Decorators

Compliance Decorators

Define TypeScript audit trails, sensitive-data classification, redaction, and retention policies with AxilJS semantic decorators.

3 min readDocumentationEdit this page

Compliance Decorators

Compliance decorators declare audit, privacy, and data-governance constraints as semantic metadata. These declarations can be consumed by logging pipelines, database layers, and export tooling.

@tAudit

tAudit records an application action in an immutable audit trail.

typescript
import { tAudit } from '@axiljs/decorator'
 
@tAudit({
  action: 'user.deleted',
})
async deleteUser(id: string) {}
 
@tAudit({
  action: 'funds.transferred',
  compliance: ['SOC2', 'PCI-DSS'],
  sensitivity: 'high',
})
async transferFunds() {}

Options

OptionTypeDescription
actionstringAudit action identifier
compliancestring[]Compliance frameworks
sensitivity'low' | 'medium' | 'high'Data sensitivity level
includeRequestbooleanInclude request data
includeResponsebooleanInclude response data

@tSensitive

tSensitive classifies a property under a specific sensitivity classification.

typescript
@tSensitive('PII')
email: string
 
@tSensitive('PCI')
cardNumber: string
 
@tSensitive('PHI')
diagnosis: string

Supported classifications include:

ClassificationDescription
'PII'Personally identifiable information
'PHI'Protected health information
'PCI'Payment card industry data
'SECRET'Secrets and credentials
'INTERNAL'Internal-only data

@tRedact

tRedact prevents a property value from appearing in logs or outbound responses.

typescript
@tRedact()
password: string

For controlled masking, specify a redaction strategy:

typescript
@tRedact({
  strategy: 'mask',
  visibleChars: 4,
})
cardNumber: string

For example, the masked value can appear as:

text
****1234

Strategies

StrategyDescription
'mask'Replace with asterisks while showing the configured number of characters
'hash'Replace with a one-way hash
'remove'Omit the value entirely from output

@tRetention

tRetention declares a data-retention policy for an entity or property.

The decorator allows retention requirements to be represented as metadata rather than embedding retention logic directly into application code.

typescript
@tRetention(/* retention policy */)

The source specification defines tRetention as the decorator for retention policy declarations, but does not specify its option schema in this documentation set.

Combining Compliance Semantics

Compliance decorators can be composed to describe both what data represents and how it should be handled.

typescript
class PaymentRecord {
  @tSensitive('PCI')
  @tRedact({
    strategy: 'mask',
    visibleChars: 4,
  })
  cardNumber: string
}

An audit operation can separately declare its governance requirements:

typescript
@tAudit({
  action: 'funds.transferred',
  compliance: ['SOC2', 'PCI-DSS'],
  sensitivity: 'high',
})
async transferFunds() {
  return this.paymentService.transfer()
}

This separates compliance intent from the implementation of logging, redaction, storage, or export behavior.

Reference

DecoratorPurpose
tAuditDeclare immutable audit-trail events
tSensitiveClassify sensitive data
tRedactPrevent sensitive values from appearing in output
tRetentionDeclare data-retention policies

Compliance decorators are semantic declarations. Their metadata can be consumed by independent infrastructure components such as logging pipelines, database layers, and export tooling rather than requiring compliance logic to be embedded into every business method.

Help improve the documentation

AxilJS is open source and documentation improvements are welcome.

AxilJS DocumentationMIT License · Built by SyntaxilitY