compliance

Map regulatory requirements to technical controls and automate evidence collection.

3|Updated May 28, 2026
One-click install
npx skills add https://github.com/mahg-es/araya --skill compliance-mahg-es
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: compliance
Source: https://github.com/mahg-es/araya/tree/main/skills/compliance
Command: npx skills add https://github.com/mahg-es/araya --skill compliance-mahg-es

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Compliance is treated as a checkbox exercise, leading to last-minute scrambles, audit failures, and regulatory fines. This skill embeds compliance into the development lifecycle — mapping regulations to technical controls, automating evidence collection, and maintaining continuous compliance.

Core Features & Use Cases

  • Mapping frameworks to controls: Documented controls mapped to GDPR, SOC 2, ISO 27001, HIPAA; automated evidence collection.
  • Audit readiness & continuous compliance: CI pipeline artifacts, evidence inventory.
  • Use Case: Imagine a product expanding into GDPR-regulated markets; you need continuous evidence for audits and regulatory reporting to demonstrate control coverage.

Quick Start

Configure initial compliance framework mapping for GDPR and enable automatic evidence collection in the CI/CD pipeline.

Frequently Asked Questions about compliance

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate evidence collection for GDPR and ISO 27001 in a CI/CD pipeline?▼

Automate evidence collection by mapping GDPR and ISO 27001 requirements to technical controls in your CI/CD pipeline, generating audit-ready artifacts for continuous compliance. This embeds regulatory evidence gathering directly into your SDLC.

What is continuous compliance and how does it apply to SDLC governance?▼

Continuous compliance integrates regulatory governance into the SDLC by mapping frameworks like HIPAA and SOC 2 to technical controls. It shifts compliance from a checkbox exercise to automated, ongoing evidence collection within development workflows.

Can I map HIPAA and SOC 2 requirements to technical controls for audit readiness?▼

Yes, you can map HIPAA and SOC 2 requirements to explicit technical controls and documentation. This generates an evidence inventory and CI pipeline artifacts, ensuring audit readiness and continuous regulatory compliance.

How do I prepare for GDPR audits when expanding into regulated markets?▼

Prepare for GDPR audits by configuring initial compliance framework mapping and enabling automatic evidence collection in your CI/CD pipeline. This maintains continuous control coverage and generates audit-ready artifacts for regulatory reporting.

What's the best way to maintain audit-ready artifacts for SOC 2 in CI/CD pipelines?▼

Maintain audit-ready artifacts by embedding SOC 2 control documentation and automated evidence collection directly into CI/CD pipelines. This ensures continuous compliance and provides an evidence inventory for governance and audits.

Does continuous regulatory compliance require explicit control implementation in the SDLC?▼

Yes, continuous regulatory compliance requires explicit control implementation and documentation in the SDLC. Mapping GDPR, ISO 27001, and HIPAA frameworks to technical controls ensures automated evidence collection and audit-ready pipeline artifacts.