Skip to main content

Compliance

Regulatory compliance frameworks and data protection

12
Standards
13
Best Practices
5
FAQs

Standards

PCI-DSS 4.0

The Payment Card Industry Data Security Standard (PCI DSS) is crucial for teams planning software migrations that involve payment processing. Compliance ensures the protection of sensitive cardholder data, mitigates risks of data breaches, and fosters customer trust. By following outlined requirements and best practices, organizations can securely transition their systems while maintaining compliance.

by PCI Security Standards Council

pci-dss-4-0

HIPAA Security Rule

The HHS standard is essential for ensuring compliance during software migrations involving health-related data. By adhering to these regulations, teams can protect sensitive information, avoid legal complications, and maintain stakeholder trust, all while facilitating effective data transfer between systems.

by U.S. Department of Health and Human Services

hipaa-security-rule

GDPR (EU 2016/679)

Adhering to established standards during software migrations is crucial for ensuring data security, integrity, and stakeholder trust. This guide provides practical insights on compliance requirements, implementation strategies, and tools to help teams navigate the complexities of migration projects with confidence.

by European Union

gdpr-eu-2016-679

UK GDPR 2021

Adhering to compliance standards during software migrations is crucial for protecting sensitive data, maintaining stakeholder confidence, and ensuring seamless transitions. This guide outlines the key requirements, practical steps for adherence, and tools to help teams navigate compliance challenges effectively.

by European Union

uk-gdpr-2021

CCPA (AB 375)

Understanding compliance standards is essential for successful software migrations. By adhering to legal and regulatory requirements, teams can protect sensitive data, uphold privacy rights, and ensure operational continuity. This guide outlines key requirements, practical strategies, and tools to help organizations navigate compliance challenges during their migration processes.

by State of California

ccpa

FedRAMP Moderate Rev 5

Understanding and adhering to GSA standards is crucial for successful migration projects, ensuring compliance, security, and interoperability. By following structured guidelines and leveraging the right tools, organizations can navigate the complexities of migration while minimizing risks and enhancing efficiency.

by U.S. General Services Administration

fedramp-moderate

ISO/IEC 29134:2017 (PIA)

Adhering to ISO/IEC standards during software migrations is critical for ensuring quality, minimizing risks, and gaining stakeholder trust. By following established requirements and utilizing appropriate tools and processes, teams can navigate common challenges and execute successful migrations that align with international best practices.

by ISO/IEC Joint Technical Committee

iso-29134-2017

ISO/IEC 38505-1:2017 (Data Governance)

Adhering to ISO/IEC standards is essential for effective migration projects, ensuring quality, security, and efficiency. By following structured compliance measures and leveraging the right tools, teams can mitigate risks, enhance trust, and streamline their migration processes.

by ISO/IEC Joint Technical Committee

iso-38505-1-2017

ISO/IEC 27001:2022

Information security management systems (ISMS) requirements. The anchor certification for enterprise information security.

by ISO/IEC

iso-iec-27001-2022

ISO/IEC 27002:2022

Information security controls — the implementation guidance companion to ISO/IEC 27001 Annex A.

by ISO/IEC

iso-iec-27002-2022

AICPA SOC 2 (Trust Services Criteria 2017, rev. 2022)

Trust Services Criteria (security, availability, processing integrity, confidentiality, privacy) underpinning SOC 2 Type I/II attestations.

by AICPA

aicpa-soc-2-tsc

PCI-DSS 4.0.1

Security requirements for every organisation that stores, processes, or transmits cardholder data. 4.0.1 is a limited revision of 4.0 that corrects and clarifies its text; the future-dated 4.0 requirements became mandatory on 31 March 2025.

by PCI Security Standards Council

pci-dss-4-0-1

Best Practices

ISO/IEC 27001:2022 Annex A Controls

Industry baseline for information-security policies and management controls.

by ISO/IEC JTC 1/SC 27

EU AI Act (Political Agreement)

First comprehensive regulatory framework for trustworthy AI in the European Union.

by European Parliament & Council

Privacy by Design 7 Principles

Framework embedding privacy into systems engineering from the outset.

