Scuto is launching soon — book a demo to get early access Book demo →
Compliance

Compliance, automated

Map every finding to the frameworks your auditors care about — automatically, continuously, and without spreadsheets. Export audit-ready evidence in SPDX, CycloneDX, CSV, and JSON — all generated within your infrastructure.

10+ supported frameworks

Enable any framework with one click. Controls are mapped automatically from your scan results.

Compliance · Frameworks
Active (2) Available
All Cloud Security Data Privacy Industry Standards Government & Regulatory Threat Intelligence
Search frameworks...
AWS FSBP v2020

Automated security checks for AWS accounts.

Cloud Security
286 controls Enabled
AWS Well-Architected v2023

Best practices for securing AWS workloads.

Cloud Security
57 controls Enable
CIS Benchmarks vMulti

Consensus-based security configuration best practices.

Cloud Security
190 controls Enabled
GDPR 2016/679

EU regulation on data protection and privacy.

Data Privacy
3 controls Enable
HIPAA v2013

US federal law for protecting health information.

Data Privacy
32 controls Enable
ISO 27001:2022 v2022

International standard for information security management.

Industry Standards
6 controls Enable
MITRE ATT&CK v14

Knowledge base of adversary tactics and techniques.

Threat Intelligence
0 controls Enable
NIST 800-53 Rev 5

Security and privacy controls for information systems.

Government & Regulatory
287 controls Enable

Assess every control automatically

Scuto maps findings from all modules to individual framework controls. See exactly where you stand.

Compliance · SOC 2 Type II
← Compliance / SOC 2 Type II

SOC 2 Type II

v2017 (TSC)

Service Organization Control 2 report on security, availability, processing integrity, confidentiality, and privacy of customer data.

Overall
86%
Compliant
Compliant
16
Partial
5
Non-Compliant
1
Not Assessed
0

Controls

22 controls assessed across 8 targets

Search controls...
All Compliant (16) Partial (5) Non-Compliant (1) Not Assessed (0)
Code Control Status Scan Coverage Issues
CC4.1 Monitoring Activities Partial
LoggingHeaders
183 (3 targets)
CC5.1 Control Activities Compliant
Access CtrlAuth
CC6.1 Logical Access Controls Compliant
Access CtrlIDORAuth
CC6.6 External Threat Measures Partial
XSSSQLiCMDiSSRFHeaders
256 (3 targets)
CC7.1 Detection and Monitoring Partial
LoggingXSSSQLi
47 (2 targets)
CC7.2 Anomaly Detection Compliant
LoggingAccess Ctrl
CC8.1 Change Management Non-Compliant
ConfigAuth
12 (1 targets)

Drill into every finding

Click any control to see every finding, affected target, and remediation detail.

Each compliance control links directly to the scan findings that affect it. See which targets are passing, which are failing, and exactly what needs to be fixed.

Findings are mapped across all Scuto modules — cloud misconfigurations, vulnerability scan results, endpoint gaps, and more — giving you a complete picture per control.

CC7.1 Partial

Detection and Monitoring

To meet its objectives, the entity uses detection and monitoring procedures to identify changes to configurations that result in the introduction of new vulnerabilities.

Passing
4
Failing
1
Not Assessed
0
Required Scan Stages
LoggingXSSSQLi
OWASP Categories
A09 LOGGING FAILURES A03 INJECTION
Targets
4 pass 1 fail
aws-production 501664XXXXXX
Partial
Open issues (47)
CloudTrail logging not enabled in region HIGH
arn:aws:cloudtrail:eu-west-1:XXXXXXXXXXXX:trail
CloudTrail logging not enabled in region HIGH
arn:aws:cloudtrail:us-east-2:XXXXXXXXXXXX:trail
GuardDuty detector not active HIGH
arn:aws:guardduty:eu-central-1:XXXXXXXXXXXX:detector
GuardDuty detector not active HIGH
arn:aws:guardduty:ap-northeast-1:XXXXXXXXXXXX:detector
VPC Flow Logs not configured MEDIUM
arn:aws:ec2:us-west-2:XXXXXXXXXXXX:vpc/vpc-0a1b2c3d
+ 42 more issues

Full audit trail for every action

Every event in the platform is logged — who did what, when, and to which resource. Ready for auditor review.

Timestamped log of every user action across your organization
Filter by category, user, and date range
Export logs for SOC 2, ISO 27001, and HIPAA audit evidence
Audit Log 229
All categories
All users
03/07/2026
03/07/2026
Timestamp User Action Details
Mar 7, 11:34 AM Sarah Chen Updated network security config
Mar 7, 10:51 AM Sarah Chen Created network security config cfg-9x8mq2k7p...
Mar 7, 10:26 AM Sarah Chen Accessed billing portal
Mar 6, 01:32 PM James Park Changed alert status 7590-856e-461e...
Mar 6, 01:32 PM James Park Changed alert status 7590-856e-461e...
Mar 5, 10:40 AM James Park Changed alert status cmmay0ybi008t...
Mar 4, 08:40 PM Sarah Chen Switched workspace Production
Mar 4, 05:56 PM Sarah Chen Created workspace Staging
Mar 4, 05:03 PM James Park Requested report FULL report

Export into your compliance platform

Push evidence directly to your Vanta or Drata account, or export in standard formats. You control when and where evidence goes.

Vanta Vanta
Drata Drata
or export as
CSV
JSON
SPDX
CycloneDX
PDF

Key capabilities

From evidence collection to audit-ready reports.

Automated Evidence Collection

Scuto automatically gathers evidence from all modules — cloud, EDR, devices, pentesting, and containers.

Continuous Monitoring

Compliance is assessed continuously, not at a point in time. Know your posture at any moment.

Export-Ready Reports

Generate audit-ready PDF and CSV reports grouped by framework, with evidence included.

Control-to-Finding Mapping

Every finding is automatically mapped to relevant compliance framework controls.

Gap Analysis Dashboard

Visualize compliance gaps across frameworks. See which controls need attention.

10+ Frameworks

ISO 27001, SOC 2, GDPR, HIPAA, PCI DSS, NIST 800-53, CIS Benchmarks, and more.

Ready to simplify compliance?

Start scanning and get your first compliance report in minutes.