{"id":"17722efe-6640-4687-b479-551efad5f338","entityType":"agent","slug":"clawhub-skills-1kalin-afrexai-compliance-engine","name":"afrexai-compliance-engine","canonicalUrl":"https://www.xpersona.co/agent/clawhub-skills-1kalin-afrexai-compliance-engine","canonicalPath":"/agent/clawhub-skills-1kalin-afrexai-compliance-engine","generatedAt":"2026-10-10T01:43:19.562Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"description":"Compliance & Audit Readiness Engine Compliance & Audit Readiness Engine Your AI compliance officer. Guides startups and scale-ups through SOC 2, ISO 27001, GDPR, HIPAA, and PCI DSS — from zero to audit-ready. No consultants needed. --- Phase 1 — Compliance Discovery Framework Selection Matrix | Framework | Who Needs It | Trigger | Timeline | Cost Range | |-----------|-------------|---------|----------|------------| | **SOC 2 Type I** | Any B2B SaaS | E","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. Last updated 4/15/2026.","installCommand":"clawhub skill install skills:1kalin:afrexai-compliance-engine","sourceUrl":"https://github.com/openclaw/skills/tree/main/skills/1kalin/afrexai-compliance-engine","homepage":null,"primaryLinks":[{"label":"View on ClawHub","url":"https://github.com/openclaw/skills/tree/main/skills/1kalin/afrexai-compliance-engine","kind":"source"}],"safetyScore":84,"overallRank":62,"popularityScore":50,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Compliance & Audit Readiness Engine Compliance & Audit Readiness Engine Your AI compliance officer. Guides startups and scale-ups through SOC 2, ISO 27001, GDPR"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[{"label":"weekly","status":"self-declared"},{"label":"and","status":"self-declared"},{"label":"tickets","status":"self-declared"},{"label":"security","status":"self-declared"}],"verifiedCount":0,"selfDeclaredCount":5,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"},{"key":"weekly","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"and","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"tickets","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"security","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile capability:weekly|supported|profile capability:and|supported|profile capability:tickets|supported|profile capability:security|supported|profile"}},"adoption":{"evidence":{"source":"no-adoption-signals","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"No source adoption metrics were available."},"stars":null,"forks":null,"downloads":null,"packageName":null,"latestVersion":null,"tractionLabel":null},"release":{"evidence":{"source":"agent-index","verified":false,"confidence":"medium","updatedAt":"2026-02-25T06:17:07.374Z","emptyReason":null},"lastUpdatedAt":"2026-04-15T00:45:39.800Z","lastCrawledAt":"2026-02-25T06:17:07.374Z","lastIndexedAt":null,"nextCrawlAt":"2026-02-26T06:17:07.374Z","lastVerifiedAt":null,"highlights":[]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install skills:1kalin:afrexai-compliance-engine","setupComplexity":"low","setupSteps":["Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-1kalin-afrexai-compliance-engine/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-1kalin-afrexai-compliance-engine/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-1kalin-afrexai-compliance-engine/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-skills-1kalin-afrexai-compliance-engine/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-skills-1kalin-afrexai-compliance-engine/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-skills-1kalin-afrexai-compliance-engine/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T01:43:19.561Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-1kalin-afrexai-compliance-engine/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-1kalin-afrexai-compliance-engine/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-1kalin-afrexai-compliance-engine/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-1kalin-afrexai-compliance-engine/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"readme":"# Compliance & Audit Readiness Engine\n\nYour AI compliance officer. Guides startups and scale-ups through SOC 2, ISO 27001, GDPR, HIPAA, and PCI DSS — from zero to audit-ready. No consultants needed.\n\n---\n\n## Phase 1 — Compliance Discovery\n\n### Framework Selection Matrix\n\n| Framework | Who Needs It | Trigger | Timeline | Cost Range |\n|-----------|-------------|---------|----------|------------|\n| **SOC 2 Type I** | Any B2B SaaS | Enterprise prospect asks | 3-6 months | $20K-$80K |\n| **SOC 2 Type II** | Established SaaS | After Type I, or direct | 6-12 months | $30K-$100K |\n| **ISO 27001** | Global/EU-facing SaaS | EU enterprise deals | 6-12 months | $40K-$120K |\n| **GDPR** | Anyone with EU users | Day 1 if EU data | 1-3 months | $5K-$30K |\n| **HIPAA** | Health data handlers | Before first PHI | 3-6 months | $20K-$60K |\n| **PCI DSS** | Payment processors | Before card data | 3-9 months | $15K-$50K |\n| **SOX** | Public companies | IPO prep | 12-18 months | $100K-$500K |\n\n### Readiness Assessment Brief\n\n```yaml\ncompany_profile:\n  name: \"\"\n  industry: \"\"\n  employee_count: 0\n  annual_revenue: \"\"\n  