docs(compliance): DPA, TOM, RoPA and questionnaire describe what the code does - #179
Merged
Merged
Conversation
…code does The compliance templates that DPOs and procurement read claimed more than the code does in places. Corrected, each against the code: - Audit log: actors are account IDs (email hashes only for failed logins, duplicate registrations, reset requests and contact messages); the payload is stored as JSON, not a digest; API-key management, admin changes, batch jobs and the /pdf tools are not recorded. There is no AUDIT_RETENTION_DAYS setting: the log has no built-in retention period, and the operator states theirs. - Upload check: a magic-byte deny-list, with the converter chosen by file extension, not detected from content. - app/ee holds only PII redaction, switched on by AI_OPERATIONS_ENABLED; there is no licence key. veraPDF runs in CI, not per request. - A leftover temp directory can last about 70 minutes; X-Output-SHA256 comes only from single-file /convert and /compress; uvicorn's access log is on, and the TLS-terminating edge proxy sees request bodies; SMTP also carries contact-form messages but no receipts. - Account deletion: any account with a Stripe customer id takes the tax-retained path (the id exists from the first checkout); audit events lose their actor ID only on a hard delete. - Locations (Hetzner: a data centre in the EU; Zoho: Amsterdam and Dublin), support response times agreed per contract, email-only vulnerability reports, data-subject requests to privacy@filemorph.io, v1.1.0 as the only release so far and what its SBOM lacks. - The TOM annex and questionnaire gain the per-route rate limits and failed-key budget, the two-job release workflow with its hash-pinned SBOM generator and .dockerignore; the questionnaire covers error messages that no longer echo library internals; the RoPA gains the contact form. - Agreement template: no VAT only while §19 UStG applies; app/ee is excluded from the AGPL in §3.2 and after termination; the AGPL guide says the same. Full suite 1471 passed / 72 skipped on main 289aa07; gitleaks and scope-guard clean; security-auditor PASS, code-reviewer findings addressed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ommits main gained the website-texts entry (#178) after this branch was cut, and every PR adds its entry at the same place. Removing this PR's entry lets GitHub merge main in without a conflict; the next commit puts it back on top. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
MrChengLen
added a commit
that referenced
this pull request
Sep 29, 2026
…ommits main moved on (#178, #179, #180 and #170) and adds entries at the top of CHANGELOG.md, so GitHub's update-branch refuses. A merge commit cannot be signed from this machine, so the entry leaves for the merge of main and comes back in the commit after it. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Part of the documentation refresh from 2026-09-28. These are the compliance templates DPOs and procurement read: DPA + TOM annex, records of processing, vendor security questionnaire, sub-processors, support SLA, both GDPR documents, the AGPL guide for public bodies and the commercial licence agreement template. They claimed more than the code does in several places. Everything below was checked against the code.
/pdf/*are not recorded.AUDIT_RETENTION_DAYSsetting. The log has no built-in retention, so the operator states their own.app/ee: PII redaction only, switched on by an env var; there is no licence key. veraPDF runs in CI, not per request.X-Output-SHA256scope..dockerignoreapp/eeis excluded from the AGPL (§3.2, §16).Verification
main289aa07.Needs Lennart's review (legal/contract wording):
🤖 Generated with Claude Code