curtis-compliance

Open-source compliance checks for fintech code. Pre-commit hook, PR review, hash-chained audit trail. HIPAA / SOC2 / PCI-DSS citations — no telemetry, no SaaS.

At a glance

shipped
2026-07-20
version
v1.1.2
license
MIT
frameworks
HIPAA · SOC2 · PCI-DSS

Highlights

Catches violations before merge
Pre-commit hook + PR review for fintech patterns: PII in logs, unencrypted storage at rest, missing audit fields.
Hash-chained audit trail
Every check appends to a tamper-evident log. Court-defensible — built for regulated industries that get sued.
Citations, not magic
Every violation links to the specific HIPAA / SOC2 / PCI-DSS clause. Compliance officers can verify in seconds.
Local-only, no telemetry
Runs on your machine. No cloud calls, no third-party scans, no usage tracking. Source is auditable.

Stack

TypeScriptNode.jspre-commit frameworkGitHub Actions

Compliance checks that actually understand fintech code. Catches the patterns auditors flag — PII leaking into logs, plaintext secrets, missing audit trails — and cites the specific HIPAA / SOC2 / PCI-DSS clause each one violates.

Install

npm install -D @jordannewell/curtis-compliance

Pre-commit hook for local checks, GitHub Action for PR review. Hash-chained log for audit defense.

Why

Most compliance tooling is enterprise SaaS that scans your repo and ships the findings to someone else’s cloud. This is the opposite — local-first, open-source, no telemetry. Built so a small fintech can run the same checks a Big-Four auditor would, without the five-figure contract.