkerd 2.16
AICardSummary — Model Card Generator (NIST AI RMF + EU AI Act Annex IV) thumbnail
Utility
Live
2025 · Lead Builder

AICardSummary — Model Card Generator (NIST AI RMF + EU AI Act Annex IV)

Interactive model-card generator. Inputs: model name + intended use + out-of-scope use + training data + eval results + bias analysis + mitigations + governance. Live preview + HTML/Markdown export. Conforms to NIST AI RMF + EU AI Act Annex IV (high-risk AI system documentation, mandatory from 2026).

NIST AI RMF 1.0EU AI Act Annex IVISO/IEC 42001 §8.4
CrossBorderTransferLog — Personal-Data Cross-Border Transfer Register thumbnail
Utility
Live
2025 · Lead Builder

CrossBorderTransferLog — Personal-Data Cross-Border Transfer Register

22 active cross-border data transfers with mechanism (SCC 2021/914 / EU-US DPF / adequacy decision / BCR / Art 49 derogation / consent). Per transfer: source jurisdiction, destination, data category, lawful basis, Schrems II TIA, frequency. Surfaces 3 with pending TIA + 1 Art 49 derogation overuse.

GDPR Art 44-49SCC 2021/914EU-US DPF Decision 2023/1795
TabletopExercise — Interactive Incident Tabletop thumbnail
Utility
Live
2025 · Lead Builder

TabletopExercise — Interactive Incident Tabletop

6 incident-tabletop scenarios (ransomware encrypts customer DB; region-wide AWS outage; sub-processor breach disclosure; supply-chain compromise via npm; insider threat exfiltration; AI model jailbreak). Walk through 5 phases per scenario (detect → triage → contain → disclose → recover); pick decisions; see canonical answer + framework-grounded rationale.

SOC2 CC7.5NIST SP 800-61 Rev 2CISA Tabletop Exercise Packages
AccessibleStatement — Public WCAG Conformance Statement Generator thumbnail
Utility
Live
2025 · Lead Builder

AccessibleStatement — Public WCAG Conformance Statement Generator

Interactive WCAG 2.2 AA conformance-statement generator. Inputs: org + URL + conformance target + status + audit date + scope + audit method + auditor + known limitations + contact channel + statement date. Outputs: live-updating EAA + ADA Title III + Section 508 + EN 301 549-aligned conformance statement with HTML and Markdown export. Mandatory disclosure under EAA 2025 (effective 2025-06-28).

WCAG 2.2EN 301 549EAA 2019/882
DataLineage — Column-Level Data Lineage thumbnail
Utility
Live
2025 · Lead Builder

DataLineage — Column-Level Data Lineage

28 columns mapped source → transformations → destinations. Each column carries data classification (direct PII / sensitive / cardholder / aggregate / indirect), every transformation that touches it (PII-scrub, hash, anonymize, redact, generalize), every downstream consumer (warehouse, ML training, partner shares). Surfaces 4 columns flowing raw to ML training without redaction + 2 lineage gaps where the source was lost during platform migration.

GDPR Art 25GDPR Art 30OpenLineage
PromptGovernance — Internal LLM Prompt Registry thumbnail
Utility
Live
2025 · Lead Builder

PromptGovernance — Internal LLM Prompt Registry

24 production prompts × owner + version + model + eval link + change log + safety review. Per prompt: system message, allowed inputs, banned outputs, kill-switch flag. Surfaces 4 prompts without current eval + 2 orphan prompts inherited from former employee + 3 prompts with safety review overdue + 1 prompt without a kill-switch.

NIST AI RMF MAP.4 + MEASURE.2.6EU AI Act Art 50ISO/IEC 42001 §6.2
SREPostmortem — Blameless Post-Mortem Template + Evidence Prompts thumbnail
Utility
Live
2025 · Lead Builder

SREPostmortem — Blameless Post-Mortem Template + Evidence Prompts

Interactive blameless post-mortem template with 5 sections × 18 evidence prompts (summary / impact / timeline / root-cause / actions). Per section: prompts that catch missing evidence, anti-blame language linter, action-item owner + due-date validator, learning-extraction prompts. Live readiness score + Markdown export. Drives the postmortem from ad-hoc to consistent without imposing a single template.

