Guides startups and scale-ups through SOC 2, ISO 27001, GDPR, HIPAA, and PCI DSS compliance to achieve audit readiness without external consultants.
数据来源:ClawHub。 在 ClawSkills 查看
选择你使用的 Agent
方法一:命令行安装(推荐)
推荐(无需提前安装 clawhub)
npx clawhub@latest --dir ~/.claude/skills install afrexai-compliance-engine或使用 clawhub CLI(需提前安装)
clawhub --dir ~/.claude/skills install afrexai-compliance-engine⚠️ 需要 Node.js 18+,没有 Node?请使用下方方法二直接下载 ZIP。 安装 Node.js →
方法二:手动下载安装(无需 Node)
下载 ZIP,解压后将文件夹放到以下路径,重启 Agent 即可:
安装路径
~/.claude/skills/afrexai-compliance-engine/💡解压后将文件夹放到上方路径,重启 Agent 即可生效
Your AI compliance officer. Guides startups and scale-ups through SOC 2, ISO 27001, GDPR, HIPAA, and PCI DSS — from zero to audit-ready. No consultants needed.
---
| Framework | Who Needs It | Trigger | Timeline | Cost Range | |-----------|-------------|---------|----------|------------| | SOC 2 Type I | Any B2B SaaS | Enterprise prospect asks | 3-6 months | $20K-$80K | | SOC 2 Type II | Established SaaS | After Type I, or direct | 6-12 months | $30K-$100K | | ISO 27001 | Global/EU-facing SaaS | EU enterprise deals | 6-12 months | $40K-$120K | | GDPR | Anyone with EU users | Day 1 if EU data | 1-3 months | $5K-$30K | | HIPAA | Health data handlers | Before first PHI | 3-6 months | $20K-$60K | | PCI DSS | Payment processors | Before card data | 3-9 months | $15K-$50K | | SOX | Public companies | IPO prep | 12-18 months | $100K-$500K |
company_profile:
name: ""
industry: ""
employee_count: 0
annual_revenue: ""
data_types_handled:
- PII (names, emails, addresses)
- Financial (payment cards, bank accounts)
- Health (PHI, medical records)
- Children (COPPA scope)
- Biometric
- Government/classified
customer_segments:
- SMB
- Mid-market
- Enterprise
- Government
geographic_scope:
- US only
- US + EU
- Global
current_state:
existing_frameworks: []
security_team_size: 0
has_written_policies: false
has_asset_inventory: false
has_risk_assessment: false
has_incident_response: false
has_vendor_management: false
previous_audits: []
known_gaps: []
drivers:
- Customer requirement
- Board/investor mandate
- Regulatory obligation
- Competitive advantage
- Insurance requirement
target_frameworks: []
target_date: ""
budget_range: ""
---
SOC 2 is built on 5 categories. Security is mandatory. Others are optional but often expected.
Availability (A1):
Confidentiality (C1):
Processing Integrity (PI1):
Privacy (P1):
| Week | Phase | Key Activities | |------|-------|---------------| | 1-2 | Scoping | Define system boundaries, select TSC, choose auditor | | 3-4 | Gap Assessment | Audit current state against TSC, document gaps | | 5-6 | Policy Writing | Draft all required policies (see policy list below) | | 7-8 | Control Implementation | Deploy technical controls, configure tools | | 9-10 | Process Implementation | Establish operational processes, train team | | 11-12 | Evidence Collection | Gather evidence for all controls, test internally | | 13-14 | Readiness Assessment | Mock audit, remediate findings | | 15-16 | Type I Audit | Auditor fieldwork, management response, report |
...
安装 Compliance & Audit Readiness Engine 后,可以对 AI 说这些话来触发它
Help me get started with Compliance & Audit Readiness Engine
Explains what Compliance & Audit Readiness Engine does, walks through the setup, and runs a quick demo based on your current project
Use Compliance & Audit Readiness Engine to guides startups and scale-ups through SOC 2, ISO 27001, GDPR, HIPAA...
Invokes Compliance & Audit Readiness Engine with the right parameters and returns the result directly in the conversation
What can I do with Compliance & Audit Readiness Engine in my marketing & growth workflow?
Lists the top use cases for Compliance & Audit Readiness Engine, with example commands for each scenario
将技能文件夹放到 ~/.claude/skills/afrexai-compliance-engine/ 目录(个人级,所有项目可用),或 .claude/skills/afrexai-compliance-engine/(项目级)。重启 AI 客户端后,用 /afrexai-compliance-engine 主动调用,或让 AI 根据上下文自动发现并使用。
Compliance & Audit Readiness Engine 支持 Claude、Cursor、OpenClaw,可与这些 AI 平台无缝集成,扩展其能力。
Compliance & Audit Readiness Engine 可免费安装使用。请查阅仓库了解许可证信息。
Guides startups and scale-ups through SOC 2, ISO 27001, GDPR, HIPAA, and PCI DSS compliance to achieve audit readiness without external consultants.
Automate my marketing & growth tasks using Compliance & Audit Readiness Engine
Identifies repetitive steps in your workflow and sets up Compliance & Audit Readiness Engine to handle them automatically
Compliance & Audit Readiness Engine 属于「Marketing & Growth」分类,该分类的技能帮助 AI 智能体在此领域执行专业任务。