▸case-01 We need to document our cardholder data environment (CDE) for an upcoming PCI DSS assessment. Please map out the end-to-end flow of payment card data from our web checkout through the payment gateway, application services, and backend databases. Make sure it visually distinguishes network boundaries, access controls, retention periods, and audit logging for our external assessor, and output the final result as an editable diagram file. | fail→fail | 36,658 | 35,554 | -3% | 1 | 1 | 0% | 6,224 | 6,756 | +9% | 0 | 0 | — |
▸case-02 Can you create an architecture diagram showing how patient electronic health records (ePHI) move through our telemetry processing platform? Show the ingress endpoints, cloud data stores, third-party analytics integrations, and backup storage, including details on access policies and data retention. I need this formatted as a native diagram file that my engineering team can edit directly. | fail→fail | 28,862 | 31,311 | +8% | 1 | 1 | 0% | 4,842 | 6,741 | +39% | 0 | 0 | — |
▸case-03 Our defense contracting team needs a data flow diagram for Controlled Unclassified Information (CUI) passing through our AWS GovCloud environment to satisfy CMMC Level 2 requirements. Please outline the data lifecycle across ingestion, processing, storage, and external transfers, highlighting trust boundaries and compliance controls, and provide it as an editable draw.io compatible file. | fail→fail | 33,537 | 32,724 | -2% | 1 | 1 | 0% | 6,210 | 6,742 | +9% | 0 | 0 | — |
▸case-04 We are preparing for our ISO 27001 audit and need to draft a formal Information Security Policy document covering acceptable use, password complexity, and workstation locking rules. Please draft this written policy document for our employee handbook. | pass→fail | 18,506 | 32,036 | +73% | 1 | 1 | 0% | 2,877 | 6,719 | +134% | 0 | 0 | — |
▸case-05 We need to configure an AWS Security Group in Terraform to restrict incoming SSH traffic on port 22 to our corporate bastion IP range (198.51.100.0/24) and block all other public access. Please write the HCL configuration file for this infrastructure code. | pass→pass | 10,239 | 13,946 | +36% | 1 | 1 | 0% | 1,811 | 3,080 | +70% | 0 | 0 | — |
▸case-06 Our compliance team needs a written audit checklist for evaluating SOC 2 Type II Security and Availability trust services criteria during our vendor risk review. Please provide a structured text questionnaire checklist. | pass→pass | 21,694 | 23,863 | +10% | 1 | 1 | 0% | 3,550 | 4,335 | +22% | 0 | 0 | — |
▸case-07 Our C-suite wants a high-level summary diagram of customer data moving through our multi-tenant SaaS application to present to the board. We want to highlight business impact and data lifecycle phases without clogging the view with deep engineering network packets or individual IP addresses. Please provide an editable diagram file. | fail→pass | 15,407 | 31,949 | +107% | 1 | 1 | 0% | 2,459 | 6,732 | +174% | 0 | 0 | — |
▸case-08 Our DevOps team is building a payment transaction pipeline across several Kubernetes pods. We need an actionable diagram detailing automated microservice calls, database connection strings, retry queues, and failure exception paths so engineers can debug routing drops. Output an editable diagram file. | fail→fail | 18,634 | 32,281 | +73% | 1 | 1 | 0% | 3,177 | 6,722 | +112% | 0 | 0 | — |
▸case-09 We are designing a diagram for our cloud data pipeline (AWS Lambda, S3 ingestion bucket, and PostgreSQL database). Base models often color database servers green or orange. Please output an editable diagram XML where core cloud systems and platform services follow standard GRC visual color conventions. | fail→pass | 30,154 | 30,543 | +1% | 1 | 1 | 0% | 6,195 | 6,727 | +9% | 0 | 0 | — |
▸case-10 In our data pipeline diagram, we need to distinguish technical cloud infrastructure from verified security controls like automated KMS encryption and manager approval gates. Output a draw.io compatible diagram XML that correctly highlights validated compliance controls using visual color conventions. | fail→fail | 31,712 | 30,777 | -3% | 1 | 1 | 0% | 6,186 | 6,718 | +9% | 0 | 0 | — |
