Compliance & SOC 2 readiness
How the compliance dashboard maps your live security posture onto GDPR, PCI DSS, HIPAA, UAE PDPL, and SOC 2 — and how the readiness percentage is worked out.
The compliance dashboard takes the security posture we already measure for you and maps it onto the frameworks buyers and auditors care about — GDPR, PCI DSS, HIPAA, UAE PDPL, and SOC 2. You don't fill in a questionnaire; each framework is scored from findings, integrations, team roles, and scan freshness that already exist in your account.
What the frameworks and crosswalk do
Every framework is a checklist of controls. We "crosswalk" each control to a concrete signal in your account and mark it pass, fail, manual, or not applicable. For example, a SOC 2 transmission-security control passes when you have no open critical or high TLS/certificate findings; a change-management control passes when branch protection is enforced on your connected GitHub org.
Some controls can't be proven by a scan — board oversight, written policies, a published privacy notice. Those stay manual until you record evidence against them. We never mark a manual control as done on your behalf.
How the readiness percentage is computed
Readiness is simply the share of controls that pass:
- We count the controls that apply to you (pass + fail).
- Readiness = passing controls ÷ applicable controls, rounded to a whole percent.
- For SOC 2, a manual control counts toward your score once you've recorded evidence for it.
A brand-new account with no scans yet shows "Not yet assessed" rather than a misleading green 100%. Once your first scan runs, real numbers appear.
How to set it up
- There's nothing to switch on — open Compliance and the engine scores you from your existing data.
- To lift your auto-checked score, add your domains and connect integrations (GitHub, your workspace) so more controls have real signals to read.
- For manual controls, use Upload evidence to attach a short note or document. That flips the control to passing and folds it into your percentage.
- Results are recomputed on demand and cached for a day, so the page loads instantly on return visits.
How to read your results
- The big number on each framework card is your readiness percentage — green at 80%+, amber in the middle, red when most controls are failing.
- Expand a framework to see each control with a plain-language evidence line, for example "2 open critical/high access-control findings across GitHub org + workspace integrations."
- Fail means a live finding in your account is blocking that control — fix the finding and the control flips to pass on the next evaluation.
- Hand the evidence lines straight to an auditor or a prospect's security team; they read as plain English, not raw control IDs.
Related: Understanding your security score explains where the underlying findings come from.