# blade47/comp > AI-generated documentation for github.com/blade47/comp ## Technical docs: Overview - [Project Overview](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/technical/section-1/project-overview): Comp AI is an open-source compliance platform designed to automate compliance processes for various regulatory frameworks. It aims to simplify evidence collection, policy management, and control im... - [Getting Started](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/technical/section-1/getting-started): This page provides a comprehensive guide to setting up and running the Comp AI platform locally for development. Comp AI is an open-source compliance platform designed to automate evidence collecti... - [Configuration](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/technical/section-1/configuration): This page details the configuration management within the project, focusing on how environment variables are loaded and how application-specific settings for services like AWS and "Better Auth" are... - [Troubleshooting](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/technical/section-1/troubleshooting): Troubleshooting in the Comp AI platform involves diagnosing and resolving issues across various layers, from local development environment setup to API request handling. This guide provides insight... ## Technical docs: System Architecture - [API Architecture](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/technical/section-2/api-architecture): The API architecture is built upon the NestJS framework, providing a structured and modular approach to developing server-side applications. It serves as the central backend for various functionali... - [Module Map](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/technical/section-2/module-map): This document provides an overview of the module structure within the apps/api directory, focusing on how different feature modules are organized and integrated into the main application. It detail... - [Extensions Layer](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/technical/section-2/extensions-layer): The Extensions Layer refers to a set of custom build extensions designed to integrate specific project dependencies and workspace packages into the @trigger.dev/build process. These extensions cust... - [Build Pipeline](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/technical/section-2/build-pipeline): This document outlines the build pipelines for the api application, covering both the traditional CodeBuild approach and a more streamlined multi-stage Docker build process. It also details the loc... ## Technical docs: Core Features - [Auth Security](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/technical/section-3/auth-security): The authentication and authorization system within the API (apps/api) is designed to secure endpoints by verifying the identity of incoming requests and ensuring they have the necessary permissions... - [Assistant Chat](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/technical/section-3/assistant-chat): The Assistant Chat module provides an API for managing ephemeral chat history for an AI assistant. It allows users to retrieve, save, and clear their conversation history, scoped to their user ID a... - [Evidence Forms](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/technical/section-3/evidence-forms): The Evidence Forms module provides a robust system for managing and processing various types of evidence submissions within an organization. It defines a set of pre-built forms, handles their submi... - [Finding Templates](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/technical/section-3/finding-templates): The finding-template/index.ts file serves as a "barrel" file, acting as a central entry point for the "Finding Templates" module within the API application. Its primary purpose is to re-export vari... - [Findings Workflow](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/technical/section-3/findings-workflow): The "Findings Workflow" within the API context refers to the set of components and processes involved in managing "findings" — likely security findings, vulnerabilities, or similar reportable items... - [Policy Management](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/technical/section-3/policy-management): Policy Management provides a robust system for organizations to create, manage, version, and publish their internal policies. It encompasses features for policy lifecycle management, including draf... - [Questionnaires](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/technical/section-3/questionnaires): The Questionnaire module provides a comprehensive solution for processing, answering, and managing security questionnaires. It enables users to upload various file formats (e.g., PDF, Excel, CSV, i... - [Knowledge Base](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/technical/section-3/knowledge-base): The Knowledge Base module provides a robust system for managing organizational documents and manual answers, integrating file storage, database persistence, and asynchronous processing capabilities... - [Risk Management](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/technical/section-3/risk-management): The Risk Management module provides a robust API for organizations to manage their identified risks. It enables users to create, retrieve, update, and delete risk records, associating them with spe... - [SOA Workflow](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/technical/section-3/soa-workflow): This page details the Statement of Applicability (SOA) Workflow, outlining the key stages involved in managing an organization's compliance posture against various standards, particularly focusing ... - [People Directory](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/technical/section-3/people-directory): The People Directory module provides a robust API for managing members within an organization. It allows for the creation, retrieval, updating, and deletion of individual members, as well as bulk c... - [Organization Admin](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/technical/section-3/organization-admin): This page outlines the functionalities and architecture related to "Organization Admin" within the API, focusing on managing organization-level settings, organizational charts, and contextual data.... ## Technical docs: Data Management - [Prisma Layer](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/technical/section-4/prisma-layer): The Prisma Layer primarily refers to the PrismaExtension class, a build extension designed for the Trigger.dev platform. Its main purpose is to automate the discovery, generation, and deployment of... - [Storage Flows](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/technical/section-4/storage-flows): This page details the various storage flows within the application, primarily focusing on how files and data are managed using Amazon S3. It covers the core S3 client configuration, and specific im... - [Validation Schemas](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/technical/section-4/validation-schemas): Validation schemas are a critical component of the API, serving two primary purposes: ensuring data integrity