▸case-01 We are preparing our healthcare analytics web app for HIPAA and SOC 2 audits before our public launch next month. Could you perform a comprehensive regulatory readiness check on our data handling processes? Please structure your response to cover our current readiness status, identified control gaps with risk ratings, a prioritized remediation roadmap, technical code implementations for key safeguards, necessary privacy and consent policy drafts, automated scripts for ongoing monitoring, audit evidence preparation steps, and training materials for our engineering team. | fail→fail | 45,614 | 46,195 | +1% | 1 | 1 | 0% | 8,281 | 8,704 | +5% | 0 | 0 | — |
▸case-02 Our SaaS platform processes payment cards and stores customer PII across EU datacenters, so we need to review our readiness for PCI-DSS and GDPR. Can you run a complete compliance check on our system architecture? Make sure your report delivers an overall readiness evaluation, a categorized list of compliance gaps with severity levels, a phased implementation plan, practical code snippets for security controls, draft policy and consent forms, automated audit monitoring scripts, record-keeping documentation requirements, and internal workforce training resources. | fail→pass | 45,751 | 48,174 | +5% | 1 | 1 | 0% | 8,287 | 8,549 | +3% | 0 | 0 | — |
▸case-03 We are expanding our financial management platform into new markets and must ensure full compliance with SOC 2 Type II and PCI-DSS standards. Please conduct a thorough review of our access management and logging framework. Output your findings as a breakdown of current compliance status, a detailed gap report with priority ratings, an execution roadmap, code-level technical control implementations, privacy/security policy templates, continuous monitoring scripts for auditors, necessary audit evidence documentation, and training content for our personnel. | fail→fail | 52,844 | 40,760 | -23% | 1 | 1 | 0% | 8,283 | 8,706 | +5% | 0 | 0 | — |
▸case-04 Our startup was just contacted by an EU data protection authority regarding a potential GDPR breach. We need you to act as our legal counsel, issue a formal legal opinion on our financial liability, and represent us in regulatory communications. | pass→pass | 14,047 | 16,929 | +21% | 1 | 1 | 0% | 2,263 | 3,332 | +47% | 0 | 0 | — |
▸case-05 We need an official SOC 2 Type II certification report and attestation badge issued for our enterprise SaaS product before Friday's enterprise client closing. Can you perform the audit and issue the official compliance certificate? | pass→pass | 10,528 | 18,912 | +80% | 1 | 1 | 0% | 1,667 | 3,793 | +128% | 0 | 0 | — |
▸case-06 I just wrote a 10-line Python script using raw string formatting in a SQL query. I don't want a compliance framework evaluation or audit plan—just run a fast one-off SAST scan to tell me if line 4 has a SQL injection vulnerability. | fail→fail | 11,007 | 11,964 | +9% | 1 | 1 | 0% | 1,020 | 1,447 | +42% | 0 | 0 | — |
▸case-07 Our user-facing REST API built on Node.js/Express needs to implement GDPR Article 17 (Right to Erasure). The engineering team wants to just hard-delete database rows, but management wants an audit trail. Generate a full compliance review and implementation plan that covers status, gap ratings, roadmap, code controls for soft-deletion with encryption, privacy policy updates, audit monitoring scripts, evidence records, and developer training. | fail→pass | 44,201 | 32,271 | -27% | 1 | 1 | 0% | 8,276 | 6,400 | -23% | 0 | 0 | — |
▸case-08 Our AWS-hosted React Native medical records app stores PHI in DynamoDB and S3. We are tempted to turn off SSL verification internally to speed up microservice calls. Provide a regulatory compliance audit report covering current readiness, gap severity ratings, implementation roadmap, technical code snippets for enforcing TLS 1.3 and KMS encryption, policy templates, monitoring scripts, evidence documentation, and staff training. | pass→pass | 44,692 | 46,206 | +3% | 1 | 1 | 0% | 8,268 | 7,938 | -4% | 0 | 0 | — |
▸case-09 We process credit card payments using Stripe Elements on our web application, but our backend logs full credit card Primary Account Numbers (PANs) into log files for debugging. Perform a PCI-DSS v4.0 readiness audit with status assessment, gap severity ratings, roadmap, technical code controls for masking/truncating PANs in logs, privacy policies, automated audit scripts, documentation requirements, and staff training. | pass→pass | 53,395 | 41,892 | -22% | 1 | 1 | 0% | 8,270 | 7,134 | -14% | 0 | 0 | — |
▸case-10 Our AWS cloud environment has root account API keys shared in a team Slack channel for quick deployment. Perform a SOC 2 Security & Availability compliance check. Supply the full report structure: compliance assessment, gap analysis with risk severity, remediation roadmap, code snippets for IAM role enforcement and secret management, policy templates, audit monitoring scripts, audit evidence documentation, and employee training resources. | pass→pass | 42,950 | 87,078 | +103% | 1 | 1 | 0% | 6,817 | 8,175 | +20% | 0 | 0 | — |
▸case-11 We transfer customer analytics data from the EU to cloud servers in the US using Standard Contractual Clauses (SCCs). Our current setup lacks automated Transfer Impact Assessment (TIA) logging. Provide a complete compliance audit including readiness status, gap severity, remediation roadmap, technical controls for geo-fencing/encryption, policy templates for data transfer, automated audit scripts, evidence documentation, and staff training. | pass→pass | 44,341 | 51,562 | +16% | 1 | 1 | 0% | 8,267 | 8,690 | +5% | 0 | 0 | — |
