Skip to content
Compliance evidence

Turn security findings into evidence your team can review.

Compliance work fails on evidence collection, not on knowing the controls. Retrievy maps what it already found in your systems to the frameworks you report against, so the evidence is a by-product of the security work rather than a separate project.

How evidence flows

From finding to reviewable evidence

The same four stages the methodology describes, viewed from the auditor request end.

  1. 1 Observed

    A finding exists

    Collected configuration shows a condition: an unsigned protocol, an over-permissioned identity, a policy with no inspection profile.

  2. 2 Mapped

    It maps to controls

    The finding is associated with the control objectives it is evidence for, across every framework you have enabled.

  3. 3 Owned

    It gets an owner

    Remediation is assigned and tracked, so the evidence includes who acted and when, not only what was wrong.

  4. 4 Confirmed

    A scan confirms it

    The closing evidence is a later collection showing the condition gone. That is what makes the record reviewable rather than self-reported.

Frameworks supported today

Findings map to CIS Controls, NIST CSF 2.0, NIST SP 800-53, ISO/IEC 27001, PCI DSS, SOC 2, HIPAA, MITRE ATT&CK and others, alongside CIS Benchmarks for the specific platforms assessed. Framework Builder additionally lets a team publish its own versioned catalog when an internal or customer-specific standard needs the same treatment.

Enabling a framework changes how findings are presented, not which findings exist. Turning one on never creates or removes a finding.

What an auditor actually receives

A control view listing the findings mapped to each objective, their severity, their current status, the owner of any remediation, and the scan that verified the fix. Where an exception was accepted, the justification, owner and expiry travel with it.

The point is traceability. Every line refers back to something collected from a named source at a known time, which is the property that survives a reviewer asking "how do you know".

Where mapping stops

Retrievy assesses the sources you connect. Controls about people, contracts, physical premises, training or governance processes are outside what any configuration scanner can observe, and Retrievy does not assess them. A control with no technical evidence source is outside the mapping, and Retrievy never treats it as satisfied on the grounds that nothing contradicted it.

A compliance score is a view of mapped evidence, not a legal attestation. It tells you how the evidence you have looks against a framework, and nothing about the controls no scanner can see.

Boundaries

What the compliance view does not claim

  • A compliance score is a view of mapped evidence, not a legal attestation.
  • Retrievy is not an auditor, an assessor, or a certification body, and produces no attestation.
  • Controls with no technical evidence source are outside the mapping entirely, and are never treated as passing.
  • Framework mappings are interpretations of how a finding relates to a control objective, not one-to-one legal equivalences.
  • Enabling a framework never changes which findings exist, only how they are grouped.
Questions

Frequently asked questions

Can Retrievy make us ISO 27001 or PCI DSS certified?
No. Certification is granted by an accredited body after an audit of a defined scope, including many controls no scanner can observe. Retrievy organizes the technical evidence those audits ask for. A compliance score is a view of mapped evidence, not a legal attestation.
What happens to controls Retrievy cannot see?
They fall outside the mapping. A control about staff training or vendor contracts has no configuration evidence to collect, and treating it as satisfied because nothing contradicted it would be the single most misleading thing this view could do.
Do we need to pick one framework?
No. A finding maps to every enabled framework at once, because the same collected fact is evidence for several control objectives. Teams reporting against more than one standard get both views from one scan.
Can we add our own control catalog?
Yes. Framework Builder publishes versioned custom catalogs inside the Compliance Hub, which is how internal standards and customer-specific requirements get the same mapping and evidence treatment as the built-in frameworks.

Stop rebuilding evidence by hand every cycle.

Connect a source read-only and see the findings, their control mappings, and the verification record together.