Solutions/Compliance

The audit reads the evidence,
not a screenshot.

Control status is a function of what the platform observed. SecurityVault maps your controls to frameworks; it holds no third-party certification of its own today.

14
Frameworks mapped
Cross-walked pair-wise and closed transitively.
Ed25519
Signed control decisions
Public key distributable to auditors.
HMAC
Chained audit log
Each record carries the hash of its predecessor.
0
Certifications held by us
SecurityVault maps your controls to frameworks; it holds no third-party certification of its own today.
How it works

From scan to control status.

01

Evidence from scans

Findings and their typed evidence are the inputs. A control is satisfied or violated by what the platform observed, not by an upload.

02

Cross-walked frameworks

Fourteen shipped frameworks with pair-wise equivalence edges; custom frameworks join the same graph.

03

Continuous re-evaluation

Control status is re-computed as evidence changes, under idempotency keys and locked framework snapshots.

04

Signed decisions

Each control decision is Ed25519-signed over a canonical payload and appended to the HMAC-chained audit log.

05

Auditor portal

Read-only, invitation-based, signed. Auditors see evidence and control narratives, never the console.

06

Trust center and questionnaires

Publish your posture to customers; answer CAIQ, SIG and HECVAT from the same evidence.

Questions auditors and CISOs ask

Straight answers.

Is SecurityVault itself certified?
Not yet. We hold no SOC 2, ISO 27001 or other third-party certification today. The platform maps your controls; our own security architecture, DPA and questionnaire answers are available on request.
Which frameworks are mapped?
SOC 2, ISO 27001, NIST 800-53 Rev. 5, NIST CSF 2.0, PCI DSS v4, HIPAA, GDPR, CCPA/CPRA, CIS Controls v8, NIS2, DORA, SOX ITGC, the FedRAMP Moderate baseline (mapping only) and HECVAT. Anything else is a custom framework with the same control model.
What does an auditor actually receive?
A portal invitation with its own credentials, scoped read access to the controls in the engagement, evidence records with hashes, and the public key to verify signed decisions.
Can we keep our GRC platform?
Yes. SecurityVault is the evidence and control-evaluation layer; export to your GRC system through the API or SIEM connectors.
See a control end to end

One control, every framework it touches.

We start from a control, walk to the findings and scans behind it, and show what an auditor sees in the portal.