Automated SOC 2 evidence collection from Identity, GitHub, and AWS sources. Evaluates findings against YAML-defined controls and generates audit-ready reports.
Click any component to see implementation details.
collect_evidence(). Uses bearer token auth, handles pagination, and normalizes
output into a standard evidence dict.
check_field, operator,
threshold, and severity.
eval()). Three-tier result: PASS โ WARNING โ FAIL with
human-readable messages.| Control | Name | Status | Severity | Details |
|---|
Controls are defined in YAML โ add new checks without touching code.