privacyexport

package
v0.2.2 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 27, 2026 License: Apache-2.0 Imports: 7 Imported by: 0

Documentation

Overview

Package privacyexport assembles a data-subject / DPO data-export bundle for one engagement (#635): the governance-relevant data the control plane holds — the detection projection rows + the engagement's active legal holds + a generated-at stamp — in a structured, read-only export. It answers a subject-access / data-portability request without mutating anything; the immutable evidence chain is unaffected (and, being source-side redacted, carries no raw PII).

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type Bundle

type Bundle struct {
	EngagementID shared.ID          `json:"engagement_id"`
	GeneratedAt  time.Time          `json:"generated_at"`
	Detections   []detection.Record `json:"detections"`
	LegalHolds   []legalhold.Hold   `json:"legal_holds"` // active holds covering this engagement's data
	Count        int                `json:"detection_count"`
}

Bundle is the structured export for one engagement.

type DetectionReader

type DetectionReader interface {
	ListDetections(ctx context.Context, engagementID shared.ID) ([]detection.Record, error)
}

DetectionReader lists an engagement's detection projection rows (tenant-scoped via ctx). ports.DetectionRecordStore satisfies it.

type HoldReader

type HoldReader interface {
	ListActive(ctx context.Context) ([]legalhold.Hold, error)
}

HoldReader lists the tenant's active legal holds. legalholduc.Service satisfies it.

type Service

type Service struct {
	// contains filtered or unexported fields
}

Service assembles the export.

func NewService

func NewService(detections DetectionReader, holds HoldReader, audit ports.AuditLogger, now func() time.Time) (*Service, error)

NewService constructs the exporter. holds is optional (nil ⇒ no hold section); the rest are required.

func (*Service) Export

func (s *Service) Export(ctx context.Context, actor string, engagementID shared.ID) (Bundle, error)

Export gathers the engagement's detection projection + active legal holds into a read-only bundle. The export itself is an audited access (a subject-access request is a governance event), but reads nothing it should not and mutates nothing.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL