Skip to content

docs(compliance): DPA, TOM, RoPA and questionnaire describe what the code does - #179

Merged
MrChengLen merged 4 commits into
mainfrom
pr-compliance-docs-truth
Sep 29, 2026
Merged

MrChengLen merged 4 commits into
mainfrom
pr-compliance-docs-truth

Conversation

@MrChengLen

Copy link
Copy Markdown
Owner

What

Part of the documentation refresh from 2026-09-28. These are the compliance templates DPOs and procurement read: DPA + TOM annex, records of processing, vendor security questionnaire, sub-processors, support SLA, both GDPR documents, the AGPL guide for public bodies and the commercial licence agreement template. They claimed more than the code does in several places. Everything below was checked against the code.

  • Audit log:
    • Actors are account IDs. The payload is JSON, not a digest.
    • API-key management, admin changes, batch jobs and /pdf/* are not recorded.
    • There is no AUDIT_RETENTION_DAYS setting. The log has no built-in retention, so the operator states their own.
  • Upload check: a magic-byte deny-list, not an allow-list. The converter is chosen by file extension.
  • app/ee: PII redaction only, switched on by an env var; there is no licence key. veraPDF runs in CI, not per request.
  • Other facts corrected:
    • Temp-file worst case is about 70 min.
    • X-Output-SHA256 scope.
    • uvicorn's access log is on.
    • The edge proxy sees request bodies.
    • SMTP also carries the contact form.
  • Account deletion: any account with a Stripe customer id takes the tax-retained path.
  • Locations and contacts:
    • Hosting: Hetzner "data centre in the EU", Zoho Amsterdam/Dublin.
    • SLA response times are agreed per contract.
    • Vulnerability reports go by email only.
    • Data-subject requests go to privacy@.
  • Added:
    • the rate limits and failed-key budget
    • the release/SBOM hardening
    • .dockerignore
    • error disclosure (CWE-209)
    • a RoPA activity for the contact form
  • Agreement template: no VAT charged only while §19 UStG applies. app/ee is excluded from the AGPL (§3.2, §16).

Verification

  • Full suite: 1471 passed / 72 skipped on main 289aa07.
  • gitleaks and scope-guard are clean.
  • security-auditor: PASS. code-reviewer: all findings fixed.

Needs Lennart's review (legal/contract wording):

  • agreement §3.2, §6.2 (reverse charge while §19 UStG applies; worth a tax-adviser check), §15.3, §16.1–16.2 and Schedules A/B
  • the Cloudflare US transfer in VSQ §2.3
  • the backup/restore claims in VSQ §4.2/§10, which can't be verified from the repo
  • "PGP key on request"

🤖 Generated with Claude Code

MrChengLen and others added 4 commits September 29, 2026 09:13
…code does

The compliance templates that DPOs and procurement read claimed more than
the code does in places. Corrected, each against the code:

- Audit log: actors are account IDs (email hashes only for failed logins,
  duplicate registrations, reset requests and contact messages); the payload
  is stored as JSON, not a digest; API-key management, admin changes, batch
  jobs and the /pdf tools are not recorded. There is no AUDIT_RETENTION_DAYS
  setting: the log has no built-in retention period, and the operator states
  theirs.
- Upload check: a magic-byte deny-list, with the converter chosen by file
  extension, not detected from content.
- app/ee holds only PII redaction, switched on by AI_OPERATIONS_ENABLED;
  there is no licence key. veraPDF runs in CI, not per request.
- A leftover temp directory can last about 70 minutes; X-Output-SHA256 comes
  only from single-file /convert and /compress; uvicorn's access log is on,
  and the TLS-terminating edge proxy sees request bodies; SMTP also carries
  contact-form messages but no receipts.
- Account deletion: any account with a Stripe customer id takes the
  tax-retained path (the id exists from the first checkout); audit events
  lose their actor ID only on a hard delete.
- Locations (Hetzner: a data centre in the EU; Zoho: Amsterdam and Dublin),
  support response times agreed per contract, email-only vulnerability
  reports, data-subject requests to privacy@filemorph.io, v1.1.0 as the only
  release so far and what its SBOM lacks.
- The TOM annex and questionnaire gain the per-route rate limits and
  failed-key budget, the two-job release workflow with its hash-pinned SBOM
  generator and .dockerignore; the questionnaire covers error messages that
  no longer echo library internals; the RoPA gains the contact form.
- Agreement template: no VAT only while §19 UStG applies; app/ee is excluded
  from the AGPL in §3.2 and after termination; the AGPL guide says the same.

Full suite 1471 passed / 72 skipped on main 289aa07; gitleaks and
scope-guard clean; security-auditor PASS, code-reviewer findings addressed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ommits

main gained the website-texts entry (#178) after this branch was cut, and
every PR adds its entry at the same place. Removing this PR's entry lets
GitHub merge main in without a conflict; the next commit puts it back on top.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@MrChengLen
MrChengLen merged commit 1c15233 into main Sep 29, 2026
7 checks passed
@MrChengLen
MrChengLen deleted the pr-compliance-docs-truth branch September 29, 2026 07:51
MrChengLen added a commit that referenced this pull request Sep 29, 2026
…ommits

main moved on (#178, #179, #180 and #170) and adds entries at the top of
CHANGELOG.md, so GitHub's update-branch refuses. A merge commit cannot be
signed from this machine, so the entry leaves for the merge of main and comes
back in the commit after it.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant