Turn security findings into evidence your team can review.
Compliance work fails on evidence collection, not on knowing the controls. Retrievy maps what it already found in your systems to the frameworks you report against, so the evidence is a by-product of the security work rather than a separate project.
From finding to reviewable evidence
The same four stages the methodology describes, viewed from the auditor request end.
-
1
Observed
A finding exists
Collected configuration shows a condition: an unsigned protocol, an over-permissioned identity, a policy with no inspection profile.
-
2
Mapped
It maps to controls
The finding is associated with the control objectives it is evidence for, across every framework you have enabled.
-
3
Owned
It gets an owner
Remediation is assigned and tracked, so the evidence includes who acted and when, not only what was wrong.
-
4
Confirmed
A scan confirms it
The closing evidence is a later collection showing the condition gone. That is what makes the record reviewable rather than self-reported.
Frameworks supported today
Findings map to CIS Controls, NIST CSF 2.0, NIST SP 800-53, ISO/IEC 27001, PCI DSS, SOC 2, HIPAA, MITRE ATT&CK and others, alongside CIS Benchmarks for the specific platforms assessed. Framework Builder additionally lets a team publish its own versioned catalog when an internal or customer-specific standard needs the same treatment.
Enabling a framework changes how findings are presented, not which findings exist. Turning one on never creates or removes a finding.
What an auditor actually receives
A control view listing the findings mapped to each objective, their severity, their current status, the owner of any remediation, and the scan that verified the fix. Where an exception was accepted, the justification, owner and expiry travel with it.
The point is traceability. Every line refers back to something collected from a named source at a known time, which is the property that survives a reviewer asking "how do you know".
Where mapping stops
Retrievy assesses the sources you connect. Controls about people, contracts, physical premises, training or governance processes are outside what any configuration scanner can observe, and Retrievy does not assess them. A control with no technical evidence source is outside the mapping, and Retrievy never treats it as satisfied on the grounds that nothing contradicted it.
A compliance score is a view of mapped evidence, not a legal attestation. It tells you how the evidence you have looks against a framework, and nothing about the controls no scanner can see.
What the compliance view does not claim
- A compliance score is a view of mapped evidence, not a legal attestation.
- Retrievy is not an auditor, an assessor, or a certification body, and produces no attestation.
- Controls with no technical evidence source are outside the mapping entirely, and are never treated as passing.
- Framework mappings are interpretations of how a finding relates to a control objective, not one-to-one legal equivalences.
- Enabling a framework never changes which findings exist, only how they are grouped.
Frequently asked questions
- Can Retrievy make us ISO 27001 or PCI DSS certified?
- No. Certification is granted by an accredited body after an audit of a defined scope, including many controls no scanner can observe. Retrievy organizes the technical evidence those audits ask for. A compliance score is a view of mapped evidence, not a legal attestation.
- What happens to controls Retrievy cannot see?
- They fall outside the mapping. A control about staff training or vendor contracts has no configuration evidence to collect, and treating it as satisfied because nothing contradicted it would be the single most misleading thing this view could do.
- Do we need to pick one framework?
- No. A finding maps to every enabled framework at once, because the same collected fact is evidence for several control objectives. Teams reporting against more than one standard get both views from one scan.
- Can we add our own control catalog?
- Yes. Framework Builder publishes versioned custom catalogs inside the Compliance Hub, which is how internal standards and customer-specific requirements get the same mapping and evidence treatment as the built-in frameworks.
Related resources
Stop rebuilding evidence by hand every cycle.
Connect a source read-only and see the findings, their control mappings, and the verification record together.