data_types_handled:\n    - PII (names, emails, addresses)\n    - Financial (payment cards, bank accounts)\n    - Health (PHI, medical records)\n    - Children (COPPA scope)\n    - Biometric\n    - Government/classified\n  customer_segments:\n    - SMB\n    - Mid-market\n    - Enterprise\n    - Government\n  geographic_scope:\n    - US only\n    - US + EU\n    - Global\n  current_state:\n    existing_frameworks: []\n    security_team_size: 0\n    has_written_policies: false\n    has_asset_inventory: false\n    has_risk_assessment: false\n    has_incident_response: false\n    has_vendor_management: false\n    previous_audits: []\n    known_gaps: []\n  drivers:\n    - Customer requirement\n    - Board/investor mandate\n    - Regulatory obligation\n    - Competitive advantage\n    - Insurance requirement\n  target_frameworks: []\n  target_date: \"\"\n  budget_range: \"\"\n```\n\n### Priority Decision Rules\n\n1. **Customer asking for SOC 2?** → Start there (most requested in B2B SaaS)\n2. **EU customers?** → GDPR is non-negotiable, do it alongside SOC 2\n3. **Health data?** → HIPAA first, then layer SOC 2\n4. **Payment data?** → PCI DSS is legally required, do immediately\n5. **Multiple frameworks?** → Map common controls (40-60% overlap between SOC 2 and ISO 27001)\n\n---\n\n## Phase 2 — SOC 2 Deep Dive\n\n### Trust Service Criteria (TSC)\n\nSOC 2 is built on 5 categories. **Security** is mandatory. Others are optional but often expected.\n\n#### CC1 — Control Environment (Foundation)\n- [ ] Board/management oversight of security\n- [ ] Organizational structure with clear security roles\n- [ ] Code of conduct / acceptable use policy\n- [ ] HR processes (background checks, onboarding, offboarding)\n- [ ] Performance evaluations include security responsibilities\n\n#### CC2 — Communication & Information\n- [ ] Security policies documented and accessible to all employees\n- [ ] External communication channels for security (status page, security@)\n- [ ] Whistleblower / anonymous reporting mechanism\n- [ ] Security awareness training program (annual + onboarding)\n- [ ] System description document maintained\n\n#### CC3 — Risk Assessment\n- [ ] Annual risk assessment process documented\n- [ ] Risk register maintained with likelihood × impact scoring\n- [ ] Risk treatment plans for high/critical risks\n- [ ] Risk appetite statement approved by management\n- [ ] Changes in business/technology trigger risk re-assessment\n\n#### CC4 — Monitoring Activities\n- [ ] Continuous monitoring of controls (not just annual)\n- [ ] Internal audit or self-assessment program\n- [ ] Deficiency tracking and remediation\n- [ ] Management review of monitoring results\n- [ ] Penetration testing (annual minimum)\n\n#### CC5 — Control Activities\n- [ ] Logical access controls (RBAC, least privilege)\n- [ ] Physical access controls (offices, data centers)\n- [ ] Change management process\n- [ ] System development lifecycle (SDLC)\n- [ ] Data backup and recovery procedures\n\n#### CC6 — Logical & Physical Access\n- [ ] User provisioning and deprovisioning process\n- [ ] MFA enforced on all critical systems\n- [ ] Password policy (12+ chars, complexity, rotation)\n- [ ] Access reviews (quarterly minimum)\n- [ ] Physical access logs for sensitive areas\n- [ ] Encryption at rest (AES-256) and in transit (TLS 1.2+)\n- [ ] Firewall rules reviewed quarterly\n- [ ] VPN or zero-trust network access\n\n#### CC7 — System Operations\n- [ ] Monitoring and alerting (uptime, errors, security events)\n- [ ] Incident detection and response procedures\n- [ ] Vulnerability management (scan weekly, patch critical <72h)\n- [ ] Anti-malware / endpoint protection\n- [ ] Capacity planning and performance monitoring\n\n#### CC8 — Change Management\n- [ ] Formal change request and approval process\n- [ ] Separation of duties (dev ≠ prod deploy)\n- [ ] Testing before production deployment\n- [ ] Rollback procedures documented\n- [ ] Emergency change process with post-hoc approval\n\n#### CC9 — Risk Mitigation (Vendors)\n- [ ] Vendor risk assessment before onboarding\n- [ ] Vendor inventory with criticality ratings\n- [ ] Annual vendor reviews\n- [ ] BAAs / DPAs with sub-processors\n- [ ] Vendor offboarding process\n\n### Additional Criteria\n\n**Availability (A1):**\n- [ ] SLAs defined and monitored\n- [ ] Disaster recovery plan tested annually\n- [ ] Business continuity plan documented\n- [ ] RTO/RPO defined for critical systems\n- [ ] Redundancy for critical infrastructure\n\n**Confidentiality (C1):**\n- [ ] Data classification scheme (Public, Internal, Confidential, Restricted)\n- [ ] Handling procedures per classification level\n- [ ] Confidentiality agreements (NDA) with employees and vendors\n- [ ] Data retention and disposal policies\n- [ ] DLP controls for sensitive data\n\n**Processing Integrity (PI1):**\n- [ ] Input validation controls\n- [ ] Processing completeness and accuracy checks\n- [ ] Output reconciliation procedures\n- [ ] Error handling and correction processes\n\n**Privacy (P1):**\n- [ ] Privacy notice published\n- [ ] Consent mechanisms for data collection\n- [ ] Data subject rights procedures (access, deletion, portability)\n- [ ] Privacy impact assessments