Compliance
This section maps regulatory and industry-standard control frameworks to the openZro features that implement them.
These pages are intended as engineering correspondence — a shared vocabulary for the security team and the auditor. They are not legal advice; the operator is responsible for their own compliance posture, and openZro the project does not hold any regulatory registration on behalf of operators.
Available mappings
- Bacen Resolução 4.893 / Circular 3.909 — Brazilian Central Bank cybersecurity policy and operational requirements for fintechs and supervised banks.
Coverage gaps welcome
If your regulatory environment is not yet covered, the mapping pattern is small and reusable: identify the controls, locate the openZro feature, name the audit artefact. Open a GitHub Discussion with the framework and we can scaffold the page together.