Controls, applicability, evidence, policies, people, risks and incidents in one module, mapped criterion by criterion from the same sealed records the scanner writes. What a machine observed and what a person attested are shown apart.
Only your auditor can declare you compliant.
Module
Early access customers get the full module. Nothing here is a separate collector; every view reads the records Security Posture already wrote.
Window status, open criteria, what changed since the last scan.
SOC 2 first. Each criterion maps to the controls that answer it.
Machine-observed operating state per control, per connection.
What is open, who owns it, when it lapses.
Declare what is out of scope, with a reason, on the record.
Sealed records and attestations, with the read and not-read lines kept.
Company facts an auditor asks for, entered once.
Policy documents with owners, review dates and acknowledgements.
Roster seeded from Entra ID, access reviews minted per scope.
A register, with treatment and review dates.
Log, timeline, and the controls each incident touched.
ISO 27001, HIPAA, PCI DSS as maps over the same records.
Two Kinds of Evidence
A criterion is answered either by something a machine read on a date, or by something a named person signed on a date. The module shows which, and it never converts one into the other.
Comes from a sealed scan record. Has a source, a timestamp and a scan log line. Repeats on every scan inside the window.
CC6.1 Azure storage.publicAccess read 2026-08-24 03:12 UTC passSigned by a named owner with a date and a reason. Shown next to machine evidence, never as it. Expires and must be renewed.
CC1.2 Board oversight attested by J. Ortega 2026-07-01 renews 2026-10-01A criterion whose sources could not be read stays open in the module. It is not filled in, estimated or carried forward from a previous window.
CC7.2 purview.auditLog denied unanswered, openThe observation window builds day by day from operating controls. A control that lapses is marked lapsed on the day it lapsed; the window does not restart, the gap is shown.
window 2026-06-01 to 2026-08-30 day 86 of 90 2 criteria openFrameworks
Mapped criterion by criterion. Azure records are mapped today; Microsoft 365, Entra ID and AWS records join the map as each mapping is written and measured. A criterion without machine evidence stays open.
Already in Security Posture, and already the record base the compliance module reads.
Same rule: one record base, a framework is a map over it, coverage declared per scan.
Tell us which framework and which clouds. We will say what the module can observe for you today and what would be attested.
We'll reach out within one business day to schedule a time that works for you.