by International Assembly for Privacy Commissioners

NIST Cybersecurity Framework 2.0

A voluntary framework of cybersecurity outcomes organized into six functions, govern, identify, protect, detect, respond, and recover, for managing organizational cyber risk.

by National Institute of Standards and Technology

NIST SP 800-53 Security and Privacy Controls

A comprehensive catalog of security and privacy controls for information systems, organized into control families with baselines for different risk levels.

by National Institute of Standards and Technology

CIS Critical Security Controls v8

A prioritized set of 18 safeguards and implementation groups that defend against the most common cyber attacks, mapped to other major frameworks.

by Center for Internet Security

Data Governance Framework

A structured set of roles, policies, and processes that make an organization accountable for the quality, security, and proper use of its data assets.

by DAMA International

ISO/IEC 42001 AI Management System

ISO/IEC 42001 is the first international standard for an Artificial Intelligence Management System, giving organizations a certifiable framework to govern AI responsibly.

by ISO/IEC

WCAG 2.2 Accessibility Compliance

The W3C Web Content Accessibility Guidelines 2.2 define testable success criteria across four principles so web content is perceivable, operable, understandable, and robust.

by World Wide Web Consortium (W3C)

Test Data Management

Practices for provisioning realistic, isolated, and compliant test data so tests are reliable, repeatable, and free of production data exposure.

by Thoughtworks

SOC 2 Compliance

SOC 2 is an AICPA auditing framework that assesses how a service organization protects customer data against five Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy.

by American Institute of Certified Public Accountants (AICPA)

PCI DSS Compliance

PCI DSS is the global security standard for organizations that handle payment card data, defining requirements to protect cardholder data across networks, systems, and processes.

by PCI Security Standards Council

GDPR Compliance Engineering

GDPR compliance engineering turns the EU General Data Protection Regulation's legal principles into concrete technical controls: lawful processing, data minimization, consent, and data-subject rights.

by European Union

Checklists

Data Governance Review Checklist

A review checklist for assessing data ownership, quality, lineage, access control, and policy compliance across data assets.

PII and Data Classification Audit Checklist

An audit checklist for discovering, classifying, and protecting personally identifiable information across systems and data stores.

SOC 2 & ISO 27001 Evidence Readiness Checklist

Prepare the controls and evidence needed for a SOC 2 or ISO 27001 audit across access, change management, and monitoring.

FAQs

What is SOC 2 compliance?

SOC 2 is an audit framework from the AICPA that evaluates how a service organization manages customer data against five Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy. A Type I report assesses controls at a single point in time, while a Type II report tests that those controls operated effectively over a period, usually 3 to 12 months. SOC 2 reports are commonly requested by enterprise customers as evidence that a SaaS vendor handles data responsibly.

What is GDPR in a nutshell?

The General Data Protection Regulation (GDPR) is an EU law that governs how organizations collect, process, and store the personal data of people in the EU and EEA, regardless of where the organization is based. It grants individuals rights such as access, correction, deletion ("right to be forgotten"), and portability, and requires a lawful basis for processing, data-protection-by-design, and breach notification within 72 hours. Non-compliance can incur fines of up to 20 million euros or 4% of global annual revenue, whichever is higher.

What is PII (personally identifiable information)?

PII is any data that can identify a specific individual, either on its own or when combined with other information. Direct identifiers include name, email, government ID, and biometric data, while indirect identifiers like IP address, device ID, or location can identify someone in combination. Handling PII triggers obligations under regulations such as GDPR and CCPA, so it should be minimized, encrypted, access-controlled, and retained only as long as necessary.

What is HIPAA compliance?

HIPAA (the Health Insurance Portability and Accountability Act) is a US law that sets standards for protecting sensitive patient health information, known as protected health information (PHI). Its Security Rule requires administrative, physical, and technical safeguards such as access controls, encryption, and audit logging, while the Privacy Rule governs how PHI may be used and disclosed. Software vendors that handle PHI on behalf of healthcare organizations are typically considered business associates and must sign a Business Associate Agreement (BAA).

What is ISO 27001?

ISO/IEC 27001 is an international standard that specifies the requirements for an information security management system (ISMS), a risk-based framework of policies, processes, and controls for protecting information assets. Organizations identify risks, select and implement controls (guided by the Annex A control set), and can pursue independent certification by an accredited auditor. Unlike SOC 2, which produces an audit report, ISO 27001 results in a formal certificate that is recognized globally, especially outside the US.