Google SRE Workbook ch. 9Etsy Debriefing GuideSOC2 CC7.4
VendorSpendDrift — Actual vs Budgeted Spend + Renewal Alerts thumbnail
Utility
Live
2025 · Lead Builder

VendorSpendDrift — Actual vs Budgeted Spend + Renewal Alerts

28 vendor contracts × actual vs budgeted spend × renewal-window clock. Per vendor: monthly burn, YTD spend ratio, contract end date, auto-renewal flag, lock-in clauses, alternates. Surfaces 4 vendors over budget (AWS +17%, Datadog +17%, Twilio +23%, Atlassian +11%) + 6 with renewal in <60 days + 1 auto-renewing legacy contract that locks us in within 27 days unless we give notice.

SOC2 CC9.2ASC 842FinOps Foundation
AttestChain — Supply-Chain Attestation Log (SLSA + Sigstore + in-toto) thumbnail
Utility
Live
2025 · Lead Builder

AttestChain — Supply-Chain Attestation Log (SLSA + Sigstore + in-toto)

22 build artifacts (containers + npm + pip + binaries + SDKs) audited against SLSA v1.0 attestation chain. Per artifact: SLSA level (1-4), Sigstore signature, in-toto provenance, SBOM (CycloneDX 1.6), source provenance, runtime verification. Surfaces 4 SLSA Level 1 artifacts (no provenance) + 2 unsigned releases + 1 vendor sidecar mirrored without verification.

SLSA v1.0Sigstorein-toto
DMADSAAudit — EU DMA + DSA Compliance Audit thumbnail
Utility
Live
2025 · Lead Builder

DMADSAAudit — EU DMA + DSA Compliance Audit

32 platform behaviors checked against EU Digital Markets Act 2022/1925 + Digital Services Act 2022/2065. Per finding: applicable article (DMA Art 5/6/7 or DSA Art 14/15/16/24/25/27/30/34/40), gatekeeper-threshold check, self-preferencing audit, dark-pattern detection. Surfaces 3 self-preferencing patterns + 2 dark-pattern UX choices that face EU consumer-law scrutiny even pre-designation.

EU DMA 2022/1925EU DSA 2022/2065EDPB 03/2022
DSARStandingOrder — Auto-Renewing DSAR Erasure Orders thumbnail
Utility
Live
2025 · Lead Builder

DSARStandingOrder — Auto-Renewing DSAR Erasure Orders

24 standing orders that auto-execute every N days for opted-out subjects. Per order: trigger event, scope, cadence, downstream sub-process fan-out, last-execution proof, statutory-hold check. Surfaces 3 standing orders SUSPENDED by legal hold + 1 with sub-processor that needs manual reconfirmation. The artifact that converts one-shot DSARs into reliable ongoing erasure.

GDPR Art 17GDPR Art 21CCPA §1798.105
OAuthConsentLog — Third-Party OAuth Grants ON Your Users thumbnail
Utility
Live
2025 · Lead Builder

OAuthConsentLog — Third-Party OAuth Grants ON Your Users

28 third-party apps with active OAuth grants on YOUR users. Per app: vendor, granted scopes (with criticality), user count, grant age, last-used, vendor-side breach status, recommended action (allow / step-up / review / dormant / consent-renewal-needed / block). Surfaces 4 dormant grants with sensitive scopes + 2 vendors needing user reconsent + 1 unknown-vendor mail.modify grant.

OAuth 2.1 §2.5GDPR Art 7 + Art 28CCPA §1798.115
PayoutRecon — Stripe Payouts vs Internal Ledger Reconciliation thumbnail
Utility
Live
2025 · Lead Builder

PayoutRecon — Stripe Payouts vs Internal Ledger Reconciliation

22 daily payouts reconciled against the internal ledger. Per payout: gross / fee / refunds / disputes / FX-spread / other-adj / Stripe net / ledger expected / variance. Break categories: refund-out-of-period, fee-rate-mismatch, dispute-chargeback, currency-fx-spread, payout-timing-skew, missing-transaction. Surfaces $4,820 in unreconciled breaks + 1 systemic fee-rate misconfiguration.

