What we shipped
A compliance report compiler that owns the full path from raw vendor data to delivered PDF. A Python orchestrator pulls from Microsoft Graph, Cisco ThousandEyes, Palo Alto Cortex, and the remaining vendor APIs into a Pydantic-validated data model. That model feeds a Claude Opus narrative generator that drafts the executive summary, the per-control findings, and the remediation recommendations. Framework-specific templates shape the tone for SOC, ISO 27001, GDPR, NIS2, or ZEN-2. The branded PDF renders at the end.
Every report produces a draft, not a final. The consultant opens it in the DNN Portal review view, sees raw vendor data alongside the narrative, edits judgment calls, and signs off. The signed report archives to S3 with a full audit trail — vendor API timestamps, prompt hash, consultant ID, edit diff. Compliance work has legal teeth; the audit trail was a contractual requirement.