Files
breakpilot-compliance/zeroclaw
Benjamin Admin fa4fd87102
Build + Deploy / build-admin-compliance (push) Successful in 9s
Build + Deploy / build-backend-compliance (push) Successful in 8s
Build + Deploy / build-ai-sdk (push) Successful in 42s
Build + Deploy / build-developer-portal (push) Successful in 8s
Build + Deploy / build-tts (push) Successful in 7s
Build + Deploy / build-document-crawler (push) Successful in 7s
Build + Deploy / build-dsms-gateway (push) Successful in 8s
Build + Deploy / build-dsms-node (push) Successful in 8s
CI / branch-name (push) Has been skipped
CI / guardrail-integrity (push) Has been skipped
CI / loc-budget (push) Failing after 18s
CI / secret-scan (push) Has been skipped
CI / go-lint (push) Has been skipped
CI / python-lint (push) Has been skipped
CI / nodejs-lint (push) Has been skipped
CI / nodejs-build (push) Successful in 2m57s
CI / dep-audit (push) Has been skipped
CI / sbom-scan (push) Has been skipped
CI / test-go (push) Failing after 49s
CI / test-python-backend (push) Successful in 42s
CI / test-python-document-crawler (push) Successful in 28s
CI / test-python-dsms-gateway (push) Successful in 23s
CI / validate-canonical-controls (push) Successful in 15s
Build + Deploy / trigger-orca (push) Successful in 2m24s
fix: 7 regex bugs from IHK Konstanz ground truth analysis
Fixes based on manual verification of all 30 failed checks:
1. Cookie table: recognize "folgende cookies" + column headers as text
2. Cookie names: add JSESSIONID, cookieinfo, et_id, BT_* patterns
3. Essential justified: match "sitzung zuordnen", "betrieb der website"
4. Social bookmarks: recognize as 2-click alternative
5. DSFA plural: "kanaelen" now matches alongside "kanal"
6. Section splitter: skip-headings no longer lose subsequent text
   (Risikoabwaegung section was cut from DSFA, losing risk scores)
7. Cookie legal basis: accept Art. 6(1)(f) in cookie context

Reduces false positives from 7 to ~1-2 for IHK Konstanz test case.
Ground truth table: zeroclaw/docs/ground-truth-ihk-konstanz.md

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-05-07 14:51:09 +02:00
..

ZeroClaw Compliance Agent Demo

Autonomer Compliance-Agent der Web-Dokumente (Cookie-Banner, Datenschutzerklaerungen) analysiert und die Ergebnisse an die zustaendige Rolle weiterleitet.

Architektur

ZeroClaw Agent (Rust, Mac Mini)
  │
  ├── LLM: Qwen 3.5:35b-a3b (Ollama, localhost:11434)
  │
  ├── Compliance SDK (Go/Gin, localhost:8093)
  │   ├── /sdk/v1/llm/chat         → Dokumentklassifizierung
  │   ├── /sdk/v1/ucca/assess      → Risikobewertung
  │   └── /sdk/v1/ucca/escalations → Eskalation + Rollenzuweisung
  │
  ├── Backend (Python/FastAPI, localhost:8002)
  │   └── /api/compliance/agent/notify → Email-Benachrichtigung
  │
  └── Mailpit (SMTP localhost:1025, Web localhost:8025)
      └── Fiktive Email-Zustellung

Voraussetzungen

  • ZeroClaw v0.7.3+ (brew install zeroclaw)
  • Ollama mit qwen3.5:35b-a3b Modell
  • Alle Compliance-Services laufen (SDK, Backend, Mailpit)

Demo ausfuehren

# 1. ZeroClaw mit Ollama verbinden (einmalig)
zeroclaw onboard --quick --provider ollama --model qwen3.5:35b-a3b

# 2. SOP ausfuehren
zeroclaw agent -m "Analysiere die Datenschutzerklaerung von https://www.google.com/intl/de/policies/privacy/"

# 3. Ergebnis pruefen
open http://localhost:8025  # Mailpit Web-UI

E2E Test

bash zeroclaw/tests/test_sop_workflow.sh

SOP-Workflow (6 Schritte)

  1. Fetch — URL holen, HTML strippen
  2. Classify — Dokumenttyp bestimmen (privacy_policy, cookie_banner, etc.)
  3. Assess — DSGVO-Risikobewertung via UCCA
  4. Summarize — Manager-Report auf Deutsch
  5. Assign — Zustaendige Rolle bestimmen (E0-E3 Mapping)
  6. Notify — Email an DSB/Teamleitung senden