Skip to main content

Findings & Audits

32
Total Findings
30
Open
2
Resolved

Platform Audits

AuditAssuranceDateScopeOpenResolved
ENISA EUDI Wallet Security Assessment🤖 AI-assisted2026-04-1585 wallet security requirements (ENISA v0.5) mapped to Siros130
GDPR Data Protection Audit🤖 AI-assisted2026-04-10All platform repos (go-wallet-backend, facetec-api, wallet-f22
ISO 27001 Annex A Coverage Assessment🤖 AI-assisted2026-04-15All 93 Annex A controls mapped to SirosID catalog150

All Open Findings

IDFindingSeverityOwnerControlsTracking
EN-P-1Wallet instance integrity verification missing🟠 highplatformcompliance#1
EN-P-2WSCD/WSCA via FIDO sign extension🔴 criticalplatformSID-KEY-01, SID-KEY-03compliance#2
EN-P-3Credential re-issuance functionality missing🟡 mediumplatformcompliance#3
EN-P-4Anti-tampering and obfuscation controls missing🟢 lowplatformcompliance#4
EN-S-1Partial audit logging and SIEM🟡 mediumplatformSID-AUDIT-01, SID-OPS-06compliance#5
EN-S-2Partial asset classification and cryptographic documentation🟡 mediumplatformSID-CRYPTO-01, SID-CRYPTO-02, SID-CRYPTO-03, SID-CRYPTO-04, SID-CRYPTO-05compliance#6
EN-S-3Partial SDLC, change management and vulnerability scanning🟡 mediumplatformSID-OPS-04, SID-OPS-05, SID-OPS-08compliance#7
EN-S-4Partial wallet unit security and lifecycle🟡 mediumplatformSID-AUTH-01, SID-AUTH-02, SID-TRANS-02, SID-TRANS-03, SID-HARD-04compliance#8
EN-S-5Partial transport and instance protection🟡 mediumplatformSID-TRANS-01, SID-AUTH-04, SID-CRYPTO-03compliance#9
EN-P-5Partial user authentication and session controls🟠 highplatformSID-AUTH-01, SID-AUTH-02, SID-AUTH-03, SID-KEY-01, SID-KEY-03, SID-CRYPTO-02compliance#10
EN-P-6Partial key management and credential operations🟡 mediumplatformSID-CRYPTO-02, SID-CRYPTO-03, SID-KEY-01, SID-KEY-03compliance#11
EN-P-7Partial hardening and error handling🟡 mediumplatformSID-HARD-01, SID-HARD-02, SID-HARD-05, SID-ACCESS-02, SID-TRANS-04compliance#12
EN-P-8Partial trust list freshness and status checking🟡 mediumplatformSID-TRUST-02, SID-TRUST-04, SID-DATA-03compliance#13
P-3Enterprise identity fields stored as plaintext🟡 mediumplatformSID-DATA-06compliance#14, go-wallet-backend#86
P-4Incomplete right-to-erasure cascade🟡 mediumplatformSID-PRIV-03compliance#15, go-wallet-backend#87, go-wallet-backend#89
ISO-O-8Partial segregation of duties🟢 lowplatformSID-ORG-02, SID-ACCESS-01compliance#16
ISO-O-9Partial threat intelligence coverage🟡 mediumplatformSID-ORG-03, SID-TRUST-02compliance#17
ISO-O-10Partial information classification🟢 lowplatformSID-DATA-01, SID-DATA-02compliance#18
ISO-O-11Partial access rights management🟢 lowplatformSID-ACCESS-01, SID-ACCESS-04compliance#19
ISO-O-12Partial supply chain security🟡 mediumplatformSID-ORG-04, SID-OPS-04compliance#20
ISO-O-13Partial incident assessment and evidence handling🟡 mediumplatformSID-OPS-01, SID-AUDIT-01compliance#21
ISO-O-14Partial PII protection🟠 highplatformSID-PRIV-01, SID-DATA-01, SID-DATA-02compliance#22
ISO-P-2Partial security event reporting🟢 lowplatformSID-PPL-04, SID-AUDIT-01compliance#23
ISO-PH-2Partial storage media controls🟢 lowplatformSID-PHY-02, SID-CRYPTO-03compliance#24
ISO-T-3Secure development lifecycle gaps🟡 mediumplatformSID-OPS-08compliance#25
ISO-T-5Partial endpoint and privileged access controls🟡 mediumplatformSID-AUTH-02, SID-HARD-03, SID-HARD-05, SID-CRYPTO-02compliance#26
ISO-T-6Partial vulnerability and malware protection🟡 mediumplatformSID-OPS-04, SID-HARD-05compliance#27
ISO-T-7Partial logging and monitoring🟡 mediumplatformSID-AUDIT-01, SID-OPS-06compliance#28
ISO-T-8Partial network security🟡 mediumplatformSID-TRANS-01, SID-TRANS-04, SID-HARD-03compliance#29
ISO-T-9Partial data leakage prevention🟢 lowplatformSID-HARD-01, SID-HARD-05, SID-PRIV-01compliance#30