Compliance
Early access

SecValley Compliance An observation window built from the records you already have.

Controls, applicability, evidence, policies, people, risks and incidents in one module, mapped criterion by criterion from the same sealed records the scanner writes. What a machine observed and what a person attested are shown apart.

Only your auditor can declare you compliant.

Request an invite See the records it reads

Eleven Views Over One Record Base

Early access customers get the full module. Nothing here is a separate collector; every view reads the records Security Posture already wrote.

Overview

Window status, open criteria, what changed since the last scan.

Frameworks

SOC 2 first. Each criterion maps to the controls that answer it.

Controls

Machine-observed operating state per control, per connection.

Tasks

What is open, who owns it, when it lapses.

Applicability

Declare what is out of scope, with a reason, on the record.

Evidence

Sealed records and attestations, with the read and not-read lines kept.

Profile

Company facts an auditor asks for, entered once.

Policies

Policy documents with owners, review dates and acknowledgements.

People

Roster seeded from Entra ID, access reviews minted per scope.

Risks

A register, with treatment and review dates.

Incidents

Log, timeline, and the controls each incident touched.

Next

ISO 27001, HIPAA, PCI DSS as maps over the same records.

Observed and Attested Are Never Mixed

A criterion is answered either by something a machine read on a date, or by something a named person signed on a date. The module shows which, and it never converts one into the other.

Observed by machine

Comes from a sealed scan record. Has a source, a timestamp and a scan log line. Repeats on every scan inside the window.

CC6.1 Azure storage.publicAccess read 2026-08-24 03:12 UTC pass

Attested by a person

Signed by a named owner with a date and a reason. Shown next to machine evidence, never as it. Expires and must be renewed.

CC1.2 Board oversight attested by J. Ortega 2026-07-01 renews 2026-10-01

Not read

A criterion whose sources could not be read stays open in the module. It is not filled in, estimated or carried forward from a previous window.

CC7.2 purview.auditLog denied unanswered, open

The window

The observation window builds day by day from operating controls. A control that lapses is marked lapsed on the day it lapsed; the window does not restart, the gap is shown.

window 2026-06-01 to 2026-08-30 day 86 of 90 2 criteria open

SOC 2 First, From Azure Records First

Building

SOC 2 Trust Services Criteria

Mapped criterion by criterion. Azure records are mapped today; Microsoft 365, Entra ID and AWS records join the map as each mapping is written and measured. A criterion without machine evidence stays open.

Live

CIS benchmarks

Already in Security Posture, and already the record base the compliance module reads.

Next

ISO 27001, HIPAA, PCI DSS

Same rule: one record base, a framework is a map over it, coverage declared per scan.

Plain termsWe do not issue audit reports, opinions or certifications. The module prepares the record; your auditor makes the call.

Early Access Is by Invite

Tell us which framework and which clouds. We will say what the module can observe for you today and what would be attested.

  • Full module, every view, no separate collector
  • Reads the Security Posture records you already have
  • No price to see until it is sellable

We respect your privacy. No spam, ever.