Back to home

Reporting

Compliance Exports

Structured evidence packs mapped to CIS Controls v8, ISO 27001 Annex A, and SOC 2 Trust Services Criteria, generated from the same monitoring data the dashboard shows and formatted for direct handoff to your auditor.

Supported frameworks

CIS Controls v8

Findings and coverage mapped to Controls 2 (Inventory and Control of Software Assets) and 10 (Malware Defenses). Each report identifies which controls are satisfied and which have open findings.

ISO 27001 Annex A

Coverage of A.8.19 (installation of software on operational systems), A.8.32 (change management - version diffs and supply chain events), A.8.16 (monitoring activities), A.5.23 (information security for cloud service use), and A.6.8 (information security event reporting). Structured for direct handoff to your ISO auditor.

SOC 2 Type II

Evidence mapped to CC6.8 (controls to prevent or detect unauthorised software), CC6.1 (logical access controls and approved extension lists), CC7.2 (monitoring for anomalies), and CC9.2 (vendor and supply chain risk). Built to give a Type II auditor reproducible evidence for the browser-extension control set over a 12-month observation period - request a sample pack to review the format before you commit.

What's in an evidence pack

  1. 01Risk-scored extension inventory across your full fleet
  2. 02Coverage statement confirming which devices were monitored and for what period
  3. 03Per-extension findings with supporting technical evidence
  4. 04Remediation status for each finding (open, in review, resolved)
  5. 05Policy enforcement log for the audit period
  6. 06Methodology summary describing our analysis approach and confidence levels
  7. 07Executive summary written for non-technical reviewers

Exports are point-in-time snapshots

A dashboard view can change tomorrow; an auditor needs evidence that stays put. Each export is a point-in-time snapshot with methodology documentation your auditor can rely on. If your auditor has specific evidence requirements, email us and we will work through them.

Request a sample evidence pack.

Email us your framework requirements.