← All docs

Security reporting

Every rule violation, with severity, remediation, and which framework control it maps to.

Findings

Every open finding, filterable by severity (critical/high/medium/low), category, and provider, with the exact remediation step and the evidence that triggered it. Exportable to CSV for an audit.

Compliance status

Findings map to controls in whichever frameworks you've enabled (ISO 27001, PCI DSS, SOC 2, Cyber Essentials, and others). An asset's compliance status is only ever computed against frameworks you've explicitly turned on.

How findings are generated

A deterministic rule engine, not a language model — every rule is a plain, reviewable function over a resource's configuration. The same input always produces the same finding, and every rule's exact logic is documented per provider.