▸case-11 We need a diagram mapping our legacy user auth pathway where an unencrypted legacy storage bucket was flagged as a major audit finding alongside an overdue risk item. Output an editable diagram XML using distinct visual colors for flagged risks and failed controls. | pass→pass | 31,473 | 30,862 | -2% | 1 | 1 | 0% | 6,187 | 6,719 | +9% | 0 | 0 | — |
▸case-12 We need a data flow diagram showing customer data transferred offsite to a third-party manual document scanning vendor. Please generate an editable diagram file using color conventions that clearly mark manual steps and external third-party organizations. | fail→fail | 23,345 | 31,520 | +35% | 1 | 1 | 0% | 2,782 | 6,716 | +141% | 0 | 0 | — |
▸case-13 When mapping our HIPAA compliance environment, we need to show our cloud Virtual Private Cloud (VPC) as a distinct authorization boundary containing all ePHI services. Provide an editable diagram XML file that formats the boundary container properly. | pass→pass | 29,036 | 31,151 | +7% | 1 | 1 | 0% | 6,185 | 6,717 | +9% | 0 | 0 | — |
▸case-14 We are mapping our financial reporting pipeline where primary transaction data flows into our ledger, while audit log attestations flow separately to a SOC 2 evidence repository. Generate an editable diagram file applying proper line styles for data paths versus attestation paths. | pass→fail | 14,591 | 30,904 | +112% | 1 | 1 | 0% | 2,645 | 6,721 | +154% | 0 | 0 | — |
▸case-15 In our fraud detection data flow, normal transactions process automatically, but flagged high-risk transactions follow a manual human escalation path. Generate an editable diagram XML that distinguishes optional or manual exception paths visually. | pass→fail | 25,301 | 30,547 | +21% | 1 | 1 | 0% | 5,353 | 6,712 | +25% | 0 | 0 | — |
▸case-16 We are preparing a GRC data flow diagram that uses dashed containers for audit scope, green nodes for controls, red nodes for risks, and dashed edges for evidence attestations. Provide an editable diagram file formatted so external auditors can interpret these color and line meanings without guessing. | pass→pass | 22,360 | 30,380 | +36% | 1 | 1 | 0% | 4,240 | 6,727 | +59% | 0 | 0 | — |
▸case-17 Generate a data flow diagram for our FedRAMP Moderate boundary mapping customer PII ingestion. Name the diagram file strictly following clean GRC naming conventions and output the raw editable diagram file. | fail→pass | 18,683 | 32,089 | +72% | 1 | 1 | 0% | 3,208 | 6,710 | +109% | 0 | 0 | — |
▸case-18 We need a data flow diagram for employee personal data transfers under GDPR. Show where HR data branches based on residency (EU vs Non-EU) and clarify which team owns each processing step rather than leaving generic unlabeled boxes. Output an editable diagram XML. | pass→pass | 30,093 | 33,349 | +11% | 1 | 1 | 0% | 6,191 | 6,723 | +9% | 0 | 0 | — |
▸case-19 Map out our customer log aggregation pipeline into SIEM storage. Base models often put a generic, unassigned box labeled 'Compliance' in the middle of the flow. Please generate an editable diagram XML where every node represents a concrete role, system, artifact, or automated action. | pass→pass | 30,740 | 32,644 | +6% | 1 | 1 | 0% | 6,196 | 6,728 | +9% | 0 | 0 | — |
▸case-20 Create a data flow diagram for our financial advisory portal showing how Restricted Financial Data and Public Marketing Data move through our API gateway to backend stores. Provide an editable diagram file with clear classification overlays. | pass→pass | 18,739 | 33,001 | +76% | 1 | 1 | 0% | 3,089 | 6,711 | +117% | 0 | 0 | — |
▸case-21 We are auditing our healthcare claims intake engine. The assessor needs to see where claims data is ingested, how long it resides in hot storage, and where audit access logs are shipped. Provide an editable diagram XML including these GRC governance elements. | fail→pass | 32,925 | 32,213 | -2% | 1 | 1 | 0% | 6,189 | 6,721 | +9% | 0 | 0 | — |
▸case-22 We need a data flow diagram for our payment subscription engine under PCI requirements. Please generate the complete native XML source code for draw.io directly, avoiding text-based flowchart syntaxes like Mermaid that require conversion steps. | pass→pass | 30,022 | 34,520 | +15% | 1 | 1 | 0% | 6,184 | 6,716 | +9% | 0 | 0 | — |