Compliance
Control-mapped findings across SOC 2, CIS, NIST, and ISO 27001, with one-click evidence export, live evidence posture, and SLA breach tracking.
At a glance
| Route | /compliance |
| Group | Security |
| Page permission | findings |
What it is
Control-mapped findings across SOC 2, CIS, NIST, and ISO 27001, with one-click evidence export, live evidence posture, and SLA breach tracking against control obligations.
Who it is for
Compliance officers, auditors, CISOs, and the engineering leads who must produce evidence when an audit arrives.
How it works
The same detection that identifies a cost or security problem also satisfies — or fails — a named control. Evidence export packages the underlying records into an auditor-consumable form.
Platform posture is disclosed too
The page surfaces the platform's own compliance posture:
- Encryption mode and at-rest protection profile for secret material
- Envelope encryption with per-record data keys, and key wrapping
- Conversation and memory retention settings
- Which data is included in AI context
Why the AI disclosure matters
An auditor examining an AI-enabled platform will ask what the model sees. Having that answer documented and exportable ahead of time removes a question that otherwise stalls an audit.
The aging monitor
Tracks findings by breach duration against control SLAs, so overdue control failures are visible rather than buried in the general queue.
Features
- Control mapping across SOC 2, CIS, NIST, and ISO 27001
- One-click evidence export
- Live evidence posture with cloud account coverage reporting
- SLA breach tracking with an aging monitor ranked by breach duration
- Encryption and key management posture disclosure
- AI data-handling disclosure — conversation retention, memory context, knowledge snippets, external research, and write-plane gating
- Policy evidence collection and export
- Programme readiness and compliance evidence bundle generation
How to use it
Identify which frameworks apply
And review the mapped control coverage for each.
Check evidence posture and resolve coverage gaps
A control cannot be evidenced across accounts the platform cannot read. A permission gap in Cloud Accounts becomes a compliance gap here.
Work the aging monitor
Prioritising the longest-breaching control failures rather than the newest ones.
Review AI data-handling settings
And align them with your organisation's policy before an auditor asks.
Export evidence bundles ahead of audit windows
Rather than during them.
Confirm audit log retention meets your framework's requirement
In Membership. See Audit Logs for retention by plan.
Why it matters
Audit preparation is expensive largely because evidence is assembled retrospectively by hand, from systems that were never designed to produce it.
Continuous control mapping with one-click export converts weeks of evidence gathering into an export.
And the AI data-handling disclosure pre-empts the question every auditor now asks of any platform with a language model in it.
Connects to
- Consumes findings from Opportunity Queue and FinSecOps
- Policy evidence from Policies
- Activity records from Audit Logs
- Retention governed by Membership
FinSecOps
Unified multi-cloud threat posture, an automation fabric of webhooks and event buses, and identity controls — where the cost and security perspectives converge.
Admin
Tenancy management — who has access, how the workspace estate is structured, which clouds and tools are connected, and how identity is federated.