compliance

Map regulatory requirements to technical controls and automate evidence collection.

3|Updated May 28, 2026
One-click install
npx skills add https://github.com/mahg-es/araya --skill compliance-mahg-es
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: compliance
Source: https://github.com/mahg-es/araya/tree/main/skills/compliance
Command: npx skills add https://github.com/mahg-es/araya --skill compliance-mahg-es

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Compliance is treated as a checkbox exercise, leading to last-minute scrambles, audit failures, and regulatory fines. This skill embeds compliance into the development lifecycle — mapping regulations to technical controls, automating evidence collection, and maintaining continuous compliance.

Core Features & Use Cases

  • Mapping frameworks to controls: Documented controls mapped to GDPR, SOC 2, ISO 27001, HIPAA; automated evidence collection.
  • Audit readiness & continuous compliance: CI pipeline artifacts, evidence inventory.
  • Use Case: Imagine a product expanding into GDPR-regulated markets; you need continuous evidence for audits and regulatory reporting to demonstrate control coverage.

Quick Start

Configure initial compliance framework mapping for GDPR and enable automatic evidence collection in the CI/CD pipeline.

Frequently Asked Questions about compliance

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate evidence collection for GDPR and ISO 27001 in a CI/CD pipeline?

Automate evidence collection by mapping GDPR and ISO 27001 requirements to technical controls in your CI/CD pipeline, generating audit-ready artifacts for continuous compliance. This embeds regulatory evidence gathering directly into your SDLC.

What is continuous compliance and how does it apply to SDLC governance?

Continuous compliance integrates regulatory governance into the SDLC by mapping frameworks like HIPAA and SOC 2 to technical controls. It shifts compliance from a checkbox exercise to automated, ongoing evidence collection within development workflows.

Can I map HIPAA and SOC 2 requirements to technical controls for audit readiness?

Yes, you can map HIPAA and SOC 2 requirements to explicit technical controls and documentation. This generates an evidence inventory and CI pipeline artifacts, ensuring audit readiness and continuous regulatory compliance.

How do I prepare for GDPR audits when expanding into regulated markets?

Prepare for GDPR audits by configuring initial compliance framework mapping and enabling automatic evidence collection in your CI/CD pipeline. This maintains continuous control coverage and generates audit-ready artifacts for regulatory reporting.

What's the best way to maintain audit-ready artifacts for SOC 2 in CI/CD pipelines?

Maintain audit-ready artifacts by embedding SOC 2 control documentation and automated evidence collection directly into CI/CD pipelines. This ensures continuous compliance and provides an evidence inventory for governance and audits.

Does continuous regulatory compliance require explicit control implementation in the SDLC?

Yes, continuous regulatory compliance requires explicit control implementation and documentation in the SDLC. Mapping GDPR, ISO 27001, and HIPAA frameworks to technical controls ensures automated evidence collection and audit-ready pipeline artifacts.