ASC 606SOX §404PCI-DSS Req 12.4
AccessReviewer — Quarterly Access Review (UAR) Workflow thumbnail
Utility
Live
2025 · Lead Builder

AccessReviewer — Quarterly Access Review (UAR) Workflow

8 reviewers × 142 employees × 12 systems. Per-grant decision (keep / reduce / revoke), justification, escalation, days-to-deadline. Sort by tier-0-system-first, dormant-first, employee, system. Surfaces 4 reviewers chronically overdue + 18 unattested grants on tier-0 systems + the SOC2 CC6.1 audit-trail.

SOC2 CC6.1ISO 27001 A.5.18NIST AC-2
APIErrorBudget — Per-Customer SLA Credit Tracker thumbnail
Utility
Live
2025 · Lead Builder

APIErrorBudget — Per-Customer SLA Credit Tracker

22 customer contracts × per-customer error-budget consumption. Per customer: tier, MSA SLA target, MRR, observed downtime min, 5xx rate, 429 rate, p99 exceedance, credit owed (% of MRR via standard ladder), notification status. Surfaces 4 customers eligible for SLA credit + 2 contracts with SLA mis-aligned with infrastructure reality.

Google SRE Workbook ch. 4AWS SLA ModelSOC2 CC4.1
DependencyDrift — Direct + Transitive Lockfile Audit thumbnail
Utility
Live
2025 · Lead Builder

DependencyDrift — Direct + Transitive Lockfile Audit

38 packages (npm + pip + Apache) audited across direct + transitive. Per package: locked version, latest, semver-distance, days-behind, known CVEs, license, services using. Surfaces 4 packages with version drift across services + 6 with major-version skew + 2 phantom dependencies (in node_modules but not in package.json).

SemVer 2.0.0OWASP A06NTIA SBOM
DRFailoverDrill — Interactive Failover Drill Recorder thumbnail
Utility
Live
2025 · Lead Builder

DRFailoverDrill — Interactive Failover Drill Recorder

14 quarterly DR failover drills logged. Per drill: target service, hypothesis, planned RTO/RPO vs observed, minute-by-minute timeline, deviations from plan, action items shipped vs open, post-mortem cross-references. The actual exercise log SOC2 CC9.1 + ISO 22301 §8.5 demand — including 1 failed drill where the failover path was undocumented.

SOC2 CC9.1ISO 22301 §8.5NIST SP 800-34
SAMLPolicyAudit — SAML / OIDC SSO Policy Audit thumbnail
Utility
Live
2025 · Lead Builder

SAMLPolicyAudit — SAML / OIDC SSO Policy Audit

22 SSO integrations across SAML 2.0, OIDC, SCIM. Per integration: signature algorithm, encryption algorithm, assertion lifetime, signed assertion + signed response + encrypted assertion, NameID format, IdP-init vs SP-init, allowed clock skew, AuthnContextClassRef. Surfaces 4 integrations with weak crypto (SHA-1, RSA-1024) + 2 over-long assertion lifetimes + 1 unsigned-assertion CRITICAL finding.

SAML 2.0OIDCNIST SP 800-63C
CarbonOffsetRegistry — Carbon-Credit Hygiene + Vintage Validation thumbnail
Utility
Live
2025 · Lead Builder

CarbonOffsetRegistry — Carbon-Credit Hygiene + Vintage Validation

20 carbon-credit purchases across 6 registries (Verra VCS, Gold Standard, ACR, CAR, Puro.earth, Climeworks, BioCarbon). Per credit: vintage year, project type, methodology, additionality, permanence, leakage, retirement status, ICVCM CCP screen. Surfaces 3 credits past quality screens (REDD+ avoided-deforestation over-crediting + low-additionality wind farm) + 1 vintage-tournament double-claim risk.

ICVCM CCP 2023SBTi BVCMVCMI Claims Code
OnCallRotation — 12-Week Schedule + Fairness Scoring thumbnail
Utility
Live
2025 · Lead Builder

OnCallRotation — 12-Week Schedule + Fairness Scoring

24 engineers × 12-week on-call schedule. Primary + secondary + follow-the-sun coverage. Fairness scored on 4 axes (weekend equity, holiday equity, page-load equity, time-zone alignment). Surfaces 4 engineers carrying disproportionate weekend duty + 1 timezone-coverage gap (no APAC primary 03:00-09:00 UTC).