for new features\n- [ ] Data breach notification procedures\n\n### SOC 2 Project Plan (16-Week Sprint)\n\n| Week | Phase | Key Activities |\n|------|-------|---------------|\n| 1-2 | **Scoping** | Define system boundaries, select TSC, choose auditor |\n| 3-4 | **Gap Assessment** | Audit current state against TSC, document gaps |\n| 5-6 | **Policy Writing** | Draft all required policies (see policy list below) |\n| 7-8 | **Control Implementation** | Deploy technical controls, configure tools |\n| 9-10 | **Process Implementation** | Establish operational processes, train team |\n| 11-12 | **Evidence Collection** | Gather evidence for all controls, test internally |\n| 13-14 | **Readiness Assessment** | Mock audit, remediate findings |\n| 15-16 | **Type I Audit** | Auditor fieldwork, management response, report |\n\n### Required Policy Documents\n\n1. **Information Security Policy** — Master policy, scope, objectives\n2. **Access Control Policy** — Authentication, authorization, reviews\n3. **Change Management Policy** — SDLC, deployment, emergency changes\n4. **Incident Response Policy** — Detection, response, notification\n5. **Risk Management Policy** — Assessment methodology, treatment, appetite\n6. **Data Classification Policy** — Levels, handling, retention, disposal\n7. **Acceptable Use Policy** — Employee responsibilities, prohibited actions\n8. **Vendor Management Policy** — Assessment, monitoring, offboarding\n9. **Business Continuity / DR Policy** — Plans, testing, RTO/RPO\n10. **HR Security Policy** — Background checks, onboarding, offboarding, training\n11. **Encryption Policy** — Standards, key management, certificate handling\n12. **Physical Security Policy** — Office access, visitor management, clean desk\n13. **Logging & Monitoring Policy** — What to log, retention, alerting\n14. **Password & Authentication Policy** — Standards, MFA requirements\n15. **Backup & Recovery Policy** — Schedule, testing, retention\n\n### Policy Template\n\n```markdown\n# [Policy Name]\n\n**Version:** 1.0\n**Owner:** [Name, Title]\n**Approved by:** [Name, Title]\n**Effective date:** [Date]\n**Next review:** [Date + 1 year]\n**Classification:** Internal\n\n## 1. Purpose\n[Why this policy exists — 2-3 sentences]\n\n## 2. Scope\n[Who and what this policy applies to]\n\n## 3. Policy Statements\n[Numbered, actionable requirements — not aspirational]\n\n### 3.1 [Topic]\n- SHALL [requirement]\n- SHALL NOT [prohibition]\n- SHOULD [recommendation]\n\n## 4. Roles & Responsibilities\n| Role | Responsibility |\n|------|---------------|\n| [Role] | [What they must do] |\n\n## 5. Exceptions\n[Process for requesting exceptions — who approves, how long, documentation]\n\n## 6. Enforcement\n[Consequences of non-compliance]\n\n## 7. Definitions\n[Technical terms used in the policy]\n\n## 8. Related Documents\n[Links to related policies, standards, procedures]\n\n## 9. Revision History\n| Version | Date | Author | Changes |\n|---------|------|--------|---------|\n| 1.0 | [Date] | [Author] | Initial release |\n```\n\n---\n\n## Phase 3 — ISO 27001 Framework\n\n### ISMS Implementation Roadmap\n\n#### Clause 4 — Context of the Organization\n- [ ] Define ISMS scope and boundaries\n- [ ] Identify interested parties and their requirements\n- [ ] Determine internal and external issues\n- [ ] Document scope statement\n\n#### Clause 5 — Leadership\n- [ ] Management commitment statement\n- [ ] Information security policy (signed by CEO/CTO)\n- [ ] Assign ISMS roles and responsibilities\n- [ ] Allocate resources (budget, people, tools)\n\n#### Clause 6 — Planning\n- [ ] Risk assessment methodology (ISO 27005 or custom)\n- [ ] Risk assessment execution\n- [ ] Risk treatment plan\n- [ ] Statement of Applicability (SoA) — map all 93 Annex A controls\n- [ ] Information security objectives (measurable, time-bound)\n\n#### Clause 7 — Support\n- [ ] Determine required competencies\n- [ ] Security awareness program\n- [ ] Internal and external communication plan\n- [ ] Document control process\n\n#### Clause 8 — Operation\n- [ ] Execute risk treatment plan\n- [ ] Implement controls from SoA\n- [ ] Manage operational changes\n- [ ] Conduct risk assessments on changes\n\n#### Clause 9 — Performance Evaluation\n- [ ] Monitoring and measurement program\n- [ ] Internal audit schedule and execution\n- [ ] Management review (at least annually)\n- [ ] Corrective action tracking\n\n#### Clause 10 — Improvement\n- [ ] Nonconformity and corrective action process\n- [ ] Continual improvement program\n- [ ] Lessons learned integration\n\n### ISO 27001:2022 Annex A Control Categories\n\n| Category | Controls | Key Areas |\n|----------|----------|-----------|\n| A.5 Organizational | 37 | Policies, roles, threat intel, asset mgmt, access, supplier |\n| A.6 People | 8 | Screening, T&C, awareness, disciplinary, termination |\n| A.7 Physical | 14 | Perimeters, entry, offices, monitoring, utilities, cabling |\n| A.8 Technological | 34 | Endpoints, access rights, auth, malware, vuln mgmt, logging, crypto, SDLC |\n\n### SOC 2 ↔ ISO 27001 Control Mapping (Save 40-60% effort)\n\n| SOC 2 TSC | ISO 27001 Annex A | Overlap |\n|-----------|------------------|---------|\n| CC1 Control Environment | A.5.1-5.6 (Org controls) | ~80% |\n| CC2 Communication | A.5.1, A.6.3 (Awareness) | ~70% |\n| CC3 Risk Assessment | Clause 6.1, A.5.7 (Threat intel) | ~90% |\n| CC5 Control Activities | A.8 (Technological) | ~75% |\n| CC6 Access | A.5.15-5.18, A.8.1-8.5 | ~85% |\n| CC7 Operations | A.8.7-8.16 (Monitoring) | ~80% |\n| CC8 Change Mgmt | A.8.25-8.33 (SDLC) | ~70% |\n| CC9 Vendors | A.5.19-5.23 (Supplier) | ~85% |\n\n**Strategy:** Build for one framework, extend to the other. SOC 2 first (faster) → ISO 27001 (adds clauses 4-10 management system).