The audit becomes a query rather than a project
Evidence tagged as it is recorded means the sampling period is already covered. Reconstruction — frequently the dominant cost of an audit — stops being necessary.
Map every event to the frameworks your auditors care about.
Compliance evidence is cheapest when it is a by-product of controls that are already operating. GuardsArm tags events against frameworks as they are ingested.

What is at stake
Audit evidence assembled retrospectively is expensive, fragile, and discovered to be incomplete at the worst possible moment.
Evidence tagged as it is recorded means the sampling period is already covered. Reconstruction — frequently the dominant cost of an audit — stops being necessary.
The distinction a careful assessor probes is between a documented control and one that provably ran every day of the period. Only the second survives.
A live posture view means a control failing in month two is found in month two, rather than during the assessment when the period is already closed.
Who carries this
Compliance and audit, funded on the basis that certification is a sales prerequisite rather than a security one.
The problem
The familiar pattern: an audit is scheduled, the assessor names a sampling period, and a team spends weeks reconstructing what happened during it from logs that were retained for operational reasons rather than evidentiary ones. The output is a report that is technically accurate and enormously expensive to produce.
It is also fragile. Reconstruction can only work with what survived, and retention policies are rarely set with an auditor’s sampling window in mind. The gap is discovered during the audit, which is the worst possible time to discover it.
Tagging at ingest inverts this. When every event carries its framework relevance from the moment it is recorded, evidence for any period in retention already exists. The audit becomes a query against data you were always collecting rather than a project to recover it.
There is a difference between demonstrating that a control is documented and demonstrating that it operated every day of the period. Only one of those survives a careful auditor.
Capabilities
Events carry tags for PCI DSS, GDPR, HIPAA, NIST 800-53, TSC and GPG13, so evidence for a control is a query rather than a manual collection exercise.
Posture across the tagged frameworks, showing where coverage exists and where it does not.
An evidence library plus generated compliance reports, which is what turns an audit from a scramble into an export.
How it fits the platform
Because tagging happens at ingest rather than at report time, evidence exists for the whole period an auditor samples — which is the distinction between a control that is documented and one that demonstrably operated.
How it works
Every event is tagged with the frameworks and controls it is relevant to as it is decoded and normalised — not when a report is generated. This is the entire argument of the module in one sentence.
Compliance posture is a live view over tagged events rather than a quarterly exercise. The gap you find in month two is a gap you can still close before the audit period ends.
Evidence is collected as it occurs and held against the control it supports. When an auditor samples a date, the records for that date already exist — they are not reconstructed from whatever survived retention.
Compliance reports draw on the tagged event store directly, so what the report says and what the platform recorded cannot diverge. Reports can be scheduled and produced as PDFs for distribution.
Why it matters
| Aspect | Mapped when the report is written | Tagged at ingest — GuardsArm |
|---|---|---|
| When the mapping is decided | When someone writes the report, against the data that survived. | As the event is normalised, before anything ages out. |
| What an auditor sampling a random week gets | Whatever can be reconstructed now for a week nobody was tagging then. | The tagged records for that week, as they were recorded at the time. |
| Effort at audit time | A project. Frequently the dominant cost of the audit. | A query. |
| What is being demonstrated | That a control is documented. | That a control demonstrably operated throughout the period. |
Frameworks
Per-event tagging, so the mapping is a property of the record rather than an interpretation applied later.
| Framework | Who it applies to | Where the platform contributes |
|---|---|---|
| PCI DSS | Anyone handling cardholder data | File integrity monitoring, access logging, configuration assessment and retention are all directly named controls. |
| HIPAA | Healthcare and business associates | Audit controls and access records over systems holding protected health information — which on-premises deployment keeps inside your network boundary. |
| GDPR | Anyone processing EU personal data | Security of processing and breach-detection obligations, plus the data-residency argument that self-hosting makes straightforward. |
| NIST 800-53 | Federal systems and their suppliers | Audit and accountability, system integrity and incident response control families. |
| TSC | SOC 2 reporting organisations | The Trust Services Criteria behind a SOC 2 report — monitoring, logical access and change management evidence. |
| GPG13 | UK public sector and suppliers | Protective monitoring controls, which map closely onto what the platform already collects. |
Self-hosting carries a compliance argument of its own: for several of these, the simplest answer to a data-residency or third-party-processing question is that the telemetry never left your infrastructure.
Terms
The accumulated record of control operation, held against the control it supports. An auditor asks for a sample from a period; this is where the sample comes from.
A live view of where you stand against each framework, derived from tagged events rather than from a self-assessment questionnaire.
Framework relevance recorded on the event itself at ingest. The property that makes everything else on this page possible.
The platform produces evidence of technical control operation. It does not write your policies, run your risk assessment or replace an assessor — and a vendor claiming otherwise should be read carefully.
Background
Plain explainers on the underlying ideas, written for someone evaluating rather than buying.
Questions
Per-event tagging for PCI DSS, GDPR, HIPAA, NIST 800-53, TSC and GPG13, with posture views, an evidence library and generated reports.
No, and the distinction matters. Frameworks specify minimums and are assessed periodically against documentation. What the tagging gives you is evidence that controls operated across the period an auditor samples, which is a different and more defensible claim.
At ingest rather than at report time, so evidence exists for the whole period rather than being assembled before an audit. Assembling evidence specially is both expensive and a signal that the control is documented rather than operated.
Works with
Every module runs in the same self-hosted stack and shares the same telemetry, severity model and response engine.
We will walk through the console, the deployment model and what it takes to stand it up in your environment.