Continuous compliance

Prove control before audit time.

Compliance is preventive security, not a standalone GRC exercise. Policy is enforced before a fix ships, checked again in live infrastructure, and turned into evidence auditors can use.

Six frameworks built in
137 policies evaluated
Pre and post-deploy gates
Auditor-shareable evidence

ops0 is preventive cloud security. Continuous compliance enforces policy checks before deployment and scans live infrastructure afterward, producing audit evidence across six frameworks: SOC 2 Type II, CIS, ISO 27001, ISO 27002, HIPAA, and GDPR.

ops0.ai/features/compliance
ops0 compliance overview for a production AWS estate: overall risk, 220 of 241 controls passing, per-framework coverage, recommended remediation actions ranked by severity, top resource types, and recent compliance scans
6
Frameworks
built in
137
Policies
evaluated
47
SOC 2 controls
cross-mapped to ISO 27001
2
Scan points
pre and post-deploy
Shareable
Evidence
for auditors
Policy lifecycleEnforced
Pre-deploy gateBlocked public database exposure
Post-deploy scan3,800 resources, continuous
Controls passing220 of 241
Risk
Low
Posture
91%
Open findings
21
Live scan
Continuous
Shift left, watch always

Policy, before and after deploy.

Pre-deploy gates block bad changes before they ship.
State-based scans watch live infrastructure after deploy.
The same policy engine runs before and after.
Framework coverage137 policies
SOC 2 Type II92%
CIS93%
ISO 2700187%
ISO 2700290%
HIPAA91%
GDPR88%
Controls passing
220 / 241
across 3,800 resources
Cross-mapped controls
47
SOC 2 to ISO 27001
Frameworks, mapped

Six frameworks, mapped.

Six compliance frameworks built in.
137 policies evaluated across clouds, Kubernetes, and configuration.
47 SOC 2 controls cross-mapped to ISO 27001.
Shareable reportReady
Q2 compliance snapshot, generated
Report IDRPT-48213
AccessPassword-protected link
FormatPDF export
Generated
2 minutes ago
Expires
30 days
Access log
Enabled
Revocation
Available
Evidence

Auditor-ready evidence.

Evidence exists before the auditor asks.
Export as a PDF or a ZIP of documents.
Share via password-protected links with access logging.
Coverage

Six frameworks, one policy engine.

SOC 2 Type II

Trust service criteria across security, availability, and confidentiality, checked continuously, not once a year.

CIS

Benchmark hardening checks for cloud accounts, operating systems, and Kubernetes clusters.

ISO 27001

Information security management controls, cross-mapped to SOC 2 so one fix closes both.

ISO 27002

Detailed security control guidance layered on top of the ISO 27001 management system.

HIPAA

Safeguards for infrastructure that stores, processes, or transmits protected health information.

GDPR

Data protection controls for infrastructure handling personal data of EU residents.

Common questions

ops0 evaluates infrastructure changes against policy and compliance checks before deployment and continues scanning live cloud state afterward.

Make compliance
continuous, not ceremonial.

Evidence should already exist before the auditor asks. The same policy engine that gates deploys keeps live infrastructure in view.

Explore Deployments