curtis-compliance
Open-source compliance checks for fintech code. Pre-commit hook, PR review, hash-chained audit trail. HIPAA / SOC2 / PCI-DSS citations — no telemetry, no SaaS.
At a glance
Highlights
Stack
Compliance checks that actually understand fintech code. Catches the patterns auditors flag — PII leaking into logs, plaintext secrets, missing audit trails — and cites the specific HIPAA / SOC2 / PCI-DSS clause each one violates.
Install
npm install -D @jordannewell/curtis-compliance
Pre-commit hook for local checks, GitHub Action for PR review. Hash-chained log for audit defense.
Why
Most compliance tooling is enterprise SaaS that scans your repo and ships the findings to someone else’s cloud. This is the opposite — local-first, open-source, no telemetry. Built so a small fintech can run the same checks a Big-Four auditor would, without the five-figure contract.
