Skip to content

Latest commit

 

History

History
123 lines (81 loc) · 11.8 KB

File metadata and controls

123 lines (81 loc) · 11.8 KB

Documentation topic map (navigation by concern)

Português (Brasil): MAP.pt_BR.md

This page is a concern-driven index: it connects high-level questions (what a CISO, DPO, or security architect cares about) to the concrete guides where behaviour, config keys, and limits are defined. Child and minor data is listed first on purpose: the product treats that linguistic category as a dedicated lane (detector, report elevation, samples—not a generic PII footnote). Use this map when you already know the topic (e.g. minors, cross-border hints) and want the shortest path without browsing every folder. The full flat index remains README.md (pt-BR).


POC documentation spine (v1.7.x)

For a proof-of-concept or partner dry-run, read in this order so dense docs do not hide posture-critical material:

  1. TECH_GUIDE.md (pt-BR) — install, first scan, ports, connectors overview.
  2. This MAP — scan the tables below (minors → jurisdiction → detection bridges → governance of the auditor). For multinational tension narrative (not legal advice), read JURISDICTION_COLLISION_HANDLING.md (pt-BR) after the jurisdiction rows.
  3. USAGE.md (pt-BR) — detection keys, report.jurisdiction_hints, CLI/API/dashboard flags.
  4. Governance of the auditor (evidence today vs gaps): ADR 0037 (English).
  5. Jurisdiction hints (not legal conclusions): ADR 0026 (English) plus the jurisdiction row in the table below.

Execution plans and PMO tables live under plain-text path docs/plans/ in your checkout; this map does not link there from product-tier Markdown (ADR 0004). Use docs/README.md — Internal and reference (pt-BR) as the deliberate entry (PLANS_TODO, PLANS_HUB, completed plans).


ADR hooks (POC-relevant, English bodies)

ADR Why it matters in a POC
0000 Baseline: ADRs complement code and plans; where to look first.
0004 Why pitch docs link here and to docs/README, not straight into docs/plans/.
0026 Jurisdiction hints: metadata-only, DPO-facing; limits of legal claims.
0035 README stakeholder tone vs optional deck vocabulary elsewhere.
0036 Exception/log redaction; safer operator evidence in logs and DB text.
0037 Self-audit: what is provable today (sessions, export trail, wipes) vs explicit gaps.

Full index: adr/README.md (pt-BR).


Minor data and child-related privacy (technical scope)

Question Read first Config / behaviour Related
How does the product flag possible minor data (DOB, age columns), thresholds, optional full scan, and cross-reference? MINOR_DETECTION.md (pt-BR) detection.minor_age_threshold, detection.minor_full_scan, detection.minor_cross_reference SENSITIVITY_DETECTION.md (pt-BR), USAGE.md detection / report sections (pt-BR)
Brazil FELCA (digital child/adolescent statute) and how the product positions metadata-only support? COMPLIANCE_FRAMEWORKS.md — Auditable and management standards (pt-BR) Same: minor flags are inventory-oriented, not age verification COMPLIANCE_AND_LEGAL.md (pt-BR)
U.S. COPPA / CA AB 2273 / CO CPA minors — technical YAML samples (norm tags, not legal advice)? COMPLIANCE_FRAMEWORKS.md — compliance samples table and disclaimers (pt-BR) Files under compliance-samples/ (e.g. compliance-sample-us_ftc_coppa.yaml) compliance-samples/README.md (pt-BR)

Design history for minor detection lives in a completed plan file under docs/plans/completed/ in your checkout (PLAN_MINOR_DATA_DETECTION); the operator guide above is the maintained entry point (no plan link here per information-architecture rules).


