Module · Enterprise

Compliance,
continuous evidence for twelve frameworks.

Every finding from every other module maps automatically to the controls that govern you: ISO 27001, SOC 2, NIST CSF, GDPR, HIPAA, PCI DSS, FedRAMP, DORA and more. No more spreadsheet archaeology the week before an audit.

Controls across ISO 27001, NIST, PCI DSS and GDPR, each mapping traceable to the finding behind it.

At a glance

Compliance at a glance

Coverage

What we observe

Twelve frameworks mapped control by control, with pass, fail and not-applicable states derived from live scan evidence.

Scoring

How it's scored

Control mapping is derived from the same findings that drive the rating, so the compliance view and the score never disagree.

Action

What happens next

Export evidence per control, and see which single fixes touch the most mapped controls at once.

What we observe

  • Findings mapped to ISO 27001, NIST, PCI DSS and GDPR
  • The control each external finding bears on
  • The specific finding behind every mapping
  • Which single fixes touch the most controls
  • Change in mapped exposure over time

What arrives on a finding

  • A Compliance report showing every control and its status
  • Traceability from a failed control to the evidence
  • Remediation that closes the control, not just the finding
  • Continuous re-evaluation rather than point-in-time
  • Evidence you can hand to an auditor
Worked example

Anatomy of a finding

ControlAn email-authentication control within your enabled frameworks
StatusFail
Triggered byThe DMARC finding from the Domain Security module
EvidenceThe published DNS record that produced the finding
Closes whenThe record reaches enforcement and the next scan confirms it
Compliance matrix mapping findings automatically to the frameworks you report against

Continuous evidence, mapped control by control across ISO 27001, NIST, PCI DSS and GDPR

What this does

Mapping observable findings to framework controls

Compliance frameworks contain a subset of controls that are externally observable, transport encryption, mail authentication, certificate management, exposure of administrative interfaces, asset inventory completeness. This module maps findings to those controls so a technical finding arrives with the control it breaks already attached.

The practical value is translation. A security team already knows an exposed management interface is bad. What takes time is explaining to an auditor, a customer's compliance team or a board committee which control it relates to and why it matters in their language. Having that mapping attached removes a recurring translation cost that is paid over and over.

It also works in the other direction, which is where most of the day-to-day use is. When a customer's security questionnaire asks about a specific control, the evidence is already assembled rather than gathered from scratch under a deadline.

The honest limit

No external assessment certifies compliance

This needs saying plainly because the category invites overclaiming. An outside-in platform cannot certify compliance with any framework, and nothing here should be represented to an auditor as doing so.

Frameworks are mostly about things that are not externally observable: governance, documented policy, risk assessment process, staff training, access reviews, incident response procedure, business continuity testing, evidence of management oversight. Those require an audit conducted by people with access, and no amount of external scanning substitutes for one.

What this does is cover the technical controls that are observable, continuously, with evidence, which is genuinely useful, because those are exactly the controls that drift between annual audits. A control that was compliant at audit and is not compliant now is the most common way an organisation ends up non-compliant while holding a valid certificate.

Between audits

Continuous evidence is the actual product

Audit is a point-in-time exercise. The period afterwards is where technical controls drift: certificates lapse, a new asset appears outside the inventory, a configuration changes during an incident and is never reverted, a supplier is added without review.

Continuous monitoring against the mapped controls turns that from something discovered at the next audit into something raised the week it happens. For organisations holding a certification, that is the difference between remediation and a finding on the record.

It also makes audit preparation less expensive. Evidence gathered continuously, timestamped and versioned, is a materially better position than reconstructing what the estate looked like across the period from memory and screenshots, and reconstruction is what most preparation actually consists of.

Questions

Common questions

Does this make us compliant with a framework?

No, and we would not claim it does. Frameworks are largely about governance, documented policy, training, access reviews and incident response, none of which are externally observable. This covers the technical controls that are, continuously and with evidence.

Then what is it actually for?

Two things. It attaches the relevant control to each technical finding, which removes a recurring translation cost when talking to auditors, customers and boards. And it catches control drift between annual audits, which is the most common way a certified organisation ends up non-compliant.

Can we use this as audit evidence?

It can support an audit as continuous, timestamped, versioned evidence for the technical controls it covers. It does not replace the audit, and an auditor will rightly want more.

Which frameworks are mapped?

The mapping covers the observable technical controls across the frameworks supported in your configuration. The pages for each framework set out exactly which controls are in scope and which are not.

What is control drift?

A control that was compliant at audit and is not now: a lapsed certificate, an asset outside the inventory, a configuration changed during an incident and never reverted. It is invisible until the next audit unless something is watching continuously.

Does a customer's compliance team accept these reports?

They are useful supporting evidence for the technical controls, assembled in advance rather than gathered under deadline. They are not a substitute for whatever certification the customer is asking to see.

Related

Where this connects

Reports →

Compliance-tailored exports with evidence attached to each control.

How scoring works →

Deterministic, versioned scoring behind every mapped finding.

Board reporting →

Turning control coverage into something a committee can govern.

Rate your own compliance first

See what attackers and insurers see. Free for your own organisation.