Google SRE WorkbookPagerDuty Schedule GuidanceILO Convention 47
VendorOnboardingCheck — 28-Step Vendor Onboarding Pipeline thumbnail
Utility
Live
2025 · Lead Builder

VendorOnboardingCheck — 28-Step Vendor Onboarding Pipeline

14 in-flight vendor onboardings × 28-step pipeline. Commercial intake → spend approval → SIG/CAIQ → SOC2/ISO review → pen-test review → DPA + SCC + DPF + TIA → sanctions screening → MSA → RoPA + DPIA + DPADeskbook → IT integration + SSO → egress firewall + audit hooks → offboarding plan + production access. Surfaces 4 stuck mid-pipeline + 2 with production access before security review.

SOC2 CC9.2GDPR Art 28ISO 27001 A.5.19
WAFRulePolicy — Web Application Firewall Rule Hygiene thumbnail
Utility
Live
2025 · Lead Builder

WAFRulePolicy — Web Application Firewall Rule Hygiene

32 WAF rules across OWASP Core Rule Set 4.x + custom rules. Per rule: action (block / log / count / disabled), 7-day fired/blocked stats, false-positive rate, last-tuned date, paranoia level. Surfaces 4 rules with FP rate >15%, 2 stuck in count-mode for >90 days (decide: promote or remove), 1 rule unfired for 18 months.

OWASP CRS 4.xOWASP Top-10PCI-DSS Req 6.4.2
ChangeRequestQueue — SOC2 CC8.1 Change-Management Board thumbnail
Utility
Live
2025 · Lead Builder

ChangeRequestQueue — SOC2 CC8.1 Change-Management Board

28 RFCs across normal / standard / emergency. Per RFC: requester, reviewer chain, risk class, blast radius, rollback plan, customer notification, sign-off chain with timestamps, pre-deploy checks. Surfaces 4 RFCs awaiting review >14 days, 4 emergency RFCs (with documented post-hoc CAB ratification), and 1 rolled-back change with lessons-learned.

SOC2 CC8.1ITIL 4 Change EnablementNIST CM-3
CodeOwnersAudit — Repo CODEOWNERS Coverage + Bus-Factor Map thumbnail
Utility
Live
2025 · Lead Builder

CodeOwnersAudit — Repo CODEOWNERS Coverage + Bus-Factor Map

22 repos audited. Per repo: CODEOWNERS coverage %, bus-factor (unique owner teams), former-employees still listed, files without an owner, branch-protection coverage, signed-commits enforcement. Surfaces 4 repos with bus-factor 1, 4 repos with stale former-employee owners, and 2 repos with no CODEOWNERS file at all.

GitHub CODEOWNERSSOC2 CC8.1CIS Controls v8 §16
EvidenceCollector — SOC2 / ISO 27001 / HIPAA / PCI Evidence Tracker thumbnail
Utility
Live
2025 · Lead Builder

EvidenceCollector — SOC2 / ISO 27001 / HIPAA / PCI Evidence Tracker

40 evidence requests across 4 frameworks. Per request: source system, collection method (automated / manual), CMMI maturity (1-5), evidence freshness, gap-list. The Vanta / Drata / Secureframe shape — built directly. Surfaces the controls that look 'covered' but actually have manual workflows masking ad-hoc execution.

SOC2 TSC 2017ISO/IEC 27001:2022HIPAA Security Rule
PenTestFindings — Penetration-Test Tracker (CVSS + Retest) thumbnail
Utility
Live
2025 · Lead Builder

PenTestFindings — Penetration-Test Tracker (CVSS + Retest)

28 findings from FY24 annual pen-test. Per finding: CVSS 3.1 base + vector, OWASP / CWE mapping, exploitability rating, evidence, our remediation, retest status. SLA clock per severity (critical 24h, high 7d, medium 30d, low 90d). 4 critical fixed in <2 weeks; 3 past SLA; 2 explicitly accepted as residual risk with documented rationale.

CVSS 3.1OWASP Top-10OWASP API Top-10
PriceParityAudit — Geographic + Cohort Price-Discrimination Audit thumbnail
Utility
Live
2025 · Lead Builder

PriceParityAudit — Geographic + Cohort Price-Discrimination Audit

24 pricing variants across 6 SKUs × 8 markets. Detects geographic discrimination (US vs EU vs APAC vs LATAM), cohort skewing (income-proxy KILLED, mobile-vs-desktop FLAGGED, B2B/B2C OK, AI-personalized KILLED), Robinson-Patman concerns, EU Geo-blocking Reg 2018/302 violations, EU Omnibus 2019/2161 sale-claim provenance.

