Skip to content

Documentation

Everything you need to secure your AI-built projects

Compliance

Features

Compliance reports

Map verified technical scan evidence to PCI DSS 4.0, GDPR, SOC 2, HIPAA, and ISO 27001 controls without claiming certification.

Supported frameworks

PCI DSS 4.0

Team+

Payment Card Industry Data Security Standard. Required if you process, store, or transmit cardholder data. Our scan maps to PCI DSS 4.0 requirements for web application security.

Checks mapped: SSL/TLS strength, security headers, injection prevention, access controls, secret management

GDPR

Team+

EU privacy evidence mapping for consent, policy disclosures, trackers, public legal surfaces, and bounded accessibility basics. Results are technical observations, not a legal opinion or compliance certification.

Checks mapped: Cookie consent, privacy-policy controller/contact/retention/rights, third-party trackers, same-origin Terms availability, and explicit unavailable/needs-auth states

SOC 2

Team+

Service Organization Control 2. Focuses on security, availability, processing integrity, confidentiality, and privacy. Our report maps scan findings to SOC 2 Trust Services Criteria.

Checks mapped: Public session controls, TLS, CORS, security headers, exposed artifacts, and WAF observations

HIPAA

Enterprise+

Technical evidence mapping for selected HIPAA safeguards. A public web scan cannot verify PHI handling, encryption at rest, internal access controls, policies, or legal compliance.

Checks mapped: TLS transport, public session-cookie flags, security headers, CORS, and sensitive-file exposure

ISO 27001

Enterprise+

Technical evidence mapping for selected ISO/IEC 27001:2022 Annex A controls. Organizational, physical, personnel, and ISMS operating evidence remain outside a public web scan.

Checks mapped: TLS cryptography, public network exposure, application headers, CORS, cookies, and exposed artifacts

What's in a report

Each compliance report includes:

Pass, fail, partial, unavailable, and not-checked state per requirement
Detailed mapping of findings to framework controls
Remediation steps for each failed control
Overall assessment score published only after domain verification and complete required scanner coverage
Coverage percentage and unknown-control count shown separately
PDF export for stakeholders Team+
PDF export and dedicated onboarding support Enterprise
Missing evidence is never a pass
A control passes only when every mapped scanner completed with verified evidence and no matching issue was found. Partial, unavailable, and missing scanner runs remain explicit coverage gaps. Findings, per-control evidence, counts, and coverage remain visible immediately. The overall score stays unavailable until domain verification and all required scanners complete.

Generate from the dashboard

From the scan results page

After any completed security scan, open the results page, click the Compliance tab and select a framework. The report immediately includes available verified evidence and findings. Verify the domain to run the six heavier scanners and finalize the aggregate score.

Generate via the API

Request a report for any completed scan by passing the framework as a path segment.

http
GET /api/v1/scans/{scanId}/compliance/GDPR
Authorization: Bearer bsk_your_key
Available frameworks
Team API keys can request PCI_DSS_4, GDPR, or SOC2. Enterprise adds HIPAA and ISO27001.

Need compliance reports?

Available on Team (€249/month) and Enterprise (contact sales) plans.