Jurisdiction hints (heuristic, metadata-only)

Question Read first Config / behaviour Related
What are jurisdiction hints, who are they for, and how do I enable them (CLI, API, dashboard, YAML)? USAGE.md — search jurisdiction_hints / Report info (pt-BR) report.jurisdiction_hints, --jurisdiction-hint, POST /scan body COMPLIANCE_AND_LEGAL.md (pt-BR)
Why hints are not legal conclusions and what ADR locked in? ADR 0026 (English) Index: adr/README.md (pt-BR) COMPLIANCE_TECHNICAL_REFERENCE.md (pt-BR)
Multinational “perfect storm” — overlapping regimes, anchor vs drift, port-style storyboard? JURISDICTION_COLLISION_HANDLING.md (pt-BR) Same opt-in hints; no numeric collision score in product yet ADR 0038, use-cases/README.md (pt-BR) — incl. port logistics storyboard

Sensitive detection and compliance depth (bridge topics)

Question Read first Notes
Regex, ML/DL, overrides, connector format hints SENSITIVITY_DETECTION.md (pt-BR) Pairs with USAGE.md report and detection keys (pt-BR)
Norm tags, samples, multi-region operation COMPLIANCE_FRAMEWORKS.md (pt-BR) Includes Brazil insurance LGPD anchor subsection and sample table
Encodings, API limits, evidence posture (IT / DPO) COMPLIANCE_TECHNICAL_REFERENCE.md (pt-BR) Operational limits, not legal advice

Governance of the auditor (who watches the watcher?)

Question Read first Notes
What evidence exists today for scan attribution, wipes, export bundles, and log redaction? What is not implemented yet? ADR 0037 (English) Honest baseline for CISO / SOC2-style narratives; avoids over-claiming per-report or per-config immutable audit rows.
SRE alignment (health, logs, future metrics) OBSERVABILITY_SRE.md (pt-BR) Links this ADR for governance-of-the-auditor framing.

Public tree PII hygiene (operator ritual)

Question Read first Notes
On-demand pass: private seeds, HEAD scan order, leak prevention defaults PII_REMEDIATION_RITUAL.md (pt-BR) Session keyword pii-remediation-ritual; complements—not replaces—the cadence below.
Short / mid / long cadence, SAFE checklist, history rewrite cautions PII_PUBLIC_TREE_OPERATOR_GUIDE.md (pt-BR) Canonical runbook; pii-fresh-audit for Windows fresh-clone proof.

Reports, exports, and GRC-shaped outputs

Question Read first
How do SQLite findings become Excel, heatmap, executive Markdown (POC_SUMMARY_*.md), evidence YAML (scan_manifest_*.yaml), audit JSON, and maturity CSV/MD? How do I regenerate the desk summary from SQLite (data-boar-report)? What is planned vs shipped for a scan-linked PDF? Where is the GRC risk-matrix JSON contract? REPORTS_AND_COMPLIANCE_OUTPUTS.md (pt-BR) · USAGE.md section 5 (pt-BR) · GRC_EXECUTIVE_REPORT_SCHEMA.md (pt-BR)

Cursor agent cold start (token-aware)

Question Read first Notes
New chat, low context, or operator typed short / token-aware — where do I start without re-reading all of AGENTS.md? OPERATOR_AGENT_COLD_START_LADDER.md (pt-BR) One-screen ordered ladder, task router, seven non-negotiables (homelab ssh = §7); then CURSOR_AGENT_POLICY_HUB / TOKEN_AWARE_SCRIPTS_HUB as needed.

Engineering doctrine (repository discipline)

Question Read first Notes
What are the four default engineering principles (fail-closed, pin+cooldown, verified integrity, metadata-first) and where are they implemented? ENGINEERING_PRACTICES.md (pt-BR) Canonical in-repo doctrine; cites SECURITY.md, .github/dependabot.yml, RELEASE_INTEGRITY.md, GLOSSARY.md — no private tooling.
Security posture map (PII gates, supply chain, local gate ritual) SECURITY_GOVERNANCE_POSTURE_HUB.md (pt-BR) Complements the principles page with themed entry points.

Where this fits

If a topic is missing from this map, add a row in both MAP.md and MAP.pt_BR.md in the same PR.

Keeping hubs aligned with repo truth

Plans sequencing and file inventory are enforced by plans_hub_sync.py and plans-stats.py (see CONTRIBUTING.md and pre-commit). This MAP is curated: after you add or change hub rows, run .\scripts\check-all.ps1 or .\scripts\lint-only.ps1 when the diff is docs-only, and follow the doc-hubs-plans-sync Cursor skill (.cursor/skills/doc-hubs-plans-sync/SKILL.md) so ADR index, AGENTS last-ADR pointer, and paired pt-BR stay in sync.