Three capabilities that build on each other. Each produces something you can put in front of an examiner.
Every system holding payment or personal data: what it holds, where it sits now, where it is going, its status and who owns it.
It deliberately covers systems we cannot move. Core databases, nightly backups and log stores hold the same payment data as the buckets, and the obligation covers them too. A register limited to what our tool happens to handle would misrepresent your position — which is the opposite of the point.
Any S3-compatible source to any S3-compatible Nigerian provider, using credentials you generate from your own accounts.
One pack covering the register, the migrations that evidence it, and the declarations behind everything else. It reports what is backed by a confirmed migration and what rests on a statement, as separate counts.
There is no overall score. Blending declarations with verified migrations into a single percentage would invent a verdict, and the first person to test it would be an examiner.
An honest position statement, including the part that is inconvenient for us.
It is issued only when every enumerated object has been confirmed. Otherwise it refuses, and tells you why.
A compliance platform that overstates its reach is worse than none, because somebody will rely on it.