A Security & Compliance Verification Agent that treats system specifications, checklists, configuration information, documents, source code, and scanner results as evidence materials, and conducts scope organization, risk candidate identification, improvement proposals, and audit reporting all within a single workspace.
Evidence-first Approach
- Each risk candidate is inseparable from the target checklist item and its supporting evidence
- Items without evidence are marked as "Unconfirmed," and conclusions are not automatically supplemented on the safe side
- Detection rules, evidence content, and reasons for missing information are explicitly stated
8-Stage Workflow
- Scope Organization (target, purpose, environment, data classification)
- Checklist Item Generation (maximum 12 items)
- Evidence Verification (detection using fixed rules)
- Explicit Identification of Missing Information (Missing Evidence)
- Risk Candidate Organization (High / Medium / Low / Needs Review)
- Generation of Follow-up Questions
- Improvement Proposal Draft (improvement direction, verification procedures, implementation candidates)
- Audit Report Output
9 Verification Domains
Authentication, Authorization, Secret Management, Logging, Encryption, Backup, Data Retention, Privacy, Dependency Management
Human-in-the-Loop
- Final judgment is made by humans only
- Each risk candidate is handled with its basis, reviewer, and comments recorded
- Supports re-evaluation (Re-check) with additional evidence
Security Measures
- Candidates such as API keys, tokens, and secret keys are masked upon input
- Input materials are treated as untrustworthy audit targets
- Prompt injection countermeasures are implemented
- Development teams that want to conduct security reviews systematically
- Organizations that want to make compliance verification evidence traceable
- Audit personnel who want to make uncertainty and unconfirmed items explicit
This demo is intended to support verification work and does not guarantee compliance with laws/standards or the safety of the target system. External LLMs are disabled and it operates as rule-based processing.
Reactions & commentsFeedback
Share your thoughts, bug reports, or suggestions directly with the developer
Log in to share your feedback
Log in to leave feedback