Skip to content

Payment Security Self-Assessment Narrative - #210

Open
Hemil-Fichadia wants to merge 4 commits into
superdocsapp:mainfrom
Hemil-Fichadia:payment-security-self-assessment
Open

Payment Security Self-Assessment Narrative#210
Hemil-Fichadia wants to merge 4 commits into
superdocsapp:mainfrom
Hemil-Fichadia:payment-security-self-assessment

Conversation

@Hemil-Fichadia

@Hemil-Fichadia Hemil-Fichadia commented Aug 27, 2026

Copy link
Copy Markdown

Builder

Hemil Fichadia
GitHub: @Hemil-Fichadia

Project

Payment Security Self-Assessment

A fintech/commerce self-assessment drafting workflow that ingests plain-text security evidence, deterministically separates implemented, planned, and unknown controls, and uses SuperDocs to produce a grounded review-and-approval document flow.

The build prevents planned controls from being represented as currently implemented and preserves unsupported claims as evidence limitations.

Current capabilities

  • .txt evidence ingestion (up to 3 files; 100 KB per file)
  • Deterministic IMPLEMENTED, PLANNED, and UNKNOWN classification
  • Evidence provenance with source file and line reference
  • Prompt-like uploaded content treated as untrusted data
  • Pre-generation evidence review
  • Real server-side SuperDocs document upload
  • Async SuperDocs generation with approval_mode: "ask_every_time"
  • Polling and human review of proposed changes
  • Explicit SuperDocs approval
  • Completed assessment display and real DOCX export
  • Grounding validation and offline regression tests

Limitations

  • Classification is deterministic and phrase based; vague prose may produce no classified fact
  • .txt evidence only; PDF/DOCX ingestion is not implemented
  • No application persistence or authentication
  • No dedicated SuperDocs search integration
  • This drafts a self-assessment; it is not a PCI DSS certification, compliance guarantee, or audit

Run

See the project README:

use-cases/Hemil-Fichadia/payment-security-self-assessment/README.md

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant