docs(features): control mapping pipeline (grounded in the C5 live results)
CI / Check (push) Skipped
CI / Check (pull_request) Successful in 5m53s
CI / Detect Changes (pull_request) Skipped
CI / Deploy Agent (pull_request) Skipped
CI / Deploy Dashboard (pull_request) Skipped
CI / Deploy Docs (pull_request) Skipped
CI / Deploy MCP (pull_request) Skipped
CI / Check (push) Skipped
CI / Check (pull_request) Successful in 5m53s
CI / Detect Changes (pull_request) Skipped
CI / Deploy Agent (pull_request) Skipped
CI / Deploy Dashboard (pull_request) Skipped
CI / Deploy Docs (pull_request) Skipped
CI / Deploy MCP (pull_request) Skipped
Extensive feature doc for the compliance control-mapping engine: - core principle (tools detect, LLM judges/grounds — never detects) - coverage model + the CRA hybrid (4 semgrep / 8 grounded / 4 not-code-checkable) - the three mapping paths (LUT 5b / semantic 5c / grounded-surface 5d) with a mermaid flow, and the shared grounding gate - semantic retrieval detail incl. the query-enrichment tuning - two worked examples from the live C5 run (auth file + varied vulns) - known limitations (absence findings, catch-all controls, corpus noise) - config flags + an appendix on the master-controls data pipeline war-story (dump-triplication -> migration 160 dedup; 502 -> 200) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Fable 5
parent
a25d41c3e5
commit
d03f027fa1
@@ -36,6 +36,7 @@ export default withMermaid(defineConfig({
|
||||
{ text: 'Pentest Architecture', link: '/features/pentest-architecture' },
|
||||
{ text: 'AI Chat', link: '/features/ai-chat' },
|
||||
{ text: 'Code Knowledge Graph', link: '/features/graph' },
|
||||
{ text: 'Compliance Control Mapping', link: '/features/control-mapping' },
|
||||
{ text: 'MCP Integration', link: '/features/mcp-server' },
|
||||
],
|
||||
},
|
||||
|
||||
Reference in New Issue
Block a user