**Compliance digest — bottom line:** security requirements remain unconfirmed (open since 3 May), so build-phase pricing cannot be fixed. Aldergate has confirmed the review mechanics, but three substantive items still need its input — the approved-package list, the architecture-dependent data-storage answer, and Lisbon staffing confirmation — plus a process gap: no direct access yet to the information-security owner. - **Security review:** mandatory before production; whether a penetration te...
Scanned 9/19/2026
Install to Claude Code
npx -y skills add welltraum/minto --skill raw --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Raw?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/welltraum-raw-70cb8a48)More formats (shields.io, HTML) on the badges page.
**Compliance digest — bottom line:** security requirements remain unconfirmed (open since 3 May), so build-phase pricing cannot be fixed. Aldergate has confirmed the review mechanics, but three substantive items still need its input — the approved-package list, the architecture-dependent data-storage answer, and Lisbon staffing confirmation — plus a process gap: no direct access yet to the information-security owner.
### Already answered (by compliance topic)
- **Security review:** mandatory before production; whether a penetration test is also needed is decided during the review by the assigned reviewer.
- **Hardening standard:** an internal framework exists, but a review is still required regardless of conformance.
- **Open-source dependencies:** a policy exists; critical dependencies are assessed during the security review; there is no standard turnaround — case by case.
- **Working location:** work from Ireland is acceptable.
- **Customer data:** storage, encryption and logging requirements exist, but Aldergate declined to answer without an architecture diagram and design walkthrough.
### Still to obtain from Aldergate (substantive items first, then process gap)
1. **Approved-package list** — promised by D. Mercer on 12 May, repeated by R. Whitcombe on 9 July; open 98 days.
2. **Data-storage/encryption/logging answer** — requires our draft architecture diagram (draft exists since 11 Aug) and a design walkthrough; Fernway agreed to send the draft before the next sync.
3. **Lisbon staffing confirmation** — two Fernway engineers are based in Lisbon; only Ireland was confirmed, and the 9 July remark received no response.
4. **Process gap: direct access to S. Okafor** — named as information-security owner but not yet in joint meetings; Whitcombe is currently passing questions along.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!