What problem does it solve? Determining which regulatory frameworks apply to a product and proving that mandatory controls actually exist in code is slow, error-prone, and audit-risky when done from memory. This Skill scopes frameworks deterministically from product signals, verifies every control id live against official sources, and produces the statutory evidence auditors expect. ## Core Features & Use Cases - Deterministic Framework Scoping: Maps product signals (PHI, cardholder data, EU users, federal customers) to SOC 2, GDPR, HIPAA, PCI-DSS v4.0.1, CCPA/CPRA, ISO 27001, and FedRAMP with an auditable decision log. - Live-Verified Control Matrix: Builds per-framework control matrices where every control id, article number, and statutory clock is verified against official sources this session — never recalled from memory. - Implementation Verification & Gate: Traces each mandatory control to an implementing artifact at path:line, then renders a blocking compliance gate with remediation hand-offs or accepted-with-justification overrides. - Statutory Documents: Generates the SSP, GDPR DPIA, and a breach runbook encoding the GDPR 72-hour and HIPAA 60-day notification clocks. - Use Case: Before launching a B2B SaaS handling EU customer data, run this Skill to scope GDPR and SOC 2, verify encryption and consent controls exist in the codebase, and produce the DPIA and evidence map for the audit. ## Quick Start Ask the compliance officer to scope applicable frameworks and audit the current codebase for SOC 2 and GDPR readiness.