Demo Scan Report
mainThe acme-corp/payments-service repository presents a mixed compliance posture across ISO 27001:2022 and SOC 2 Type II frameworks. While the codebase demonstrates some security awareness — including the presence of a Dockerfile and dependency management files — several significant gaps exist that prevent full compliance certification. Critical deficiencies were identified in secrets management, where database credentials and payment API keys appear to be hardcoded in source files. The absence of a formal SECURITY.md policy, lack of structured logging for security events, and missing branch protection enforcement are the most pressing concerns requiring immediate remediation. The SOC 2 assessment reveals particular weaknesses in the CC6 (Logical Access) and CC7 (System Operations) criteria, with insufficient controls around authentication, session management, and audit logging. ISO 27001 gaps are concentrated in Annex A controls related to cryptography (A.8.24), secure development (A.8.25), and information security incident management (A.5.26). Prioritizing the critical and high findings will significantly improve compliance posture and reduce organisational risk.
package.json
docker-compose.yml
.github/workflows/commitlint.yml
.github/workflows/compliance-scan.yml
.env.example
SECURITY.md
sst.config.ts