SOC 2 Readiness
24/7 Security Monitoring
Canadian-Based SOC
GuardsArm Platform · Govern

Compliance

Map every event to the frameworks your auditors care about.

Compliance evidence is cheapest when it is a by-product of controls that are already operating. GuardsArm tags events against frameworks as they are ingested.

  • PCI DSS · GDPR · HIPAA
  • NIST 800-53 · TSC · GPG13
  • Evidence library
Security events being tagged with compliance framework controls as they are ingested, accumulating into an evidence library and generated reports

What is at stake

Audit evidence assembled retrospectively is expensive, fragile, and discovered to be incomplete at the worst possible moment.

The audit becomes a query rather than a project

Evidence tagged as it is recorded means the sampling period is already covered. Reconstruction — frequently the dominant cost of an audit — stops being necessary.

Demonstrate that a control operated, not merely that it exists

The distinction a careful assessor probes is between a documented control and one that provably ran every day of the period. Only the second survives.

Gaps surface while there is still time to close them

A live posture view means a control failing in month two is found in month two, rather than during the assessment when the period is already closed.

Who carries this

Compliance and audit, funded on the basis that certification is a sales prerequisite rather than a security one.

The problem

Audit evidence is almost always assembled backwards

The familiar pattern: an audit is scheduled, the assessor names a sampling period, and a team spends weeks reconstructing what happened during it from logs that were retained for operational reasons rather than evidentiary ones. The output is a report that is technically accurate and enormously expensive to produce.

It is also fragile. Reconstruction can only work with what survived, and retention policies are rarely set with an auditor’s sampling window in mind. The gap is discovered during the audit, which is the worst possible time to discover it.

Tagging at ingest inverts this. When every event carries its framework relevance from the moment it is recorded, evidence for any period in retention already exists. The audit becomes a query against data you were always collecting rather than a project to recover it.

There is a difference between demonstrating that a control is documented and demonstrating that it operated every day of the period. Only one of those survives a careful auditor.

Capabilities

What the compliance module does

Per-event compliance tagging

Events carry tags for PCI DSS, GDPR, HIPAA, NIST 800-53, TSC and GPG13, so evidence for a control is a query rather than a manual collection exercise.

Compliance posture views

Posture across the tagged frameworks, showing where coverage exists and where it does not.

Evidence library and generated reports

An evidence library plus generated compliance reports, which is what turns an audit from a scramble into an export.

How it fits the platform

Because tagging happens at ingest rather than at report time, evidence exists for the whole period an auditor samples — which is the distinction between a control that is documented and one that demonstrably operated.

How it works

Four stages, and the first one is the whole argument

  1. Tagging happens at ingest

    Every event is tagged with the frameworks and controls it is relevant to as it is decoded and normalised — not when a report is generated. This is the entire argument of the module in one sentence.

  2. Posture views aggregate continuously

    Compliance posture is a live view over tagged events rather than a quarterly exercise. The gap you find in month two is a gap you can still close before the audit period ends.

  3. The evidence library accumulates

    Evidence is collected as it occurs and held against the control it supports. When an auditor samples a date, the records for that date already exist — they are not reconstructed from whatever survived retention.

  4. Reports are generated from the same data

    Compliance reports draw on the tagged event store directly, so what the report says and what the platform recorded cannot diverge. Reports can be scheduled and produced as PDFs for distribution.

Why it matters

Tagging at ingest against tagging at report time

AspectMapped when the report is writtenTagged at ingest — GuardsArm
When the mapping is decidedWhen someone writes the report, against the data that survived.As the event is normalised, before anything ages out.
What an auditor sampling a random week getsWhatever can be reconstructed now for a week nobody was tagging then.The tagged records for that week, as they were recorded at the time.
Effort at audit timeA project. Frequently the dominant cost of the audit.A query.
What is being demonstratedThat a control is documented.That a control demonstrably operated throughout the period.

Frameworks

The six frameworks events are tagged against

Per-event tagging, so the mapping is a property of the record rather than an interpretation applied later.

FrameworkWho it applies toWhere the platform contributes
PCI DSSAnyone handling cardholder dataFile integrity monitoring, access logging, configuration assessment and retention are all directly named controls.
HIPAAHealthcare and business associatesAudit controls and access records over systems holding protected health information — which on-premises deployment keeps inside your network boundary.
GDPRAnyone processing EU personal dataSecurity of processing and breach-detection obligations, plus the data-residency argument that self-hosting makes straightforward.
NIST 800-53Federal systems and their suppliersAudit and accountability, system integrity and incident response control families.
TSCSOC 2 reporting organisationsThe Trust Services Criteria behind a SOC 2 report — monitoring, logical access and change management evidence.
GPG13UK public sector and suppliersProtective monitoring controls, which map closely onto what the platform already collects.

Self-hosting carries a compliance argument of its own: for several of these, the simplest answer to a data-residency or third-party-processing question is that the telemetry never left your infrastructure.

Terms

Including the boundary

Evidence library

The accumulated record of control operation, held against the control it supports. An auditor asks for a sample from a period; this is where the sample comes from.

Compliance posture

A live view of where you stand against each framework, derived from tagged events rather than from a self-assessment questionnaire.

Per-event tagging

Framework relevance recorded on the event itself at ingest. The property that makes everything else on this page possible.

Where this stops

The platform produces evidence of technical control operation. It does not write your policies, run your risk assessment or replace an assessor — and a vendor claiming otherwise should be read carefully.

Background

Understand the concept first

Plain explainers on the underlying ideas, written for someone evaluating rather than buying.

Questions

Common questions

Which frameworks are covered?

Per-event tagging for PCI DSS, GDPR, HIPAA, NIST 800-53, TSC and GPG13, with posture views, an evidence library and generated reports.

Does passing these checks mean we are secure?

No, and the distinction matters. Frameworks specify minimums and are assessed periodically against documentation. What the tagging gives you is evidence that controls operated across the period an auditor samples, which is a different and more defensible claim.

When is evidence collected?

At ingest rather than at report time, so evidence exists for the whole period rather than being assembled before an audit. Assembling evidence specially is both expensive and a signal that the control is documented rather than operated.

See Compliance running on your own infrastructure

We will walk through the console, the deployment model and what it takes to stand it up in your environment.