Add compliance baseline for ip-legal plugin#58
Conversation
|
All contributors have signed the CLA ✍️ ✅ |
I have read the CLA Document and I hereby sign the CLA |
|
I have read the CLA Document and I hereby sign the CLA |
Introduce COMPLIANCE.md as a plugin-level shared guardrail covering: - Deployment environment classification (public cloud / private / air-gapped) - Five-tier information sensitivity framework with per-tier AI rules - Mandatory pre-input self-assessment checklist - Per-skill confidentiality quick-reference table - Bright-line prohibited input rules - Output management, labeling, and storage requirements - Audit logging and incident reporting standards - Privilege and work-product considerations This file provides a jurisdiction-agnostic compliance foundation that reinforces the design principle from CONTRIBUTING.md: "CLAUDE.md provides plugin-level safety net." Skills read COMPLIANCE.md alongside CLAUDE.md to determine the appropriate environment and tier for each invocation. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
5ef3545 to
4bfcc51
Compare
|
recheck |
|
recheck |
Summary
This PR adds
COMPLIANCE.mdto theip-legalplugin — a jurisdiction-agnostic compliance baseline that every skill reads before execution.What it covers
Design rationale
CONTRIBUTING.md states that
CLAUDE.mdprovides the "plugin-level safety net." This file complements CLAUDE.md by providing a dedicated compliance baseline focused on data handling and confidentiality — concerns that apply to every legal AI deployment regardless of jurisdiction.The file is jurisdiction-agnostic. It does not cite any specific country's laws, making it reusable across all claude-for-legal plugins.
Test plan
skills/directory