You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This page is a concern-driven index: it connects high-level questions (what a CISO, DPO, or security architect cares about) to the concrete guides where behaviour, config keys, and limits are defined. Child and minor data is listed first on purpose: the product treats that linguistic category as a dedicated lane (detector, report elevation, samples—not a generic PII footnote). Use this map when you already know the topic (e.g. minors, cross-border hints) and want the shortest path without browsing every folder. The full flat index remains README.md (pt-BR).
POC documentation spine (v1.7.x)
For a proof-of-concept or partner dry-run, read in this order so dense docs do not hide posture-critical material:
TECH_GUIDE.md (pt-BR) — install, first scan, ports, connectors overview.
This MAP — scan the tables below (minors → jurisdiction → detection bridges → governance of the auditor). For multinational tension narrative (not legal advice), read JURISDICTION_COLLISION_HANDLING.md (pt-BR) after the jurisdiction rows.
Governance of the auditor (evidence today vs gaps):ADR 0037 (English).
Jurisdiction hints (not legal conclusions):ADR 0026 (English) plus the jurisdiction row in the table below.
Execution plans and PMO tables live under plain-text path docs/plans/ in your checkout; this map does not link there from product-tier Markdown (ADR 0004). Use docs/README.md — Internal and reference (pt-BR) as the deliberate entry (PLANS_TODO, PLANS_HUB, completed plans).
Design history for minor detection lives in a completed plan file under docs/plans/completed/ in your checkout (PLAN_MINOR_DATA_DETECTION); the operator guide above is the maintained entry point (no plan link here per information-architecture rules).
Jurisdiction hints (heuristic, metadata-only)
Question
Read first
Config / behaviour
Related
What are jurisdiction hints, who are they for, and how do I enable them (CLI, API, dashboard, YAML)?
USAGE.md — search jurisdiction_hints / Report info (pt-BR)
report.jurisdiction_hints, --jurisdiction-hint, POST /scan body
Canonical runbook; pii-fresh-audit for Windows fresh-clone proof.
Reports, exports, and GRC-shaped outputs
Question
Read first
How do SQLite findings become Excel, heatmap, executive Markdown (POC_SUMMARY_*.md), evidence YAML (scan_manifest_*.yaml), audit JSON, and maturity CSV/MD? How do I regenerate the desk summary from SQLite (data-boar-report)? What is planned vs shipped for a scan-linked PDF? Where is the GRC risk-matrix JSON contract?
If a topic is missing from this map, add a row in bothMAP.md and MAP.pt_BR.md in the same PR.
Keeping hubs aligned with repo truth
Plans sequencing and file inventory are enforced by plans_hub_sync.py and plans-stats.py (see CONTRIBUTING.md and pre-commit). This MAP is curated: after you add or change hub rows, run .\scripts\check-all.ps1 or .\scripts\lint-only.ps1 when the diff is docs-only, and follow the doc-hubs-plans-sync Cursor skill (.cursor/skills/doc-hubs-plans-sync/SKILL.md) so ADR index, AGENTS last-ADR pointer, and paired pt-BR stay in sync.