WIG — Compliance documents for review

Privacy-compliance docs (Technical Privacy Requirements). The first three tabs are process docs for review; “All docs” is the full catalog.

Card context · WIG-1298 — In Review

📋 What it requires
§2/§7: maintain an incident response plan that defines who is notified internally, the escalation path, how affected users are identified, and the timeline for external notification.
📄 This document
Covers the 4 required items (internal notification · escalation · affected-user identification · timeline).
⏳ Still missing
Review/approval, assign who fills each role (Incident Commander · Technical Responder · Legal/Comms), and formally adopt it. Process doc — no code.

🟠 Decisions we need from you

  • Confirm who fills each role: Incident Commander, Technical Responder, Legal/Comms.
  • Do the escalation path and timelines reflect how we actually operate today?
  • Any additional legal/contractual requirement to cover in notification?

Card context · WIG-1307 — Blocked

📋 What it requires
§7: implement real-time alerting for anomalous data-access patterns (bulk downloads, unexpected API calls, access from unusual IP ranges).
📄 This document
A design spec: defines the signals, the already-available data sources, and 2 implementation approaches.
⏳ Still missing
The implementation: choose an approach (SigNoz/New Relic alert rules vs cron) + thresholds, build the alerting for the 3 classes (volume · privileged · geo/IP), route to privacy@, and verify. The cron option depends on WIG-1324.

🟠 Decisions we need from you

  • Choose an approach: alert rules on SigNoz/New Relic (recommended, no new infra) vs a dedicated cron.
  • Do you approve building it, and at what priority? (the cron option depends on finishing WIG-1324)
  • Do you confirm initial thresholds or delegate them to the team to tune against real traffic?

Card context · WIG-1296 — Blocked

📋 What it requires
§2: conduct regular access reviews (at minimum quarterly) to ensure no unauthorized access to production systems / user data exists.
📄 This document
The quarterly review process: systems in scope, per-quarter steps, an evidence log, and off-cycle triggers (departures / role changes).
⏳ Still missing
Assign an owner, run the first quarter and record evidence, and document the grant/revoke process. Ops/governance — no code.

🟠 Decisions we need from you

  • Who is the review owner (accountable for running it each quarter)?
  • Is the systems-in-scope list complete (Railway, AWS, Cloudflare, DB, GitHub, vendors, email)?

Every compliance doc we created, grouped by how much review it needs. Each is collapsed — click to expand context + the full document.