Compliance findings across all frameworks and Cloud/API Guard.
critical
2
high
4
medium
1
low
0
| Finding | Severity | Status | Source | Owner | Due | Action |
|---|---|---|---|---|---|---|
Unrestricted API key detected (frontend-exposed) A Google Maps API key with no application or API restrictions was found embedded in a public frontend bundle. | critical | Open | cloud api guard | Sam Okafor | May 30, 2026 | |
AI billing spike anomaly Sample AI provider spend increased 480% over the 7-day baseline within a 24-hour window. | critical | In triage | cloud api guard | Alex Doe | May 29, 2026 | |
Missing AI system inventory coverage Discovered AI usage does not fully reconcile with the registered AI inventory; 3 systems appear unregistered. | high | Awaiting evidence | control gap | Alex Doe | Jun 5, 2026 | |
Missing human oversight evidence No attestations or procedures documenting human oversight for high-risk AI systems. | high | Open | control gap | Priya Sharma | Jun 10, 2026 | |
Missing / expired data retention policy The data retention policy evidence has expired and no current replacement is on file. | high | Open | evidence expiry | Jordan Lee | Jun 1, 2026 | |
Risky service account with long-lived key A service account holds an editor role and a user-managed key unused for 90+ days. | high | In remediation | cloud api guard | Sam Okafor | Jun 3, 2026 | |
Incomplete supplier security evidence A critical supplier questionnaire is missing encryption and sub-processor sections. | medium | Awaiting evidence | control gap | Sam Okafor | Jun 12, 2026 |