Compliance
Cloud Compliance Monitoring
Framework scores from live findings — not a spreadsheet you update twice a year.
Twelve frameworks ship mapped to 10ETLabs posture rules: CIS AWS Foundations, CIS Microsoft Azure Foundations (subset), CIS Google Cloud Foundations (subset), SOC 2, PCI DSS, HIPAA, ISO 27001, NIST CSF, FedRAMP, GDPR, India’s DPDP Act, and the 10ET AI Workload Baseline. Control pass/fail comes from this tenant’s open findings. Write your own frameworks — or clone a built-in one — with controls mapped to the same rules or to manual attestations, and generate a signed evidence pack for any framework. This is not a 185-control catalog; it is a live mapping you can defend in a walkthrough.

Compliance
Ten packs — including DPDP and an AI workload baseline — scored from the same live findings the SOC already remediates. Not a spreadsheet from last quarter.
See it work
From one finding to every framework it touches
Controls pass or fail from open findings, so one fix moves every framework that maps to it.
Findings → controls → framework scores
01Findings from the last scan
Open findings are the evidence. Nothing is typed into a spreadsheet.
What you get
Twelve frameworks
Each framework lists mapped controls, pass/fail counts, and a score derived from live results.
Custom frameworks
Owners and admins author tenant frameworks: sections, controls, guidance, and a mapping to any implemented rule or to a manual attestation with owner, due date, justification, and attached evidence. Clone a built-in, import JSON or CSV, and keep every published version.
Evidence packs, not screenshots
One ZIP per framework, scope, and point in time: a PDF summary, per-control evidence (failing findings, passing resources, attestations, rule definitions), controls.csv, evidence.json, and a SHA-256 manifest signed with an Ed25519 key. Monthly or quarterly schedules email owners and admins.
Scores move with each scan
Each scan you run or schedule re-evaluates controls, and scores move. No separate “compliance product” with stale attestations.
Honest scope
Built-in mappings cover the high-signal rules each collector implements, and a custom framework can only map rules that exist — unknown rule ids are rejected. Controls no rule can check are attested by a person, and say so in the evidence pack.
In this module
Step 1
Scan as usual
Compliance evaluation runs after posture findings are written.
Step 2
Review framework scores
Open Compliance. Drill into a framework key for control-level results.
Step 3
Hand over evidence
Generate an evidence pack for the framework, cloud, or account in scope. The auditor checks the manifest hashes and signature; downloads are in the audit log.
In this release
- Twelve frameworks mapped to live findings, including CIS Azure and GCP subsets, DPDP, and an AI workload baseline
- Custom frameworks with versioning, manual attestations, and JSON / CSV import and export
- Signed evidence packs (PDF, CSV, JSON, attachments) on demand or monthly / quarterly
- CSV export and scores on Overview
On the roadmap
- Continuous control monitoring SLAs
Labeled roadmap for this module only. Site-wide scope is on Trust and FAQ.
More of the platform
Other modules — not a reprint of this page.
AI security
AI workload security
Trace attack paths to models and agents on SageMaker, Bedrock, Azure AI Foundry and Vertex AI — exposed notebooks, public training data, model weights anyone can swap, retrieval sources fed from public buckets, and workload identities with admin rights.
Code security
Agentless code-to-cloud security
Check Terraform, CloudFormation, ARM, and Kubernetes YAML against built-in pattern rules — in the console or on every pull request — then see the same risk classes on live AWS, Azure, GCP, Kubernetes, and other VPS.
CSPM
Cloud Security Posture Management
Misconfiguration and identity-risk checks across AWS, Azure, GCP, Kubernetes, and other VPS — AWS-first, re-checked on every scan you run or schedule.
CWPP
Cloud Workload Protection
Inventory VMs, Lambda functions, and hosts from the control plane, and look inside VM disks with opt-in, agentless DeepScan.
CIEM
Cloud Identity & Access
AWS IAM, Azure Entra ID and GCP service accounts: missing MFA, standing admins, and effective Azure permissions that can reach sensitive data.
Containers
Container & Kubernetes Security
EKS, AKS, and any Kubernetes API you connect, ECR scan-on-push, and public services in one queue — agentless by default, with an optional sensor for runtime evidence and deploy-time blocking.
Vulnerabilities
Cloud Vulnerability Management
ECR scan-on-push gaps from the control plane, plus package CVEs from opt-in DeepScan or the optional host sensor, prioritized by blast radius.