\n\n---\n\n## Phase 4 — GDPR Compliance Program\n\n### 12 Core Requirements\n\n1. **Lawful Basis for Processing** — Document legal basis for each data processing activity\n   - Consent | Contract | Legal obligation | Vital interest | Public task | Legitimate interest\n   - [ ] Data processing register (Article 30)\n   - [ ] Legitimate Interest Assessments (LIAs) where applicable\n\n2. **Data Subject Rights** — Respond within 30 days\n   - [ ] Right of access (SAR) process\n   - [ ] Right to rectification\n   - [ ] Right to erasure (\"right to be forgotten\")\n   - [ ] Right to data portability (machine-readable export)\n   - [ ] Right to restrict processing\n   - [ ] Right to object\n   - [ ] Automated decision-making opt-out\n\n3. **Privacy by Design & Default** — Build privacy into products\n   - [ ] Privacy Impact Assessment (PIA/DPIA) template\n   - [ ] Data minimization review for each feature\n   - [ ] Default privacy settings (opt-in, not opt-out)\n\n4. **Data Protection Officer (DPO)** — Required if:\n   - Public authority, OR\n   - Large-scale systematic monitoring, OR\n   - Large-scale processing of special category data\n\n5. **Consent Management**\n   - [ ] Granular consent mechanisms (not bundled)\n   - [ ] Easy withdrawal (as easy as giving consent)\n   - [ ] Consent records with timestamp, version, scope\n   - [ ] Cookie consent banner (ePrivacy)\n\n6. **Data Processing Agreements (DPAs)**\n   - [ ] DPA template for sub-processors\n   - [ ] Article 28 requirements checklist\n   - [ ] Sub-processor notification process\n   - [ ] Sub-processor register\n\n7. **International Transfers**\n   - [ ] Transfer mechanism (SCCs, adequacy decision, BCRs)\n   - [ ] Transfer Impact Assessment\n   - [ ] Supplementary measures where needed\n\n8. **Breach Notification**\n   - [ ] 72-hour notification to supervisory authority\n   - [ ] \"Undue delay\" notification to affected individuals\n   - [ ] Breach register with risk assessment\n   - [ ] Breach response team and escalation path\n\n9. **Records of Processing Activities (ROPA)**\n\n```yaml\nprocessing_activity:\n  name: \"\"\n  purpose: \"\"\n  lawful_basis: \"\"\n  data_categories: []\n  data_subjects: []\n  recipients: []\n  retention_period: \"\"\n  transfers_outside_eea: false\n  transfer_mechanism: \"\"\n  technical_measures: []\n  organizational_measures: []\n  dpia_required: false\n  last_reviewed: \"\"\n```\n\n10. **Privacy Notice** — Must include:\n    - Identity of controller\n    - DPO contact (if applicable)\n    - Purposes and lawful basis\n    - Categories of data\n    - Recipients / transfers\n    - Retention periods\n    - Data subject rights\n    - Right to complain to supervisory authority\n    - Whether providing data is statutory/contractual requirement\n\n11. **Data Retention Schedule**\n\n| Data Type | Retention Period | Legal Basis | Disposal Method |\n|-----------|-----------------|-------------|-----------------|\n| Customer PII | Duration + 3 years | Contract + legitimate interest | Automated deletion |\n| Employee records | Duration + 7 years | Legal obligation | Secure shred |\n| Financial records | 7 years | Legal obligation | Secure shred |\n| Server logs | 90 days | Legitimate interest | Automated rotation |\n| Marketing consent | Until withdrawn | Consent | Database purge |\n| Support tickets | 2 years after resolution | Legitimate interest | Automated deletion |\n\n12. **Training & Awareness**\n    - [ ] Mandatory GDPR training for all employees (annual)\n    - [ ] Role-specific training (developers, support, marketing, HR)\n    - [ ] Training records with completion tracking\n\n---\n\n## Phase 5 — HIPAA Compliance (Health Data)\n\n### HIPAA Security Rule — 3 Safeguard Categories\n\n#### Administrative Safeguards\n- [ ] Security Management Process (risk analysis, risk management)\n- [ ] Assigned Security Responsibility (HIPAA Security Officer)\n- [ ] Workforce Security (authorization, clearance, termination)\n- [ ] Information Access Management (access authorization, establishment, modification)\n- [ ] Security Awareness Training (reminders, malware, login monitoring, password mgmt)\n- [ ] Security Incident Procedures (response, reporting)\n- [ ] Contingency Plan (backup, DR, emergency mode, testing)\n- [ ] Evaluation (periodic technical/non-technical)\n- [ ] BAAs with all business associates\n\n#### Physical Safeguards\n- [ ] Facility Access Controls (contingency ops, facility security plan, access control, maintenance records)\n- [ ] Workstation Use (policies, restrictions)\n- [ ] Workstation Security (physical safeguards)\n- [ ] Device and Media Controls (disposal, re-use, accountability, data