Continuous compliance

Prove control before audit time.

Compliance is preventive security, not a standalone GRC exercise. Policy is enforced before a fix ships, checked again in live infrastructure, and turned into a signed audit pack auditors can use.

Six frameworks built in
137 policies evaluated
Pre and post-deploy gates
Auditor-shareable evidence

ops0 brings your clouds, runtime, infrastructure code, and workflows into one operating context. Continuous compliance enforces policy checks before deployment and scans live infrastructure afterward, producing audit evidence across six frameworks: SOC 2 Type II, CIS, ISO 27001, ISO 27002, HIPAA, and GDPR, shared as snapshot reports or signed audit packs for a chosen audit period.

ops0.ai/features/compliance
ops0 compliance overview for a production AWS estate: overall risk, 220 of 241 controls passing, per-framework coverage, recommended remediation actions ranked by severity, top resource types, and recent compliance scans

Audit season is a scramble for evidence. Here the evidence is already there. 

6 frameworks137 policiesBefore and after deployShareable proof
Before and after deploy
01 / 04 · Gate

Checked before it ships.

137 policies run against the plan. One fails: a storage bucket without encryption.

BEFORE DEPLOYLIVEDEPLOYs3 · encryption offencryption enabledconsole change · sg rule widenedresolved same daySOC 20%CIS0%ISO 270010%ISO 270020%HIPAA0%GDPR0%
Going deeper

Compliance that runs, not a checklist.

Shift left, watch always

Policy, before and after deploy.

Pre-deploy gates block bad changes before they ship.
State-based scans watch live infrastructure after deploy.
Policy lifecycleEnforced
Pre-deploy gateBlocked public database exposure
Post-deploy scan3,800 resources, continuous
Controls passing220 of 241
Risk
Low
Posture
91%
Open findings
21
Live scan
Continuous
Under the hood

One policy engine, every framework.

Coverage
Six frameworks, mapped.
SOC 2 Type II92%
CIS93%
ISO 2700187%
ISO 2700290%
HIPAA91%
GDPR88%

One policy engine, checked against SOC 2 Type II, CIS, ISO 27001, ISO 27002, HIPAA, and GDPR at the same time.

Breadth
137 policies.
137
Encryption and access41
Network exposure35
Identity and secrets29
Logging and monitoring32
Cross-mapped
47 SOC 2 controls, cross-mapped.
SOC 2 CC6.1→ISO 27001 A.9.1
SOC 2 CC6.6→ISO 27001 A.8.20
SOC 2 CC7.2→ISO 27001 A.8.16

One fix closes both frameworks at once.

Proof you can share
A report an auditor can open.
AccessPassword-protected link
Expires30 days
Access logViewed 3 times

ops0 itself is SOC 2 Type II.

In the cluster
Kyverno, installed and enforced.
Policy engineKyverno
ClustersConnected
ModeEnforce
Kiwi drafts the rule
Describe the rule, review the draft.
@ops0 block public S3 buckets in prod
Drafted as a Rego policy. It stays off until you enable it.

Common questions

ops0 evaluates infrastructure changes against policy and compliance checks before deployment and continues scanning live cloud state afterward. Describe a rule in plain language and Kiwi drafts the Kyverno policy for your review.

Make compliance
continuous, not ceremonial.

Evidence should already exist before the auditor asks. ops0 keeps policy results, live findings, and deployment records together, ready to share as a signed audit pack.

Explore Deployments