GovernDiff · audit report

Policy change review

GovernDiff provides machine-assisted document comparison and review cues. It does not constitute legal advice, a policy-effect assessment, or a compliance determination. Important changes must be verified by a person with the appropriate responsibility and expertise.

Generator
governdiff/0.6.0 · schema 1.5
Generated
2026-08-21T13:07:16.481772+00:00
Scope
all · redacted no
Old document
examples/public-cases/01-incident-deadline/old.md
55dbb4cf8170d29e82169ecbbd0962b479f649b07e0db89b992d5dd269f9947c
New document
examples/public-cases/01-incident-deadline/new.md
516f8aa9aa304f2789595d14160245dd816ea65b9a40ebe743e1e50f1176a65f

Overview

Changes1
Findings2
Active2
Breaking2

Changes and evidence

modified · GVC-81A584FE55

Vendor incident response policy > Notification

Alignment confidence high 0.92 · review unreviewed

modality-strengthened · modality

Normative force was strengthened.

highhigh 0.92unreviewed

Detected a shift from permitted language to mandatory language.

BeforeVendors may report a security incident within 72 hours after discovery.
AfterVendors must report a security incident within 24 hours after discovery.
Machine
may → must
Effective
may → must

deadline-shortened · deadline

A deadline changed from 72 hours to 24 hours.

highhigh 0.94unreviewed

A relative duration with the same unit appears once in both aligned clauses.

BeforeVendors may report a security incident within 72 hours after discovery.
AfterVendors must report a security incident within 24 hours after discovery.
Machine
72 hours → 24 hours
Effective
72 hours → 24 hours