backup)\n\n#### Technical Safeguards\n- [ ] Access Control (unique user ID, emergency access, automatic logoff, encryption)\n- [ ] Audit Controls (hardware, software, procedural mechanisms)\n- [ ] Integrity Controls (authentication of ePHI, transmission security)\n- [ ] Person or Entity Authentication (verify identity)\n- [ ] Transmission Security (integrity controls, encryption)\n\n### HIPAA Breach Rule\n- **≤500 individuals:** Annual batch notification to HHS (within 60 days of year end)\n- **>500 individuals:** Notify HHS within 60 days + media notification\n- **All breaches:** Notify affected individuals without unreasonable delay (≤60 days)\n- **Penalties:** $100-$50,000 per violation, up to $1.5M per year per category\n\n---\n\n## Phase 6 — PCI DSS 4.0 (Payment Data)\n\n### 12 Requirements Summary\n\n| # | Requirement | Key Controls |\n|---|------------|-------------|\n| 1 | Install/maintain network security controls | Firewalls, network segmentation |\n| 2 | Apply secure configurations | No vendor defaults, CIS benchmarks |\n| 3 | Protect stored account data | Encryption, masking, key mgmt |\n| 4 | Encrypt transmission over open networks | TLS 1.2+, no SSL/early TLS |\n| 5 | Protect from malicious software | Anti-malware, regular updates |\n| 6 | Develop secure systems | SDLC, vuln mgmt, WAF |\n| 7 | Restrict access by business need | RBAC, least privilege |\n| 8 | Identify users and authenticate | MFA, password standards |\n| 9 | Restrict physical access | Badges, cameras, visitor logs |\n| 10 | Log and monitor all access | Centralized logging, review |\n| 11 | Test security regularly | Vuln scans, pen tests, IDS |\n| 12 | Support security with policies | Policies, training, incident response |\n\n### Scope Reduction Strategy\n- **Use tokenization** — Replace card data with tokens (Stripe, Braintree handle PCI for you)\n- **Use hosted payment pages** — Never touch raw card data (SAQ A instead of SAQ D)\n- **Network segmentation** — Isolate cardholder data environment\n- **Cloud provider compliance** — Leverage AWS/GCP/Azure PCI certifications\n\n**SAQ Decision:**\n- Fully outsourced (Stripe Checkout) → **SAQ A** (22 controls, simplest)\n- API-based (Stripe Elements) → **SAQ A-EP** (~140 controls)\n- You store/process card data → **SAQ D** (300+ controls, avoid this)\n\n---\n\n## Phase 7 — Compliance Tooling Stack\n\n### Essential Tools by Category\n\n| Category | Budget Option | Mid-Range | Enterprise |\n|----------|-------------|-----------|-----------|\n| GRC Platform | Notion/Sheets | Vanta, Drata | ServiceNow, OneTrust |\n| Policy Mgmt | Google Docs + versioning | Vanta policies | Hyperproof |\n| Vulnerability Scanning | OWASP ZAP, Trivy | Qualys, Tenable | Rapid7 |\n| SIEM/Logging | ELK Stack, Wazuh | Datadog, Sumo Logic | Splunk |\n| Endpoint Protection | CrowdStrike Falcon Go | SentinelOne | CrowdStrike Enterprise |\n| Identity/Access | Google Workspace + Okta | JumpCloud | Azure AD P2 |\n| Training | KnowBe4 Free | KnowBe4 | Proofpoint |\n| Pen Testing | HackerOne Community | Cobalt | Bishop Fox |\n| Backup | Native cloud backups | Veeam | Commvault |\n\n### Automation-First Compliance\n\n**What to automate (saves 70%+ of audit prep):**\n- Evidence collection (screenshots of configs → API pulls)\n- Access reviews (quarterly manual → continuous monitoring)\n- Vulnerability scanning (manual → scheduled + auto-ticket)\n- Policy acknowledgment (email → onboarding workflow)\n- Vendor assessments (spreadsheets → intake forms with scoring)\n- Training tracking (manual → LMS with auto-reminders)\n\n### Compliance-as-Code Patterns\n\n```\n# Infrastructure compliance\n- Terraform with Sentinel policies (enforce encryption, tagging)\n- OPA/Rego for Kubernetes admission control\n- AWS Config Rules / Azure Policy for cloud compliance\n- GitHub branch protection rules as change management evidence\n\n# Application compliance\n- Automated dependency scanning in CI (Snyk, Dependabot)\n- SAST in PR pipeline (Semgrep, CodeQL)\n- Container scanning (Trivy, Grype)\n- License compliance (FOSSA, Licensee)\n```\n\n---\n\n## Phase 8 — Audit Preparation\n\n### 90-Day Audit Prep Checklist\n\n**Days 90-60: Foundation**\n- [ ] Confirm audit scope with auditor\n- [ ] Complete system description document\n- [ ] Verify all policies are current (reviewed within 12 months)\n- [ ] Confirm all employees completed security training\n- [ ] Run vulnerability scan and remediate critical/high findings\n- [ ] Schedule penetration test (results needed before audit)\n\n**Days 60-30: Evidence Gathering**\n- [ ] Collect evidence for each control (organized by TSC/clause)\n- [ ] Access review documentation (screenshots of reviews, action items)\n- [ ] Change management evidence (sample of tickets showing approval flow)\n- [ ] Incident response test evidence (tabletop exercise minutes)\n- [ ] DR test evidence (recovery test results, RTO achieved)\n- [ ] Vendor review evidence (assessment records, DPAs)\n- [ ] Risk assessment and treatment plan (current year)\n- [ ] Board/management meeting minutes discussing security\n\n**Days 30-0: Final Prep**\n- [ ] Internal mock audit — walk through every control\n- [ ] Remediate any mock audit findings\n- [ ] Brief