EU Geo-blocking 2018/302EU Omnibus 2019/2161FTC Robinson-Patman
DeprecationCalendar — RFC 8594 Sunset Rollout thumbnail
Utility
Live
2025 · Lead Builder

DeprecationCalendar — RFC 8594 Sunset Rollout

24 deprecated items (APIs, endpoints, fields, OAuth scopes, SDK versions, formats). Per item: announce date, sunset date, replacement, RFC 8594 Sunset header status, customer migration progress, 7-day traffic on the old path. Surfaces 4 items past sunset still receiving traffic, including the v1 PAN-storage endpoint that triggers a PCI-DSS Req 3.5 finding.

RFC 8594RFC 9745SemVer 2.0.0
IncidentSeveritySim — Severity Classification Trainer thumbnail
Utility
Live
2025 · Lead Builder

IncidentSeveritySim — Severity Classification Trainer

Interactive trainer with 22 incident scenarios across 6 categories. Pick a severity (SEV-1 to SEV-4); get the canonical answer + the 5-dimension impact rationale (blast radius, data sensitivity, customer visibility, regulatory implications, time sensitivity). Tracks accuracy + over-paged + under-paged across the session.

PagerDuty Severity GuidanceGoogle SRE WorkbookNIST SP 800-61
RetentionPolicy — Data Retention Schedule thumbnail
Utility
Live
2025 · Lead Builder

RetentionPolicy — Data Retention Schedule

38 data classes with retention period, source of the rule (regulation / contract / business / legitimate-interest / consent), legal-hold trigger, deletion mechanism, evidence of execution. Surfaces 2 over-retained classes (Twilio SMS, Mixpanel events), 2 with no automated deletion (legacy mongo, ChinaPartnerCo archive), and 2 active legal holds (DOJ subpoena, SEC TCR).

GDPR Art 5(1)(e)FRCP Rule 37(e)5AMLD
TrademarkWatch — IP Watch + Confusability Triage thumbnail
Utility
Live
2025 · Lead Builder

TrademarkWatch — IP Watch + Confusability Triage

22 trademark-watch hits across USPTO TSDR, EUIPO eSearch, WIPO Madrid, and domain registrars. Per hit: 3-axis confusability scoring (phonetic distance + Nice-class overlap + visual similarity), opposition-window clock, decision matrix (oppose / cease-and-desist / monitor / no-action / settled). Includes one URS domain takedown and one Madrid LATAM multi-country opposition.

Lanham Act §43(a)EUIPOWIPO Madrid
AccessibilityAudit — WCAG 2.2 AA Conformance Audit thumbnail
Utility
Live
2025 · Lead Builder

AccessibilityAudit — WCAG 2.2 AA Conformance Audit

32 findings across 18 page templates. Each mapped to a WCAG 2.2 success criterion (including the 9 new SC introduced Oct 2023: 2.4.11 Focus Not Obscured, 2.5.7 Dragging Movements, 2.5.8 Target Size, 3.2.6 Consistent Help, 3.3.7 Redundant Entry, 3.3.8 Accessible Authentication). Per finding: page, element, contrast preview, suggested code fix. EAA + ADA Title III + Section 508 + EN 301 549 alignment.

WCAG 2.2 AAEN 301 549ADA Title III
APIDocsLinter — OpenAPI 3.1 Lint + Breaking-Change Detector thumbnail
Utility
Live
2025 · Lead Builder

APIDocsLinter — OpenAPI 3.1 Lint + Breaking-Change Detector

22 findings across an OpenAPI 3.1 spec, 9 lint classes (missing operationId, untyped 5xx, undocumented 429, RFC 7807 gap, breaking parameter rename, deprecated-no-sunset, response schema drift, semver mismatch, PII in query, unsafe-eval). Maps Spectral-style severity to SemVer impact (MAJOR / MINOR / PATCH).