Vibgrate CLI

See a real scan run

A replay of the actual CLI running against our test repositories — live progress, real findings, a genuine DriftScore. Nothing executes in your browser.

Replay
demo@vibgrate — bash
npx @vibgrate/cli scan
 
╭──────────────────────────────────────────╮
Vibgrate Drift Report
╰──────────────────────────────────────────╯
 
── node-turborepo (node) .
Runtime: >=18.0.0 (6 majors behind)
Frameworks:
Turbo: 1.13.4 → 2.10.8 (1 behind)
TypeScript: 5.9.3 → 7.0.2 (2 behind)
Dependencies:
1 current 1 1-behind 3 2+ behind 1 unknown
 
── @repo/admin (node) apps/admin
Frameworks:
TanStack Query: 5.101.4 → 5.101.4 (current)
React: 18.3.1 → 19.2.8 (1 behind)
React DOM: 18.3.1 → 19.2.8 (1 behind)
TypeScript: 5.9.3 → 7.0.2 (2 behind)
Vite: 5.4.21 → 8.2.1 (3 behind)
Dependencies:
3 current 9 1-behind 3 2+ behind 4 unknown
 
── @repo/api (node) apps/api
Frameworks:
Express: 4.22.2 → 5.2.1 (1 behind)
TypeScript: 5.9.3 → 7.0.2 (2 behind)
Vitest: 1.6.1 → 4.1.10 (3 behind)
Dependencies:
7 current 5 1-behind 3 2+ behind 4 unknown
 
── @repo/web (node) apps/web
Frameworks:
Next.js: 14.2.35 → 16.3.0 (2 behind)
React: 18.3.1 → 19.2.8 (1 behind)
React DOM: 18.3.1 → 19.2.8 (1 behind)
TypeScript: 5.9.3 → 7.0.2 (2 behind)
Dependencies:
2 current 6 1-behind 3 2+ behind 5 unknown
 
── @repo/config (node) packages/config
Frameworks:
TypeScript: 5.9.3 → 7.0.2 (2 behind)
Dependencies:
2 current 2 1-behind 5 2+ behind 0 unknown
 
── @repo/database (node) packages/database
Frameworks:
Prisma: 5.22.0 → 7.9.1 (2 behind)
TypeScript: 5.9.3 → 7.0.2 (2 behind)
Dependencies:
1 current 0 1-behind 3 2+ behind 1 unknown
 
── @repo/types (node) packages/types
Frameworks:
TypeScript: 5.9.3 → 7.0.2 (2 behind)
Dependencies:
0 current 0 1-behind 1 2+ behind 1 unknown
 
── @repo/ui (node) packages/ui
Frameworks:
React: 18.3.1 → 19.2.8 (1 behind)
TypeScript: 5.9.3 → 7.0.2 (2 behind)
React: 18.3.1 → 19.2.8 (1 behind)
Dependencies:
1 current 4 1-behind 1 2+ behind 1 unknown
 
── @repo/utils (node) packages/utils
Frameworks:
TypeScript: 5.9.3 → 7.0.2 (2 behind)
Vitest: 1.6.1 → 4.1.10 (3 behind)
Dependencies:
0 current 1 1-behind 2 2+ behind 1 unknown
 
Tech Stack
Frontend: React, React DOM
Meta-frameworks: Next.js
Bundlers: tsx, Turbo, Vite
CSS / UI: Autoprefixer, PostCSS, Tailwind CSS
Backend: Express
ORM / Database: Prisma, Prisma Client
Testing: Vitest
Lint & Format: ESLint, ESLint Prettier, ESLint React, Prettier, typescript-eslint
 
Services & Integrations
Auth: JWT 9.0.3
Databases: Prisma 5.22.0
 
TypeScript
v5.3.3 · strict ✔ · MIXED · target: ES2022
 
Build & Deploy
Package Managers: pnpm
Monorepo: npm-workspaces, pnpm-workspaces, turbo
 