team on auditor interviews (what to expect, who answers what)\n- [ ] Prepare management assertion letter\n- [ ] Set up auditor access (read-only to evidence repository)\n- [ ] Confirm all monitoring/alerting is functioning\n- [ ] Verify offboarding was completed for all departed employees\n\n### Evidence Organization\n\n```\n/compliance-evidence/\n  /SOC2-2026/\n    /CC1-control-environment/\n      org-chart.pdf\n      code-of-conduct-signed.pdf\n      background-check-process.pdf\n    /CC2-communication/\n      security-training-completion.csv\n      security-policy-acknowledgments.pdf\n    /CC3-risk-assessment/\n      risk-assessment-2026.xlsx\n      risk-treatment-plan.pdf\n    /CC6-access/\n      access-review-Q1.pdf\n      access-review-Q2.pdf\n      mfa-enforcement-screenshot.png\n      offboarding-checklist-samples/\n    /CC7-operations/\n      vulnerability-scan-reports/\n      pentest-report-2026.pdf\n      incident-log-2026.csv\n    /CC8-change-management/\n      sample-change-tickets/\n      deployment-pipeline-config.png\n    /CC9-vendors/\n      vendor-inventory.xlsx\n      vendor-assessments/\n      dpas-and-baas/\n```\n\n### Auditor Interview Prep\n\n**Common questions and who should answer:**\n\n| Question | Best Respondent | Key Points |\n|----------|----------------|-----------|\n| \"Walk me through your risk assessment process\" | CISO/Security Lead | Methodology, frequency, treatment |\n| \"How do you manage access to production?\" | Engineering Lead | RBAC, approval flow, reviews |\n| \"Describe your change management process\" | Engineering Lead | PR review, testing, deployment |\n| \"How do you handle security incidents?\" | Security Lead | Detection, response, communication |\n| \"How do you evaluate vendors?\" | Security/Procurement | Assessment, monitoring, contracts |\n| \"Describe your backup and recovery process\" | Infrastructure Lead | Schedule, testing, RTO/RPO |\n| \"How do you track and remediate vulnerabilities?\" | Security Lead | Scanning, SLAs, patching |\n| \"Walk me through employee onboarding/offboarding\" | HR + IT | Checklist, timing, verification |\n\n---\n\n## Phase 9 — Continuous Compliance\n\n### Monthly Compliance Dashboard\n\n```yaml\ncompliance_dashboard:\n  month: \"\"\n  \n  control_health:\n    total_controls: 0\n    controls_passing: 0\n    controls_failing: 0\n    controls_not_tested: 0\n    health_percentage: 0\n    \n  action_items:\n    open: 0\n    overdue: 0\n    closed_this_month: 0\n    \n  key_metrics:\n    mean_time_to_patch_critical: \"\"\n    access_reviews_completed: \"X/X\"\n    security_training_completion: \"\"\n    incidents_this_month: 0\n    vendor_reviews_due: 0\n    policies_due_for_review: 0\n    \n  risk_register:\n    high_risks: 0\n    risks_without_treatment: 0\n    new_risks_identified: 0\n    \n  upcoming:\n    next_pen_test: \"\"\n    next_dr_test: \"\"\n    next_audit: \"\"\n    next_access_review: \"\"\n```\n\n### Compliance Calendar\n\n| Frequency | Activity |\n|-----------|----------|\n| **Weekly** | Review security alerts, patch critical vulln |\n| **Monthly** | Control testing sample, metrics dashboard, policy exception review |\n| **Quarterly** | Access reviews, vendor risk check, risk register update, tabletop exercise |\n| **Semi-annual** | Vulnerability scan (external), BCP/DR test, security training refresh |\n| **Annual** | Full risk assessment, penetration test, policy review cycle, SOC 2/ISO audit, security awareness training, management review |\n\n### Compliance Debt Tracker\n\n```yaml\ncompliance_debt:\n  - id: \"CD-001\"\n    framework: \"SOC 2\"\n    control: \"CC6.1\"\n    finding: \"MFA not enforced on staging environment\"\n    severity: \"High\"\n    identified: \"2026-01-15\"\n    owner: \"\"\n    target_remediation: \"2026-02-15\"\n    status: \"In Progress\"\n    compensating_control: \"VPN + IP allowlisting\"\n```\n\n### When Controls Fail\n\n**Severity-based response:**\n\n| Severity | Response Time | Actions |\n|----------|-------------|---------|\n| **Critical** | 24 hours | Immediate remediation, notify management, consider if breach occurred |\n| **High** | 7 days | Remediation plan, compensating control if needed, risk acceptance by CISO |\n| **Medium** | 30 days | Add to sprint, track in compliance debt |\n| **Low** | 90 days | Batch with next review cycle |\n\n---\n\n## Phase 10 — Multi-Framework Management\n\n### Common Control Framework (CCF)\n\nBuild controls ONCE, map to MULTIPLE frameworks:\n\n```yaml\ncontrol:\n  id: \"CCF-AC-001\"\n  title: \"Multi-Factor Authentication\"\n  description: \"MFA required for all access to production systems and sensitive data\"\n  owner: \"Security Team\"\n  \n  framework_mapping:\n    soc2: [\"CC6.1\", \"CC6.6\"]\n    iso27001: [\"A.8.5\"]\n    gdpr: [\"Article 32\"]\n    hipaa: [\"§164.312(d)\"]\n    pci_dss: [\"Req 8.4\"]\n    \n  evidence:\n    - type: \"Configuration screenshot\"\n      source: \"Okta MFA policy\"\n      frequency: \"Quarterly\"\n    - type: \"Access review\"\n      source: \"Okta user report\"\n      frequency: \"Quarterly\"\n      \n  test_procedure: \"Verify MFA policy is enforced, test with non-MFA login attempt\"\n  last_tested: \"\"\n  