-
released this
2026-09-01 12:12:07 +00:00 | 1 commits to main since this releaseContainer delivery. Pre-built OCI image tarball inside
cyber-suite-single-tenant.zip—docker loadand run. Static linux/amd64 binary + Dockerfile also inside.Built from main
a6c82d4d(go1.25, CGO_ENABLED=0, static, linux/amd64).Notable since v2.6.39:
- Regulatory applicability on Vendor Control Mapping: a Required for column across ten regimes — Responsible AI, EU AI Act, SOx, GDPR, NIS2, DORA, Saudi PDPL, ISO 27001, SOC 2, NCA ECC
- Why now carries a Regulatory relevance block: one sentence per regime, including the negatives — "why is this control not in scope for SOx" is what an auditor asks and normally what nobody has written down
- The Microsoft agentic-AI reference set ships 780 assessments (78 controls × 10 regimes)
- Broad baselines de-emphasised: ISO 27001 matches all 78 controls here and SOC 2 all but four, so at equal weight they drown the six regimes that actually differ
- Sets seeded before this data existed are backfilled on next render
- Tabbed vendor detail page; mapping table read-only with the rationale inline and SCF anchors linking into Cyber Policy
- CSP nonce so inline scripts execute (they were silently blocked browser-side); HTML-injection fix for pages containing non-ASCII text; Temporal namespace configurable
The Dockerfile now parameterises
BASE_IMAGE, so you can wrap the same binary in your own hardened base and co-sign it — seeLOAD-AND-RUN.md.
⚠️ Read before showing the regime data to a customer. The seeded regime determinations were derived from control text and domain, not the regulation text. They are a first pass, known to be imperfect, and on screen they look authoritative. Every entry is marked
source=seed, and_meta.regimeMethodologyin the seed records the provenance. Have someone who knows the regulations review them before they inform a client decision. UNASSESSED renders distinctly from NOT-REQUIRED — the product never claims a judgement nobody made.Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
0 downloads