OpenAPI 3.1RFC 7807SemVer 2.0.0
CarbonLedger — Scope 1+2+3 Emissions Ledger thumbnail
Utility
Live
2025 · Lead Builder

CarbonLedger — Scope 1+2+3 Emissions Ledger

20 emission sources spanning Scope 1 (gas + fleet + refrigerant leakage), Scope 2 (location-based AND market-based per dual-reporting rule), Scope 3 (purchased goods, business travel, employee commute, use-of-sold-products at 280 tCO₂e, financed-emissions). Per-source: GHG-Protocol-aligned methodology, FY24 actuals vs FY22 baseline, SBTi 1.5°C-aligned 2030 target.

GHG ProtocolSBTi 1.5°CCSRD ESRS E1
WaitlistEthics — A/B Test Ethics + Consent Review thumbnail
Utility
Live
2025 · Lead Builder

WaitlistEthics — A/B Test Ethics + Consent Review

20 experiments scored against Belmont Principles (respect / beneficence / justice) + IRB-lite checklist + GDPR Art 6(1)(f) balancing test. Surfaces 4 blocked/killed experiments (Cambridge Analytica-style emotion contagion, income-inferred pricing, unauthorized $1 charge, pre-checked EU consent), 5 in-review (AI urgency, mood-targeted upsell, GeoIP price discrimination, click-to-cancel dark pattern, per-user dynamic LLM pricing).

Belmont ReportGDPR Art 6(1)(f)GDPR Art 22
NPSGovern — Customer-Feedback Governance + PII Redaction thumbnail
Utility
Live
2025 · Lead Builder

NPSGovern — Customer-Feedback Governance + PII Redaction

28 customer responses across NPS, CSAT, exit surveys, in-app comments. PII-scan + redaction (email, phone, SSN, name, address, DOB, account number). Per-response action: share-ok / share-redacted / cannot-share / crisis-escalate. Lawful basis tagged, retention enforced, employee-name vs third-party-name distinction surfaced.

GDPR Art 5(1)(c)GDPR Art 6(1)(f)NIST SP 800-122 PII
ConsentLedger — Append-Only Consent Proof Log thumbnail
Utility
Live
2025 · Lead Builder

ConsentLedger — Append-Only Consent Proof Log

32 hash-chained consent events. Each entry: subject, purpose, prompt version, exact prompt text shown to subject, affirmative-action evidence, timestamp, source IP-truncated to /16, UA, signed envelope with the hash of the previous entry. Tamper-evident — the artifact that defends GDPR Art 7(1) 'the controller shall be able to demonstrate that the data subject has consented'.

GDPR Art 7GDPR Art 4(11)ePrivacy 5(3)
DataMapInventory — Records of Processing Activities (GDPR Art 30) thumbnail
Utility
Live
2025 · Lead Builder

DataMapInventory — Records of Processing Activities (GDPR Art 30)

32 processing activities as a real RoPA. Per activity: purpose, Art 6 lawful basis, categories of data subjects, categories of personal data (Art 9 sensitive flagged), recipients, international transfers, retention period, Art 32 security measures. The canonical artifact every supervisory authority asks for first.

GDPR Art 30GDPR Art 6GDPR Art 9
FreightEthics — UFLPA + Modern Slavery Supply-Chain Register thumbnail
Utility
Live
2025 · Lead Builder

FreightEthics — UFLPA + Modern Slavery Supply-Chain Register

22 supplier sites mapped across 4 tiers (finished good → component → sub-assembly → raw material). UFLPA Xinjiang-traceability, Modern Slavery Act 2015 §54 coverage, EU CSDDD 2024/1760 due-diligence, ILO 8 core-conventions risk. Surfaces 2 XUAR-located polysilicon + transformer suppliers (UFLPA rebuttable presumption applies), 1 DRC cobalt site without OECD Annex II audit.

UFLPA PL 117-78UK MSA 2015 §54EU CSDDD 2024/1760
PromptLeak — Prompt-Injection Catalog (OWASP LLM01) thumbnail
Utility
Live
2025 · Lead Builder

PromptLeak — Prompt-Injection Catalog (OWASP LLM01)

28 prompt-injection payloads across 8 classes: direct (DAN, fiction-framing, authority impersonation), indirect via RAG (poisoned docs, hidden HTML, web-search injection), system-prompt exfiltration, training-data extraction, jailbreaks, encoded payloads, multimodal (image-OCR, audio-injection), tool/agent abuse (SSRF, XPIA). Each payload includes 4-layer mitigations.

