Back to Home

Demo Scan Report

acme-corp/payments-serviceMar 26, 2026main
Compliance Gaps Found
Executive Summary

The acme-corp/payments-service repository presents a mixed compliance posture across ISO 27001:2022 and SOC 2 Type II frameworks. While the codebase demonstrates some security awareness — including the presence of a Dockerfile and dependency management files — several significant gaps exist that prevent full compliance certification. Critical deficiencies were identified in secrets management, where database credentials and payment API keys appear to be hardcoded in source files. The absence of a formal SECURITY.md policy, lack of structured logging for security events, and missing branch protection enforcement are the most pressing concerns requiring immediate remediation. The SOC 2 assessment reveals particular weaknesses in the CC6 (Logical Access) and CC7 (System Operations) criteria, with insufficient controls around authentication, session management, and audit logging. ISO 27001 gaps are concentrated in Annex A controls related to cryptography (A.8.24), secure development (A.8.25), and information security incident management (A.5.26). Prioritizing the critical and high findings will significantly improve compliance posture and reduce organisational risk.

ISO 27001:2022
Annex A Controls Assessment
FAIL
62/100
4/14 controls passed·2 critical4 high5 medium3 low
SOC 2 Type II
Trust Service Criteria Assessment
FAIL
54/100
6/13 controls passed·2 critical3 high4 medium2 low
Dependency Vulnerabilities
NPM advisory database · 312 packages · pnpm
FAIL
52/100
1 critical2 high2 moderate1 low
Dependency Health Audit
npm registry version lag · 312 packages · 28 production
PASS
89/100
2 minor1 patch· 3 outdated of 28 production packages
Files Scanned
Key files whose content was sent to the AI for this scan.
  • package.json

  • docker-compose.yml

  • .github/workflows/commitlint.yml

  • .github/workflows/compliance-scan.yml

  • .env.example

  • SECURITY.md

  • sst.config.ts

Report ID: scan_demo_acme-payments_seedBranch: main · Commit: a3f8c12
We use cookies
We use essential cookies to remember your preferences (theme, colour scheme, sidebar state) and analytics cookies via PostHog to understand how you use the product and diagnose errors. Clerk, our authentication provider, sets session cookies required to keep you signed in.

By clicking "Accept", you agree to our use of cookies.

Learn more