compliancelisted
Install: claude install-skill radozaprazny/attest
# /compliance — declared compliance posture (COMPLIANCE.md)
This skill maintains **`COMPLIANCE.md`** — the record of **under what rules** the project must
operate: which regimes apply, the self-assessed classification, the obligations that follow,
and how personal data is handled. **EU-first.** It records the project's *posture*, not the
law — it cites provisions by article/ID and **never reproduces regulation text or issues a
legal verdict**.
The skill is **generic** — work with what you actually find in the repo, and assume nothing
about the specific project.
## The control documents — keep them separate
**Anti-duplication:** status → `PROGRESS.md` · rules → `CLAUDE.md` · why-it-exists →
`BUSINESS.md` · why-we-chose-X-over-Y → `DECISIONS.md` · under-what-rules → `COMPLIANCE.md`.
Write each fact in exactly one place. (full table: GUIDE PART 1)
> The three "why" docs collide here — fence them. A specific technical **choice and its
> rationale** is a `DECISIONS.md` entry; `COMPLIANCE.md` records only the **standing
> obligation** that binds it, cross-referenced by ADR id. A product **boundary** is a
> `BUSINESS.md` non-goal, not an obligation.
## Two axes, EU-first
The AI Act and the GDPR are **independent axes** — fill each only if its own trigger fires:
- **EU AI Act** — trigger: is it an **AI system** (Art 3(1)) or a **GPAI model**? The
archetype in `BUSINESS.md` is only a *hint* that it *may* apply — a `service` or
`data-pipeline` embedding a model is in scope