Compliance Decorators
Define TypeScript audit trails, sensitive-data classification, redaction, and retention policies with AxilJS semantic decorators.
Compliance Decorators
Compliance decorators declare audit, privacy, and data-governance constraints as semantic metadata. These declarations can be consumed by logging pipelines, database layers, and export tooling.
@tAudit
tAudit records an application action in an immutable audit trail.
Options
| Option | Type | Description |
|---|---|---|
action | string | Audit action identifier |
compliance | string[] | Compliance frameworks |
sensitivity | 'low' | 'medium' | 'high' | Data sensitivity level |
includeRequest | boolean | Include request data |
includeResponse | boolean | Include response data |
@tSensitive
tSensitive classifies a property under a specific sensitivity classification.
Supported classifications include:
| Classification | Description |
|---|---|
'PII' | Personally identifiable information |
'PHI' | Protected health information |
'PCI' | Payment card industry data |
'SECRET' | Secrets and credentials |
'INTERNAL' | Internal-only data |
@tRedact
tRedact prevents a property value from appearing in logs or outbound responses.
For controlled masking, specify a redaction strategy:
For example, the masked value can appear as:
Strategies
| Strategy | Description |
|---|---|
'mask' | Replace with asterisks while showing the configured number of characters |
'hash' | Replace with a one-way hash |
'remove' | Omit the value entirely from output |
@tRetention
tRetention declares a data-retention policy for an entity or property.
The decorator allows retention requirements to be represented as metadata rather than embedding retention logic directly into application code.
The source specification defines tRetention as the decorator for retention policy declarations, but does not specify its option schema in this documentation set.
Combining Compliance Semantics
Compliance decorators can be composed to describe both what data represents and how it should be handled.
An audit operation can separately declare its governance requirements:
This separates compliance intent from the implementation of logging, redaction, storage, or export behavior.
Reference
| Decorator | Purpose |
|---|---|
tAudit | Declare immutable audit-trail events |
tSensitive | Classify sensitive data |
tRedact | Prevent sensitive values from appearing in output |
tRetention | Declare data-retention policies |
Compliance decorators are semantic declarations. Their metadata can be consumed by independent infrastructure components such as logging pipelines, database layers, and export tooling rather than requiring compliance logic to be embedded into every business method.