Missing User Warnings
Medium
- Confidence
- 83% confidence
- Finding
- The script persists regulatory submission records to a local JSON file without any notice, consent flow, or safeguards around storing potentially sensitive business data and personal identifiers such as responsible_person, product_name, notes, and regulatory strategy details. In a regulatory affairs context, these records can include confidential commercial information and employee data, so silent plaintext storage increases the risk of unauthorized disclosure if the host is shared, compromised, or backups/logging expose the file.
