Compliance + Reporting
Generate audit-ready reports from scan findings. PCI DSS, HIPAA, SOC 2, ISO 27001, GDPR — and your own custom frameworks.
Frameworks supported
Each framework comes with a control mapping that ties Sectora findings + scan coverage to specific clauses. For example, PCI DSS Requirement 6.5 ("Address common coding vulnerabilities") maps to SAST findings in the OWASP Top 10 categories.
Generating a report
- Compliance → + New report
- Pick framework + scope (specific projects, or org-wide)
- Pick time window (last 30/90 days, custom range)
- Pick format: PDF (auditor-ready), CSV (raw data), JSON (machine-parseable)
- Generate. Reports render asynchronously; download from the same page when ready.
Generation typically takes 30 seconds to 5 minutes depending on finding volume. Reports are retained for 1 year and can be re-downloaded.
What's in a report
A standard PDF report contains:
- Executive summary — single-page overview suitable for the auditor or board. Risk posture, trends, top categories.
- Control mapping table — every framework clause, the Sectora signals that demonstrate compliance, and the current pass/fail state.
- Finding inventory — every open + accepted-risk finding, grouped by severity, with disposition (open / in_progress / SLA-status).
- Coverage section — what assets are being scanned, scan frequency, scan engine coverage matrix.
- Audit trail — every config + decision change in the report window (mark-FP, accept-risk, role grants, scan triggers).
- Remediation summary — findings closed in the period; mean-time-to-resolution per severity.
- Outstanding risks — findings approaching or breaching SLA.
Continuous compliance
Sectora's scan engines double as continuous-compliance evidence. PCI 6.6 ("Address public-facing web app vulnerabilities") is satisfied by ongoing DAST scans. SOC 2 CC7.1 ("Identify configuration changes") is satisfied by Sectora's audit log. The auditor accepts Sectora's report rather than you assembling evidence manually.
Custom frameworks
Bring your own control framework — common for industry-specific compliance (e.g. specific banking regulators, FedRAMP).
- Compliance → Frameworks → + Custom framework
- Define your controls (CSV or JSON import)
- Map each control to Sectora signals — "clause X.Y requires zero open Critical SAST findings on assets tagged production" → editor builds the query
- Save. The framework now appears in the report dropdown alongside the standard ones.
SLA + continuous monitoring
Many frameworks require time-bound remediation (PCI 6.5: critical vulns fixed within 30 days). Sectora enforces this via per-severity SLAs:
- Set SLA targets at Settings → SLA (default: Critical 48h, High 7d, Medium 30d, Low 90d).
- Findings nearing breach trigger escalation alerts (Slack / PagerDuty).
- Breached findings appear on the Compliance dashboard and in reports.
- Trend data shows SLA adherence over time — a key metric in audit conversations.
Evidence collection for auditors
When the auditor wants to see specific evidence, Sectora can grant them read-only Auditoraccess (Settings → Team → Invite as Auditor). They see findings + audit log + reports but can't change anything. Their access is logged and tied to their email.
Alternative: export-only mode (no login required) — generate the report + a signed verification URL. The auditor verifies the report wasn't tampered with via Sectora's public verification endpoint.
Data residency + retention
For GDPR, regulated industries, etc.:
- EU-only data residency option (Enterprise) — scans + findings + audit log stored exclusively in eu-west.
- Data retention policies per data class (findings, audit log, scan traces) configurable at Settings → Data Retention.
- DSAR support — Sectora exports all data associated with a specific user email within 30 days of request.
What's next
- Risk Scoring — how findings get prioritised, which feeds the compliance dashboard.
- Vulnerability Management — the queue compliance reports describe.
- Policy Engine — define your own compliance-driven rules.