Documentation
¶
Overview ¶
Package privacyexport assembles a data-subject / DPO data-export bundle for one engagement (#635): the governance-relevant data the control plane holds — the detection projection rows + the engagement's active legal holds + a generated-at stamp — in a structured, read-only export. It answers a subject-access / data-portability request without mutating anything; the immutable evidence chain is unaffected (and, being source-side redacted, carries no raw PII).
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Bundle ¶
type Bundle struct {
EngagementID shared.ID `json:"engagement_id"`
GeneratedAt time.Time `json:"generated_at"`
Detections []detection.Record `json:"detections"`
LegalHolds []legalhold.Hold `json:"legal_holds"` // active holds covering this engagement's data
Count int `json:"detection_count"`
}
Bundle is the structured export for one engagement.
type DetectionReader ¶
type DetectionReader interface {
ListDetections(ctx context.Context, engagementID shared.ID) ([]detection.Record, error)
}
DetectionReader lists an engagement's detection projection rows (tenant-scoped via ctx). ports.DetectionRecordStore satisfies it.
type HoldReader ¶
HoldReader lists the tenant's active legal holds. legalholduc.Service satisfies it.
type Service ¶
type Service struct {
// contains filtered or unexported fields
}
Service assembles the export.
func NewService ¶
func NewService(detections DetectionReader, holds HoldReader, audit ports.AuditLogger, now func() time.Time) (*Service, error)
NewService constructs the exporter. holds is optional (nil ⇒ no hold section); the rest are required.