Product Purpose Signals
Frameworks: react, nextjs
Evidence: 177
Top Signals:
- [heading] Dashboard (apps/admin/src/pages/Dashboard.tsx)
- [title] Revenue Overview (apps/admin/src/pages/Dashboard.tsx)
- [copy] workspace:* (packages/ui/package.json)
- [copy] ./dist (packages/ui/tsconfig.json)
- [copy] ./src/index.ts (packages/ui/package.json)
- [copy] @repo/config/tsconfig-base.json (packages/ui/tsconfig.json)
- [copy] @repo/ui (packages/ui/package.json)
- [copy] #3b82f6 (apps/admin/src/pages/Dashboard.tsx)
Unknowns:
- No pricing or billing evidence found.
- No integrations/connectors evidence found.
- No route structure evidence found.
 
Security Posture
Lockfile ✖ · .env ✔ · node_modules ✔
 
Platform
Native modules: turbo
 
Code Quality
Files: 36 · Functions: 183 · Avg complexity: 2.62 · Avg length: 21.13 lines
Max nesting: 2 · Circular deps: 0 · Dead code: 0%
God files: apps/admin/src/pages/Products (448 lines)
 
Database Schema
postgresql · 8 models · 1 enum
Models: Address, CartItem, Category, Order, OrderItem (+3 more)
 
Findings (16 errors, 11 warnings)
Node.js runtime ">=18.0.0" reached end-of-life on 2025-04-30 (latest: 24.0.0).
vibgrate/runtime-eol in .
TypeScript is 2 major versions behind (current: 5.9.3, latest: 7.0.2).
vibgrate/framework-major-lag in .
60% of dependencies are 2+ major versions behind in node-turborepo.
vibgrate/dependency-rot in .
@types/node is 6 major versions behind (spec: ^20.11.0, latest: 26.1.2).
vibgrate/dependency-major-lag in .
TypeScript is 2 major versions behind (current: 5.9.3, latest: 7.0.2).
vibgrate/framework-major-lag in apps/admin
Vite is 3 major versions behind (current: 5.4.21, latest: 8.2.1).
vibgrate/framework-major-lag in apps/admin
vite is 3 major versions behind (spec: ^5.0.12, latest: 8.2.1).
vibgrate/dependency-major-lag in apps/admin
TypeScript is 2 major versions behind (current: 5.9.3, latest: 7.0.2).
vibgrate/framework-major-lag in apps/api
Vitest is 3 major versions behind (current: 1.6.1, latest: 4.1.10).
vibgrate/framework-major-lag in apps/api
@types/node is 6 major versions behind (spec: ^20.11.0, latest: 26.1.2).
vibgrate/dependency-major-lag in apps/api
vitest is 3 major versions behind (spec: ^1.2.1, latest: 4.1.10).
vibgrate/dependency-major-lag in apps/api
Next.js is 2 major versions behind (current: 14.2.35, latest: 16.3.0).
vibgrate/framework-major-lag in apps/web
TypeScript is 2 major versions behind (current: 5.9.3, latest: 7.0.2).
vibgrate/framework-major-lag in apps/web
@types/node is 6 major versions behind (spec: ^20.11.0, latest: 26.1.2).
vibgrate/dependency-major-lag in apps/web
TypeScript is 2 major versions behind (current: 5.9.3, latest: 7.0.2).
vibgrate/framework-major-lag in packages/config
56% of dependencies are 2+ major versions behind in @repo/config.
vibgrate/dependency-rot in packages/config
eslint-plugin-react-hooks is 3 major versions behind (spec: ^4.6.0, latest: 7.1.1).
vibgrate/dependency-major-lag in packages/config
Prisma is 2 major versions behind (current: 5.22.0, latest: 7.9.1).
vibgrate/framework-major-lag in packages/database
TypeScript is 2 major versions behind (current: 5.9.3, latest: 7.0.2).
vibgrate/framework-major-lag in packages/database
75% of dependencies are 2+ major versions behind in @repo/database.
vibgrate/dependency-rot in packages/database
TypeScript is 2 major versions behind (current: 5.9.3, latest: 7.0.2).
vibgrate/framework-major-lag in packages/types
100% of dependencies are 2+ major versions behind in @repo/types.
vibgrate/dependency-rot in packages/types
TypeScript is 2 major versions behind (current: 5.9.3, latest: 7.0.2).
vibgrate/framework-major-lag in packages/ui
TypeScript is 2 major versions behind (current: 5.9.3, latest: 7.0.2).
vibgrate/framework-major-lag in packages/utils
Vitest is 3 major versions behind (current: 1.6.1, latest: 4.1.10).
vibgrate/framework-major-lag in packages/utils
67% of dependencies are 2+ major versions behind in @repo/utils.
vibgrate/dependency-rot in packages/utils
vitest is 3 major versions behind (spec: ^1.2.1, latest: 4.1.10).
vibgrate/dependency-major-lag in packages/utils
 
