Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
travisjneuman avatar

Compliance Engineering

  • 80 installs
  • 86 repo stars
  • Updated July 17, 2026
  • travisjneuman/.claude

Helps with ai & agent building tasks during AI-assisted development.

About

compliance-engineering is a Claude Code skill for ai & agent building. It helps solo builders move faster with AI-assisted coding.

  • compliance-engineering
  • AI & Agent Building
  • AI-coding skill

Compliance Engineering by the numbers

  • 80 all-time installs (skills.sh)
  • +3 installs in the week ending Aug 5, 2026 (Skillselion tracking)
  • Ranked #5,249 of 16,546 AI & Agent Building skills by installs in the Skillselion catalog
  • Data as of Aug 5, 2026 (Skillselion catalog sync)
npx skills add https://github.com/travisjneuman/.claude --skill compliance-engineering

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs80
repo stars86
Last updatedJuly 17, 2026
Repositorytravisjneuman/.claude

What it does

Helps with ai & agent building tasks during AI-assisted development.

Files

SKILL.mdMarkdownGitHub ↗

Compliance Engineering

Framework Overview

FrameworkScopeKey Requirements
SOC 2Service organizationsSecurity, availability, confidentiality, privacy, processing integrity
HIPAAHealthcare data (PHI)Encryption, access controls, audit logging, BAAs
GDPREU personal dataConsent, data minimization, right to erasure, DPIAs
PCI-DSSPayment card dataNetwork segmentation, encryption, access controls, logging
FedRAMPUS government cloudNIST 800-53 controls, continuous monitoring, authorization

SOC 2 Controls in Code

Audit Logging

interface AuditEvent {
  timestamp: string;
  actor: { id: string; role: string; ip: string };
  action: string;
  resource: { type: string; id: string };
  outcome: 'success' | 'failure';
  metadata: Record<string, unknown>;
}

async function auditLog(event: AuditEvent): Promise<void> {
  // Write-once, append-only storage (immutable)
  await auditStore.append({
    ...event,
    timestamp: new Date().toISOString(),
    hash: computeChainHash(event), // tamper detection
  });
}

Access Control

// RBAC with principle of least privilege
const permissions = {
  admin: ['read', 'write', 'delete', 'manage_users'],
  editor: ['read', 'write'],
  viewer: ['read'],
} as const;

function authorize(user: User, action: string, resource: Resource): boolean {
  const allowed = permissions[user.role];
  if (!allowed?.includes(action)) {
    auditLog({ action, outcome: 'failure', actor: user, resource });
    return false;
  }
  return true;
}

HIPAA Technical Safeguards

  • Encryption at rest: AES-256 for PHI storage, AWS KMS / GCP KMS for key management
  • Encryption in transit: TLS 1.2+ mandatory, certificate pinning for mobile
  • Access controls: Unique user IDs, automatic logoff, MFA required
  • Audit controls: Log all PHI access, retain logs 6+ years, tamper-evident
  • Data backup: Encrypted backups, tested restore procedures, geographic redundancy

GDPR Implementation

Consent Management

interface ConsentRecord {
  userId: string;
  purpose: string;
  granted: boolean;
  timestamp: string;
  source: 'explicit' | 'legitimate_interest';
  withdrawable: boolean;
}

// Data Subject Access Request (DSAR)
async function handleDSAR(userId: string, type: 'access' | 'erasure' | 'portability') {
  switch (type) {
    case 'access': return await exportUserData(userId); // JSON/CSV
    case 'erasure': return await deleteUserData(userId); // Right to be forgotten
    case 'portability': return await exportPortableData(userId); // Machine-readable
  }
}

Data Minimization

  • Collect only what's needed for the stated purpose
  • Set retention policies with automatic deletion
  • Pseudonymize where possible (replace PII with tokens)
  • Anonymize for analytics (k-anonymity, differential privacy)

PCI-DSS Key Controls

  • Never store CVV/CVC — ever, in any form
  • Tokenize card numbers — use Stripe/Braintree tokens instead of raw PANs
  • Network segmentation — isolate cardholder data environment (CDE)
  • Quarterly vulnerability scans — ASV-approved external scans
  • Penetration testing — annual at minimum, after significant changes

Compliance as Code

  • Policy as code: Open Policy Agent (OPA), AWS Config Rules, Azure Policy
  • Infrastructure compliance: Terraform Sentinel, Checkov, tfsec
  • Runtime compliance: Falco for container monitoring, AWS GuardDuty
  • Evidence collection: Automated screenshot/log collection for audit evidence

Related skills

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.