Compliance & Security¶
This section maps regulatory requirements to NornicDB controls and procedures.
Start Here¶
- GDPR requirements and workflows: gdpr-compliance.md
- HIPAA controls and operational mapping: hipaa-compliance.md
- SOC2 control coverage: soc2-compliance.md
- Encryption controls: encryption.md
- Audit evidence and logging posture: audit-logging.md
- Background workers and MVCC for auditors: background-workers-mvcc-audit-guide.md
- RBAC/compliance access model: rbac.md
Control Domains¶
- Data protection and crypto: encryption.md
- Access control: rbac.md
- Auditability and retention: audit-logging.md
- Background processing and version history: background-workers-mvcc-audit-guide.md
Standards Mapping¶
- GDPR: gdpr-compliance.md
- HIPAA: hipaa-compliance.md
- SOC2: soc2-compliance.md
Related Security/Operations Docs¶
- Runtime security controls: ../security/README.md
- Production operations and runbooks: ../operations/README.md
- Symptom-based routing: ../ISSUES-INDEX.md