result: \"\"\n  next_test: \"\"\n```\n\n### Framework Expansion Strategy\n\n**Year 1:** SOC 2 Type I → establishes baseline\n**Year 1-2:** SOC 2 Type II → proves sustained operation\n**Year 2:** + GDPR → covers EU expansion\n**Year 2-3:** + ISO 27001 → international credibility\n**As needed:** + HIPAA / PCI DSS → industry-specific\n\n### Audit Fatigue Prevention\n\n- **Single evidence repository** — collect once, map to all frameworks\n- **Continuous monitoring** — evidence auto-collected, not scrambled at audit time\n- **Control owner accountability** — each control has ONE owner, not \"security team\"\n- **Compliance sprints** — 2-week sprints dedicated to compliance work, not crammed before audit\n- **Auditor relationship** — same firm for multiple frameworks if possible (they know your environment)\n\n---\n\n## Phase 11 — Scoring & Quality\n\n### Compliance Readiness Score (0-100)\n\n| Dimension | Weight | Score 0-10 |\n|-----------|--------|-----------|\n| **Policy Coverage** — All required policies exist, reviewed, approved | 15% | |\n| **Technical Controls** — Security tools deployed and configured | 20% | |\n| **Process Maturity** — Operational processes followed consistently | 20% | |\n| **Evidence Quality** — Complete, organized, recent evidence | 15% | |\n| **Training & Awareness** — All employees trained, records maintained | 10% | |\n| **Vendor Management** — All critical vendors assessed and contracted | 10% | |\n| **Risk Management** — Current assessment, treatment plans, monitoring | 10% | |\n\n**Scoring guide:**\n- 0-2: Not started / major gaps\n- 3-4: In progress / significant gaps\n- 5-6: Partially implemented / some gaps\n- 7-8: Implemented / minor improvements needed\n- 9-10: Mature / audit-ready\n\n**Interpretation:**\n- **< 40:** Not ready — significant work needed (3-6 months)\n- **40-60:** Getting there — focus on gaps (1-3 months)\n- **60-80:** Nearly ready — polish and evidence gathering (2-6 weeks)\n- **80+:** Audit-ready — schedule the audit\n\n---\n\n## Edge Cases & Special Situations\n\n### Startup with Zero Compliance\n- Start with **security basics** (MFA, encryption, access control, backups) before any framework\n- Use a GRC platform from Day 1 (Vanta/Drata cost $10-15K/yr but save 100+ hours)\n- Don't wait for perfect — \"documented and improving\" beats \"undocumented and perfect\"\n- Budget $20-40K for first SOC 2 Type I (auditor + tools + time)\n\n### Multi-Cloud / Hybrid Infrastructure\n- Map shared responsibility model for each provider\n- Ensure consistent controls across environments\n- Consider cloud-specific compliance tools (AWS Audit Manager, Azure Compliance Manager)\n- Network segmentation especially important\n\n### Acquired Company Integration\n- Conduct compliance gap assessment within 30 days of close\n- Identify highest-risk gaps (access control, data handling)\n- 90-day integration plan to bring to baseline\n- Don't assume their compliance posture matches claims\n\n### International (Multi-Jurisdiction)\n- Map all jurisdictions where you operate or store data\n- GDPR applies if you have EU *users* — not just EU office\n- Data residency requirements (Russia, China, India, Brazil)\n- Consider local DPA registrations\n\n### Regulated Industries (FinTech, HealthTech)\n- Layer industry regulations ON TOP of SOC 2/ISO\n- FinTech: SOC 2 + PCI DSS + potentially banking regs (state MTLs, FinCEN)\n- HealthTech: SOC 2 + HIPAA + potentially FDA (SaMD)\n- EdTech: SOC 2 + FERPA + COPPA (if under 13)\n\n---\n\n## Natural Language Commands\n\n| Command | What It Does |\n|---------|-------------|\n| \"Assess our compliance readiness\" | Run readiness assessment, score, identify gaps |\n| \"Create SOC 2 project plan\" | Generate 16-week implementation timeline |\n| \"Write [policy name] policy\" | Generate policy from template with your context |\n| \"Map controls across frameworks\" | Build common control framework mapping |\n| \"Prepare for audit\" | Generate 90-day audit prep checklist with evidence needs |\n| \"Review our GDPR compliance\" | Check all 12 GDPR requirements against current state |\n| \"Score our compliance posture\" | Run 7-dimension scoring rubric |\n| \"Generate evidence checklist\" | List all evidence needed for specific framework |\n| \"Build vendor assessment\" | Create vendor risk assessment for a specific vendor |\n| \"Plan framework expansion\" | Recommend next framework based on business needs |\n| \"Track compliance debt\" | Review and prioritize open compliance items |\n| \"Run monthly compliance review\" | Update dashboard, check deadlines, identify actions |\n","readmeExcerpt":"Compliance & Audit Readiness Engine Your AI compliance officer. Guides startups and scale-ups through SOC 2, ISO 27001, GDPR, HIPAA, and PCI DSS — from zero to audit-ready. No consultants needed. --- Phase 1 — Compliance Discovery Framework Selection Matrix | Framework | Who Needs It | Trigger | Timeline | Cost Range | |-----------|-------------|---------|----------|------------| | **SOC 2 Type I** | Any B2B SaaS | E","codeSnippets":[],"executableExamples":[{"language":"yaml","snippet":"company_profile:\n  name: \"\"\n  industry: \"\"\n  employee_count: 0\n  annual_revenue: \"\"\n  