Compliance + Reporting

Generate audit-ready reports from scan findings. PCI DSS, HIPAA, SOC 2, ISO 27001, GDPR — and your own custom frameworks.

Frameworks supported

PCI DSS 4.0
HIPAA Security Rule
SOC 2 (Trust Services Criteria)
ISO 27001:2022
GDPR (Article 32)
NIST CSF 2.0
OWASP ASVS Level 1/2/3
CIS Critical Security Controls
Custom (BYO mapping)

Each framework comes with a control mapping that ties Sectora findings + scan coverage to specific clauses. For example, PCI DSS Requirement 6.5 ("Address common coding vulnerabilities") maps to SAST findings in the OWASP Top 10 categories.

Generating a report

  1. Compliance → + New report
  2. Pick framework + scope (specific projects, or org-wide)
  3. Pick time window (last 30/90 days, custom range)
  4. Pick format: PDF (auditor-ready), CSV (raw data), JSON (machine-parseable)
  5. Generate. Reports render asynchronously; download from the same page when ready.

Generation typically takes 30 seconds to 5 minutes depending on finding volume. Reports are retained for 1 year and can be re-downloaded.

What's in a report

A standard PDF report contains:

  • Executive summary — single-page overview suitable for the auditor or board. Risk posture, trends, top categories.
  • Control mapping table — every framework clause, the Sectora signals that demonstrate compliance, and the current pass/fail state.
  • Finding inventory — every open + accepted-risk finding, grouped by severity, with disposition (open / in_progress / SLA-status).
  • Coverage section — what assets are being scanned, scan frequency, scan engine coverage matrix.
  • Audit trail — every config + decision change in the report window (mark-FP, accept-risk, role grants, scan triggers).
  • Remediation summary — findings closed in the period; mean-time-to-resolution per severity.
  • Outstanding risks — findings approaching or breaching SLA.

Continuous compliance

Sectora's scan engines double as continuous-compliance evidence. PCI 6.6 ("Address public-facing web app vulnerabilities") is satisfied by ongoing DAST scans. SOC 2 CC7.1 ("Identify configuration changes") is satisfied by Sectora's audit log. The auditor accepts Sectora's report rather than you assembling evidence manually.

Custom frameworks

Bring your own control framework — common for industry-specific compliance (e.g. specific banking regulators, FedRAMP).

  1. Compliance → Frameworks → + Custom framework
  2. Define your controls (CSV or JSON import)
  3. Map each control to Sectora signals — "clause X.Y requires zero open Critical SAST findings on assets tagged production" → editor builds the query
  4. Save. The framework now appears in the report dropdown alongside the standard ones.

SLA + continuous monitoring

Many frameworks require time-bound remediation (PCI 6.5: critical vulns fixed within 30 days). Sectora enforces this via per-severity SLAs:

  • Set SLA targets at Settings → SLA (default: Critical 48h, High 7d, Medium 30d, Low 90d).
  • Findings nearing breach trigger escalation alerts (Slack / PagerDuty).
  • Breached findings appear on the Compliance dashboard and in reports.
  • Trend data shows SLA adherence over time — a key metric in audit conversations.

Evidence collection for auditors

When the auditor wants to see specific evidence, Sectora can grant them read-only Auditoraccess (Settings → Team → Invite as Auditor). They see findings + audit log + reports but can't change anything. Their access is logged and tied to their email.

Alternative: export-only mode (no login required) — generate the report + a signed verification URL. The auditor verifies the report wasn't tampered with via Sectora's public verification endpoint.

Data residency + retention

For GDPR, regulated industries, etc.:

  • EU-only data residency option (Enterprise) — scans + findings + audit log stored exclusively in eu-west.
  • Data retention policies per data class (findings, audit log, scan traces) configurable at Settings → Data Retention.
  • DSAR support — Sectora exports all data associated with a specific user email within 30 days of request.

What's next