OWASP LLM Top-10NIST AI RMFEU AI Act Art 15
WhistleblowerIntake — EU 2019/1937 + SOX §806 Intake Queue thumbnail
Utility
Live
2025 · Lead Builder

WhistleblowerIntake — EU 2019/1937 + SOX §806 Intake Queue

18 active reports across EU Whistleblower Directive 2019/1937, SOX §806, Dodd-Frank §922, German HinSchG, French Sapin II. Per-report: anonymity tier, channel, retaliation-risk score, 7-day acknowledgment clock + 3-month feedback clock (Art 9), workflow stage, assigned investigator. Includes one nested retaliation case and one SEC TCR Dodd-Frank §922 filing.

EU 2019/1937SOX §806Dodd-Frank §922
CSPReporter — Content-Security-Policy Violation Triage thumbnail
Utility
Live
2025 · Lead Builder

CSPReporter — Content-Security-Policy Violation Triage

22 seeded CSP violations across 5 properties. Classifies each by directive (script-src, img-src, connect-src, frame-ancestors, …), risk class (XSS attempt / shadow IT / 3p drift / browser-noise / clickjacking probe / SRI mismatch / unsafe-eval / mixed-content), and recommended action with the actual directive fix.

W3C CSPOWASP Top-10SOC2 CC6.7
TrainingTracker — Security-Awareness Training Compliance thumbnail
Utility
Live
2025 · Lead Builder

TrainingTracker — Security-Awareness Training Compliance

40 employees × 8 training modules (security awareness, phishing simulation, HIPAA, PCI, GDPR, secure coding, AI risk, role-based privilege). Per-employee × per-module completion matrix, annual + 90-day cadences, retake-after-fail tracking. Maps to PCI Req 12.6, HIPAA §164.530(b)(1), SOC2 CC1.4.

PCI-DSS Req 12.6HIPAA §164.530SOC2 CC1.4
CookieConsent — TCF v2.2 + GPP Signal Validator thumbnail
Utility
Live
2025 · Lead Builder

CookieConsent — TCF v2.2 + GPP Signal Validator

12 properties across 4 jurisdictions (EU, US-CA, US-VA, multi-state). Validates IAB TCF v2.2 + GPP MSPS strings, 8 banner checks (reject-all on layer 1, balanced buttons, scroll ≠ consent, cookie-table accuracy, no dark patterns, no non-essential cookies pre-consent). Surfaces the €60M CNIL pattern (reject buried in settings) and the beta domain with NO BANNER firing GA4 + Hotjar.

IAB TCF v2.2IAB GPPePrivacy 2002/58/EC
EgressGate — Third-Party API Egress Allow-List thumbnail
Utility
Live
2025 · Lead Builder

EgressGate — Third-Party API Egress Allow-List

28 outbound destinations from 8 production services. Allow-list state, 7-day traffic baseline, 4-dimension anomaly score (request rate, error rate, response size, geographic dispersion). Surfaces shadow IT (api.anthropic.com from a still-unidentified ECS task), denied destinations (Google Fonts loading visitor IPs), and one bare-IP exfil drill.

SOC2 CC6.6NIST 800-53 SC-7Shadow IT
ScopeCreep — OAuth Scope Audit thumbnail
Utility
Live
2025 · Lead Builder

ScopeCreep — OAuth Scope Audit

32 OAuth grants across 14 SaaS apps. For every grant: scopes granted vs scopes actually used in last 90 days, classification (active / dormant / unused), recommended minimum-grant. Flags the dormant 'admin: *', the 'iam:*' that has never been used, and the former-employee Google Workspace token still alive.

SOC2 CC6.3NIST AC-6Least Privilege
SecretRotation — 64-Secret Rotation Inventory thumbnail
Utility
Live
2025 · Lead Builder

SecretRotation — 64-Secret Rotation Inventory

64 seeded secrets across 12 systems. Rotation cadence vs policy. Last-rotated age, blast-radius, owner, vault. Surfaces the 'orphan token' (no owner, no last-rotated metadata), the deprecated mongo password 880 days stale, the FCM legacy server key still in env vars, and the still-running IAM access key that should have been migrated to OIDC.

PCI-DSS 8.3.9NIST SP 800-57SOC2 CC6.1