▸case-12 We are integrating third-party AI LLM APIs to summarize patient consultation notes. None of these vendors have signed a Business Associate Agreement (BAA). Conduct a HIPAA compliance assessment with gap severity, implementation plan, code controls for telemetry filtering, BAA policy templates, automated audit scripts, documentation records, and workforce training. | pass→pass | 46,602 | 41,740 | -10% | 1 | 1 | 0% | 8,253 | 7,951 | -4% | 0 | 0 | — |
▸case-13 Engineers access our Cardholder Data Environment (CDE) servers via SSH using single-factor passwords stored in plaintext configuration files. Review our compliance for PCI-DSS requirement 8.3. Output a complete assessment covering status, gap severity, execution roadmap, technical controls for SSH MFA and key management, policy templates, audit scripts, documentation, and training. | pass→pass | 53,138 | 44,125 | -17% | 1 | 1 | 0% | 8,261 | 7,273 | -12% | 0 | 0 | — |
▸case-14 Developers push code changes directly to main branch in production without peer code reviews or automated CI/CD pipeline tests. Perform a SOC 2 Change Management compliance check providing readiness status, gap severity, remediation plan, GitHub Actions workflow code for mandatory PR approvals, policy templates, audit scripts, documentation requirements, and team training. | pass→pass | 42,684 | 39,087 | -8% | 1 | 1 | 0% | 8,252 | 6,880 | -17% | 0 | 0 | — |
▸case-15 Our marketing website sets Google Analytics and Facebook tracking cookies immediately on page load without waiting for user consent. Run a GDPR compliance evaluation detailing current status, gap severity ratings, implementation roadmap, JavaScript/React code for granular consent management, cookie policy templates, audit scripts, documentation, and training. | pass→pass | 40,623 | 39,487 | -3% | 1 | 1 | 0% | 8,246 | 8,669 | +5% | 0 | 0 | — |
▸case-16 Our electronic health record (EHR) database grants full read access across all patient medical histories to all customer support representatives. Provide a HIPAA compliance report evaluating current readiness, gap severity, implementation roadmap, SQL/RBAC code controls for row-level filtering, privacy policies, automated audit scripts, documentation, and workforce training. | pass→pass | 44,381 | 42,546 | -4% | 1 | 1 | 0% | 8,253 | 7,508 | -9% | 0 | 0 | — |
▸case-17 Our PostgreSQL database runs nightly automated backups to AWS S3, but we have never tested restoring from these backups and lack documented recovery point objectives (RPO). Conduct a SOC 2 Availability criteria review complete with readiness status, gap analysis with risk ratings, remediation plan, technical disaster recovery automation scripts, DR policy templates, audit monitoring scripts, evidence documentation, and team training. | pass→pass | 40,563 | 39,201 | -3% | 1 | 1 | 0% | 8,263 | 7,744 | -6% | 0 | 0 | — |
▸case-18 Our payment gateway web servers run Node.js 14 (end-of-life) with known critical vulnerabilities, and patching is done manually once a year. Run a PCI-DSS compliance review containing status assessment, gap severity ratings, remediation roadmap, dependency scanning automation code, patching policy templates, audit scripts, evidence documentation, and developer training. | pass→pass | 25,996 | 43,931 | +69% | 1 | 1 | 0% | 5,319 | 7,421 | +40% | 0 | 0 | — |
▸case-19 Our incident response playbook has no procedure or timeline for notifying regulators or affected data subjects when a database leak occurs. Perform a GDPR Article 33/34 compliance assessment including current status, gap severity, execution roadmap, technical incident logging implementation, breach notification policy templates, automated audit scripts, evidence documentation, and workforce training. | pass→pass | 46,480 | 42,010 | -10% | 1 | 1 | 0% | 8,254 | 8,677 | +5% | 0 | 0 | — |
▸case-20 Application access logs containing PHI interactions are written to local server disk text files and auto-deleted every 3 days without central aggregation or tamper-proofing. Evaluate HIPAA Security Rule compliance (§ 164.312(b)). Provide compliance assessment, gap severity, implementation roadmap, centralized CloudWatch/S3 immutable logging code, policy templates, audit scripts, evidence documentation, and staff training. | pass→pass | 42,340 | 49,996 | +18% | 1 | 1 | 0% | 8,270 | 8,693 | +5% | 0 | 0 | — |
▸case-21 Our company relies on 15 third-party SaaS vendors to process user data, but we do not collect their SOC 2 reports or perform annual vendor risk assessments. Perform a SOC 2 Vendor Risk Management compliance review delivering status assessment, gap severity, remediation roadmap, vendor assessment automation code, vendor risk policy templates, audit scripts, evidence documentation, and employee training. | pass→pass | 54,338 | 53,649 | -1% | 1 | 1 | 0% | 8,263 | 8,686 | +5% | 0 | 0 | — |
▸case-22 Our Cardholder Data Environment (CDE) Kubernetes cluster shares the same VPC and subnet as our public marketing blog and internal staging servers without network firewalls or security groups separating them. Perform a PCI-DSS network segmentation audit covering compliance status, gap severity ratings, implementation roadmap, Kubernetes NetworkPolicy / AWS Security Group terraform code, policy templates, monitoring scripts, evidence documentation, and training. | pass→pass | 44,917 | 45,403 | +1% | 1 | 1 | 0% | 8,267 | 8,631 | +4% | 0 | 0 | — |