**Answer:** The compliance track is partially answered – we know the security review is required, an internal hardening framework exists, an open‑source policy is in place, dependency approval will be assessed during the review, and Fernway staff can work from Ireland – but we still need the approved‑package list, the architecture diagram (to resolve data‑storage, encryption and logging questions), and a defined turnaround time for dependency approvals. **What is already answered** - **Securi...
Scanned 9/19/2026
Install to Claude Code
npx -y skills add welltraum/minto --skill raw --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Raw?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/welltraum-raw-cd8c5e8d)More formats (shields.io, HTML) on the badges page.
**Answer:** The compliance track is partially answered – we know the security review is required, an internal hardening framework exists, an open‑source policy is in place, dependency approval will be assessed during the review, and Fernway staff can work from Ireland – but we still need the approved‑package list, the architecture diagram (to resolve data‑storage, encryption and logging questions), and a defined turnaround time for dependency approvals.
**What is already answered**
- **Security review** – required before production (Q1).
- **Hardening framework** – internal standard exists; review still required (Q2).
- **Open‑source policy** – policy exists; approved‑package list will be sent (Q3).
- **Critical dependency approval** – assessed during the security review (Q4).
- **Staff location** – work from Ireland is acceptable (Q6).
**What still needs to be obtained from Aldergate**
- **Approved‑package list** – promised (12 May, 9 July) but not yet received (R‑11).
- **Architecture diagram** – required to answer where customer data may be stored and the associated encryption/logging requirements (Q7, R‑14).
- **Turnaround time for dependency approval** – no standard defined; case‑by‑case (Q5).
**Immediate actions for today**
1. Follow up with S. Okafor (information security owner) to request the approved‑package list.
2. Send the draft architecture diagram to Aldergate (as agreed in the 9 July sync).
3. Clarify with Aldergate whether any expected SLA exists for dependency‑approval decisions.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!