at runtime and providing clear, machine-readable API specifications for documentation. ... ## Technical docs: Backend Systems - [Platform Integrations](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/technical/section-5/platform-integrations): The Platform Integrations module provides a robust framework for connecting to external services, managing credentials securely, performing automated checks, synchronizing employee data, and handli... - [Cloud Security](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/technical/section-5/cloud-security): The Cloud Security module provides functionality to scan various cloud providers (AWS, Azure, GCP) for security findings. It integrates with the system's credential management to securely access cl... - [Notifications](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/technical/section-5/notifications): The notification system provides mechanisms for alerting users about significant events within the application, such as mentions in comments, changes in task status, or new findings. It leverages b... - [Comments System](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/technical/section-5/comments-system): The Comments System provides a robust API for managing comments associated with various entities within the application, such as tasks, policies, vendors, and risks. It supports creating, retrievin... - [Operations Endpoints](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/technical/section-5/operations-endpoints): This document outlines the various operational endpoints exposed by the API, covering browser automation, device agent management, device listing, and health checks. These endpoints facilitate inte... ## Technical docs: Frontend Components - [UI Surfaces](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/technical/section-6/ui-surfaces): The "UI Surfaces" within the Comp AI project primarily refer to the email templates and reusable components designed for transactional communications. These surfaces are built using React for Email... ## Technical docs: Deployment - [Deployment Guide](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/technical/section-7/deployment-guide): This guide provides comprehensive instructions for deploying and running the Comp AI platform, covering both cloud-based CI/CD processes for the API and local development setups. It details the ste... - [Third-party Services](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/technical/section-7/third-party-services): The project leverages several third-party services to provide core functionalities such as browser automation, email communication, caching, and cloud storage. These integrations enhance the applic... - [Release Process](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/technical/section-7/release-process): The release process for the comp project encompasses automated package publishing, rigorous dependency management, and defined build and deployment strategies. This ensures consistency across inter... ## Technical docs: Extensibility - [Framework Editor](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/technical/section-8/framework-editor): The Framework Editor module provides an API for managing "Task Templates". These templates define recurring tasks with properties such as name, description, frequency, and responsible department. T... - [Developer Tooling](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/technical/section-8/developer-tooling): Developer tooling for the api application encompasses a suite of scripts, configurations, and dependencies designed to streamline development, build processes, and maintain code quality. This inclu... ## Technical docs: How It Works - [Decode Single Task JWT](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/technical/how-it-works/decode-single-task-jwt): This document outlines the execution flow when a user initiates the download of task evidence from the SingleTask component, leading to the decoding of a JSON Web Token (JWT) payload. The primary g... - [Integrate & Decode JWT](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/technical/how-it-works/integrate-decode-jwt): This document outlines the execution flow that occurs when a user initiates the download of an automation evidence PDF from the TaskIntegrationChecks component. The primary goal of this process is ... - [Get Platform Connection](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/technical/how-it-works/get-platform-connection): This document outlines the execution flow for testing an integration connection, specifically focusing on how the IntegrationPlatformTestPage initiates a connection test and how the backend API pro... - [Update Platform Status](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/technical/how-it-works/update-platform-status): The "IntegrationPlatformTestPage -> UpdateStatus" flow describes the process initiated when a user attempts to test an existing integration connection from the Integration Platform Test Page. This ... - [Autofill Node Processing](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/technical/how-it-works/autofill-node-processing): This document outlines the execution flow for the "AutoFill -> ProcessNode" process, which is initiated when a user requests to auto-fill a Statement of Applicability (SOA) document. The primary go... - [Check Automation Run Success](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/technical/how-it-works/check-automation-run-success): This document details the execution flow that calculates the compliance score for frameworks displayed on the dashboard, specifically focusing on how the success of automated evidence collection ru... - [Get Browser Assets](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/technical/how-it-works/get-browser-assets): This process describes how the frontend application's BrowserAutomations component, through its interaction with the useBrowserContext hook, ultimately leads to a visual update of the Electron devi... - [Create Empty Paragraph](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/technical/how-it-works/create-empty-paragraph): This document describes the execution flow for "Editor -> CreateEmptyParagraph," a process that ensures the structural integrity of content within the TipTap editor. This flow is critical when the ... - [Get Platform Secret Key](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/technical/how-it-works/get-platform-secret-key): This document outlines the execution flow initiated when a user attempts to test an integration connection from the IntegrationPlatformTestPage in the frontend. The core purpose of this flow is to ... - [Derive Platform Key](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/technical/how-it-works/derive-platform-key): This document outlines the execution flow when a user initiates a "Test Connection" action from the Integration Platform Test Page, specifically focusing on the backend process of decrypting stored... ## Technical docs: API Reference - [comp API](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/api/api-overview): Version: inferred - [GET Redirect to Swagger documentation](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/api/endpoints/redirecttoswagger):