Privacy

Local-first. Technically ready. Not a legal certificate.

VibeDoctor inspects source on the developer machine. A full scan already includes privacy signals. Dedicated review and DPDP commands are extras, not a substitute for running the product. It cannot certify legal compliance.

npx @neuralaxis/vibedoctor scan --full

Local-first

What runs where.

On the machine

  • Core scanning and report generation.
  • Built-in privacy-detector. No external service required.
  • HTML, JSON, Markdown, SARIF, and agent reports written under .vibedoctor/.
  • Evidence stored in reports is masked or classified instead of preserving raw PII.

Optional network

  • setup may download scanner tools.
  • Dependency scanners (for example OSV-Scanner) may query their own data sources.
  • Optional AI adjudication for Privacy Review runs only when explicitly enabled and the configured API-key environment variables are present.
  • There is no hosted VibeDoctor service required to produce a diagnosis.

Privacy Review

Deterministic first. Advisory by default.

npx @neuralaxis/vibedoctor privacy-review --refresh --format markdown

Category scan: vibedoctor scan --category privacy --report json. The review command writes .vibedoctor/privacy-review.json.

Privacy findings affect the privacy category score by default, but do not lower the overall score or fail CI unless you opt into privacy gates.

checks:
  privacy:
    fail_on_regulated_identifiers: true
    fail_on_sensitive_attributes: true

DPDP technical readiness

Engineering evidence. Not certification.

The DPDP module maps apparent personal-data processing, evaluates visible technical controls, identifies deterministic technical risks, and creates a human-review queue.

It provides technical readiness evidence, not legal compliance or certification. Static analysis cannot establish legal applicability, production behavior, contractual adequacy, notice quality, or organisational policy implementation.

Start with the full DPDP scan. The rest of the table is for after you have a report.

npx @neuralaxis/vibedoctor dpdp scan --full
CommandPurpose
dpdp initScaffold optional context and evidence.
dpdp scan --fullFull technical-readiness scan.
dpdp scan --changedEvidence from changed files.
dpdp mapPrint the personal-data map.
dpdp review-queueQuestions requiring human review.
dpdp reportJSON, HTML, or Markdown.
dpdp handoffAgent handoff.
dpdp verifyLive changed-scope verification.
dpdp explain <id>Explain a control or finding.

Controls distinguish DETERMINISTIC checks, TECHNICAL_SIGNAL, DECLARED_EVIDENCE, and HUMAN_REVIEW. Absence of evidence is never marked VERIFIED. Skipped optional scanners are never passes.