data_types_handled:\n    - PII (names, emails, addresses)\n    - Financial (payment cards, bank accounts)\n    - Health (PHI, medical records)\n    - Children (COPPA scope)\n    - Biometric\n    - Government/classified\n  customer_segments:\n    - SMB\n    - Mid-market\n    - Enterprise\n    - Government\n  geographic_scope:\n    - US only\n    - US + EU\n    - Global\n  current_state:\n    existing_frameworks: []\n    security_team_size: 0\n    has_written_policies: false\n    has_asset_inventory: false\n    has_risk_assessment: false\n    has_incident_response: false\n    has_vendor_management: false\n    previous_audits: []\n    known_gaps: []\n  drivers:\n    - Customer requirement\n    - Board/investor mandate\n    - Regulatory obligation\n    - Competitive advantage\n    - Insurance requirement\n  target_frameworks: []\n  target_date: \"\"\n  budget_range: \"\""},{"language":"markdown","snippet":"# [Policy Name]\n\n**Version:** 1.0\n**Owner:** [Name, Title]\n**Approved by:** [Name, Title]\n**Effective date:** [Date]\n**Next review:** [Date + 1 year]\n**Classification:** Internal\n\n## 1. Purpose\n[Why this policy exists — 2-3 sentences]\n\n## 2. Scope\n[Who and what this policy applies to]\n\n## 3. Policy Statements\n[Numbered, actionable requirements — not aspirational]\n\n### 3.1 [Topic]\n- SHALL [requirement]\n- SHALL NOT [prohibition]\n- SHOULD [recommendation]\n\n## 4. Roles & Responsibilities\n| Role | Responsibility |\n|------|---------------|\n| [Role] | [What they must do] |\n\n## 5. Exceptions\n[Process for requesting exceptions — who approves, how long, documentation]\n\n## 6. Enforcement\n[Consequences of non-compliance]\n\n## 7. Definitions\n[Technical terms used in the policy]\n\n## 8. Related Documents\n[Links to related policies, standards, procedures]\n\n## 9. Revision History\n| Version | Date | Author | Changes |\n|---------|------|--------|---------|\n| 1.0 | [Date] | [Author] | Initial release |"},{"language":"yaml","snippet":"processing_activity:\n  name: \"\"\n  purpose: \"\"\n  lawful_basis: \"\"\n  data_categories: []\n  data_subjects: []\n  recipients: []\n  retention_period: \"\"\n  transfers_outside_eea: false\n  transfer_mechanism: \"\"\n  technical_measures: []\n  organizational_measures: []\n  dpia_required: false\n  last_reviewed: \"\""},{"language":"text","snippet":"# Infrastructure compliance\n- Terraform with Sentinel policies (enforce encryption, tagging)\n- OPA/Rego for Kubernetes admission control\n- AWS Config Rules / Azure Policy for cloud compliance\n- GitHub branch protection rules as change management evidence\n\n# Application compliance\n- Automated dependency scanning in CI (Snyk, Dependabot)\n- SAST in PR pipeline (Semgrep, CodeQL)\n- Container scanning (Trivy, Grype)\n- License compliance (FOSSA, Licensee)"},{"language":"text","snippet":"/compliance-evidence/\n  /SOC2-2026/\n    /CC1-control-environment/\n      org-chart.pdf\n      code-of-conduct-signed.pdf\n      background-check-process.pdf\n    /CC2-communication/\n      security-training-completion.csv\n      security-policy-acknowledgments.pdf\n    /CC3-risk-assessment/\n      risk-assessment-2026.xlsx\n      risk-treatment-plan.pdf\n    /CC6-access/\n      access-review-Q1.pdf\n      access-review-Q2.pdf\n      mfa-enforcement-screenshot.png\n      offboarding-checklist-samples/\n    /CC7-operations/\n      vulnerability-scan-reports/\n      pentest-report-2026.pdf\n      incident-log-2026.csv\n    /CC8-change-management/\n      sample-change-tickets/\n      deployment-pipeline-config.png\n    /CC9-vendors/\n      vendor-inventory.xlsx\n      vendor-assessments/\n      dpas-and-baas/"},{"language":"yaml","snippet":"compliance_dashboard:\n  month: \"\"\n  \n  control_health:\n    total_controls: 0\n    controls_passing: 0\n    controls_failing: 0\n    controls_not_tested: 0\n    health_percentage: 0\n    \n  action_items:\n    open: 0\n    overdue: 0\n    closed_this_month: 0\n    \n  key_metrics:\n    mean_time_to_patch_critical: \"\"\n    access_reviews_completed: \"X/X\"\n    security_training_completion: \"\"\n    incidents_this_month: 0\n    vendor_reviews_due: 0\n    policies_due_for_review: 0\n    \n  risk_register:\n    high_risks: 0\n    risks_without_treatment: 0\n    new_risks_identified: 0\n    \n  upcoming:\n    next_pen_test: \"\"\n    next_dr_test: \"\"\n    next_audit: \"\"\n    next_access_review: \"\""}],"parameters":{},"dependencies":[],"permissions":[],"extractedFiles":[],"languages":["typescript"],"docsSourceLabel":"CLAWHUB","editorialOverview":"Compliance & Audit Readiness Engine Compliance & Audit Readiness Engine Your AI compliance officer. Guides startups and scale-ups through SOC 2, ISO 27001, GDPR, HIPAA, and PCI DSS — from zero to audit-ready. No consultants needed. --- Phase 1 — Compliance Discovery Framework Selection Matrix | Framework | Who Needs It | Trigger | Timeline | Cost Range | |-----------|-------------|---------|----------|------------| | **SOC 2 Type I** | Any B2B SaaS | E","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":367,"uniquenessScore":68,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T01:43:19.562Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}