docs(security): DPA is not available; sub-processor list is published - #5967
Conversation
|
Landing PR to merge first: https://github.com/vivekchand/clawmetry-landing/pull/828 publishes /compliance, /subprocessors and /dpa, which this SECURITY.md change links. |
✅ Drift Bot (ClawMetry): no drift detectedDrift Bot analyzed the changed files against this project's blueprints and requirements and found no drift. |
2 similar comments
✅ Drift Bot (ClawMetry): no drift detectedDrift Bot analyzed the changed files against this project's blueprints and requirements and found no drift. |
✅ Drift Bot (ClawMetry): no drift detectedDrift Bot analyzed the changed files against this project's blueprints and requirements and found no drift. |
SECURITY.md said "DPA / sub-processor list: Available on request; not yet published". No DPA has been drafted, so offering one on request was wrong, and the sub-processor list is now public on clawmetry.com. Split the row and link the compliance status page. The same table said "SSO / SAML / SCIM: Not implemented" while the published sub-processor list names WorkOS for SAML and OIDC sign-in. Split that row too: SSO is in progress on the managed cloud only, not yet verified against a live identity provider; SCIM is not implemented. Refs vivekchand/clawmetry-landing#815 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Jm9d7s4fN55hN3YzQo75o9
e757feb to
072bb28
Compare
✅ Drift Bot (ClawMetry): no drift detectedDrift Bot analyzed the changed files against this project's blueprints and requirements and found no drift. |
✅ Drift Bot (ClawMetry): no drift detectedDrift Bot analyzed the changed files against this project's blueprints and requirements and found no drift. |
|
Updated to current main via Generated by Claude Code |
A first draft now exists (private); nothing is available to sign until counsel review, matching clawmetry.com/dpa. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PpgUzn1U4r61abUJN4PXn4
✅ Drift Bot (ClawMetry): no drift detectedDrift Bot analyzed the changed files against this project's blueprints and requirements and found no drift. |
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PpgUzn1U4r61abUJN4PXn4
✅ Drift Bot (ClawMetry): no drift detectedDrift Bot analyzed the changed files against this project's blueprints and requirements and found no drift. |
Both merged onto main after 0.12.879 and before this release branch was cut, so the release already contains their code. #5957 gets its CHANGELOG entry; #5967 is documentation only. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Jm9d7s4fN55hN3YzQo75o9
…y, cold-load fix, hosted Cost Optimizer data Carries #5950 (clawmetry service install/status/uninstall, per-user collectors on shared hosts), #5965 (LiteLLM gateway spend by team/person/key), #5957 (cold-load timeouts), #5996 (Cost Optimizer evidence slice), #5967 (CHANGELOG entries). This triggers PyPI 0.12.880. After it publishes: verify wheel contains clawmetry service and gateway_litellm; wait for cloud auto-pin PR; landing #836 can drop its DO NOT MERGE prefix; cloud #2450 and #2455 can merge after the pin. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Jgaf95Zzshc3FUBzqNRxiT
Refs vivekchand/clawmetry-landing#815
Requirement: https://factory.8090.ai/project/b415065f-ab2f-4f53-8864-0c009fd098cb/requirements/6f0ecab6-cdbd-4e47-a5ea-8765b22deee4 (Public Assurance Status, Sub-processor List and DPA Availability).
Merge order: satisfied. Landing PR https://github.com/vivekchand/clawmetry-landing/pull/828 (merged 2026-09-14) publishes /compliance, /subprocessors and /dpa, which this change links.
Why
The Compliance status table said "DPA / sub-processor list: Available on request; not yet published". The private supplier pack recorded that no DPA had been drafted or reviewed, so a DPA was never available on request. The sub-processor list is now published on clawmetry.com.
The same table said "SSO / SAML / SCIM: Not implemented", while the published /subprocessors page names WorkOS as the SAML and OIDC sign-in broker. The two public documents disagreed.
Change
Docs only:
SECURITY.md.No code, no routes, no tests affected.
Not changed (noted for a follow-up)
🤖 Generated with Claude Code
https://claude.ai/code/session_01Jm9d7s4fN55hN3YzQo75o9