╭──────────────────────────────────────────╮
Top Priority Actions
╰──────────────────────────────────────────╯
 
1. Upgrade EOL runtime in node-turborepo
End-of-life runtimes no longer receive security patches and block ecosystem upgrades.
./.
>=18.0.0 → 24.0.0 (6 majors behind)
Impact: −10 drift points (runtime & EOL)
 
2. Fix security posture: no lockfile found
Without a lockfile, installs are non-deterministic. Run the install command to generate one and commit it.
./
Missing: package-lock.json, pnpm-lock.yaml, or yarn.lock
 
3. Upgrade Vite 5.4.21 → 8.2.1 in @repo/admin (+2 more)
3 major versions behind. Major framework drift increases breaking change risk and blocks access to security fixes and performance improvements.
./apps/admin
Vite: 5.4.21 → 8.2.1 (3 majors behind)
./apps/api
Vitest: 1.6.1 → 4.1.10 (3 majors behind)
./packages/utils
Vitest: 1.6.1 → 4.1.10 (3 majors behind)
Impact: −5–15 drift points
 
4. Reduce dependency rot in @repo/types (100% severely outdated)
1 of 1 dependencies are 2+ majors behind. Run `npm outdated` and prioritise packages with known CVEs or breaking API changes.
./packages/types
typescript: 5.9.3 → 7.0.2 (2 majors behind)
Impact: −5–10 drift points
 
5. Reduce dependency rot in @repo/database (75% severely outdated)
3 of 4 dependencies are 2+ majors behind. Run `npm outdated` and prioritise packages with known CVEs or breaking API changes.
./packages/database
@prisma/client: 5.22.0 → 7.9.1 (2 majors behind)
prisma: 5.22.0 → 7.9.1 (2 majors behind)
typescript: 5.9.3 → 7.0.2 (2 majors behind)
Impact: −5–10 drift points
 
╭──────────────────────────────────────────╮
Architecture Layers
╰──────────────────────────────────────────╯
 
Archetype: monorepo (80% confidence)
Files classified: 29 (6 unclassified)
 
presentation 9 files drift ████████████████████ 100 risk high
routing 4 files drift ████████████████████ 100 risk high
middleware 2 files drift ███████▍░░░░░░░░░░░░ 37 risk moderate
domain 4 files drift ████████████████████ 100 risk high
data-access 2 files drift ████████████████████ 100 risk high
infrastructure 0 files drift ░░░░░░░░░░░░░░░░░░░░ 0 risk none
config 3 files drift ░░░░░░░░░░░░░░░░░░░░ 0 risk none
shared 5 files drift ████████████████████ 100 risk high
testing 0 files drift ████████████████████ 100 risk high
 
╭──────────────────────────────────────────╮
DriftScore Summary
╰──────────────────────────────────────────╯
 
DriftScore: 66/100
Risk Level: HIGH
Projects: 9
Classified: 8 nano · 1 micro · 0 small · 0 standard
Billable: 0.42 · 9 detected → 0.42 billable projects (micro-project pricing)
0.1 micro · 0.32 nano
These fractions add up across repositories, then round down to whole billable projects.
 
Score Breakdown
Runtime: ████████████████████ 100
Frameworks: █████████▏░░░░░░░░░░ 46
Dependencies: ██████░░░░░░░░░░░░░░ 30
EOL Risk: ████████████████████ 100
 
Scanned at 2026-08-07T06:14:10.284Z · 25.2s · 286 files scanned · 56 workspace files · 27 dirs
Press Run to start.