Security & Governance Compliance, risk, and reports

Compliance, risk, and reports

These three pages are for posture reporting: frameworks and assessments, quantified risk, and files you hand to auditors.

Compliance

Route: /compliance Who: OWNER and ADMIN

Compliance maps technical policy results onto frameworks (controls and assessments), not just raw scan findings.

Frameworks available in intelligence/compliance views include CIS, NIST CSF, SOC 2, PCI DSS, HIPAA, GDPR, ISO 27001, FedRAMP, CMMC, DORA, NIS2, and Kubernetes CIS. The Compliance page lists framework summaries, posture, assessments, exceptions, and schedules.

i

Compliance is not a substitute for fixing violations. A high framework score with open critical findings still needs remediation on Dashboard and My findings.

Risk

Route: /security/risk Who: OWNER and ADMIN

Risk is the command center for severity mix, trends, heatmaps, and prioritized remediation. It uses the security intelligence risk model (score 0–100 across dimensions such as severity, exploitability, internet exposure, asset criticality, compliance impact, identity exposure, KEV/EPSS, and finding age).

i

This page does not run scans. It aggregates scan and intelligence data. If the page is empty, run scans and enable live scan first.

Reports

Route: /governance/reports Who: OWNER and ADMIN

Entitlement: full evidence bundle and persona pack require the governance feature (Professional / Enterprise). CSV policy export of recent evaluations is available more broadly.

!

If evidence bundle download fails, the usual cause is missing governance entitlement on the organization plan—not a permissions bug for OWNER.

What you can download

Export Contents Typical audience
Policy report (CSV) Evaluations / violations for the last 30 days Platform / DevSecOps
Evidence bundle Combined pack: policy CSV, compliance JSON, audit CSV, persona files Auditors, GRC
Persona export JSON, CSV, or HTML for EXECUTIVE, CISO, COMPLIANCE, AUDITOR, DEVSECOPS Role-specific reviews
i

Scheduled evidence (Dashboard settings)
You can schedule evidence delivery (webhook live; email and S3 until credentials exist) and run a schedule on demand. Configure under Governance Dashboard → Settings. Change-management tickets for remediations are configured under Administration → Integrations → Change Management.

Audit trail

Governance actions (gate changes, exception decisions, break-glass, policy publish) are written to Administration → Audit Logs (/administration/audit-logs).

VIEWER has audit:read; MEMBER does not.

Optional audit webhook streams governance-category events to a SIEM.