Pick a framework
GET /compliance/frameworks returns the four supported frameworks (SOC 2, ISO 27001, FedRAMP Low, HIPAA), each with its full control catalogue (code · category · title) and the count of controls.
SOC 2 · ISO · FedRAMP · HIPAA
Continuous-control monitoring that maps every cloud configuration to SOC 2, ISO 27001, HIPAA and FedRAMP Low controls — and produces auditor-grade evidence packs in one click.
By the numbers
SOC 2 · ISO 27001 · FedRAMP Low · HIPAA
0
frameworks reported
10 + 12 + 12 + 11
0
controls auto-evaluated
CSV · JSON · PDF
0
export formats
configurable per report
0
default lookback (days)
How it works
GET /compliance/frameworks returns the four supported frameworks (SOC 2, ISO 27001, FedRAMP Low, HIPAA), each with its full control catalogue (code · category · title) and the count of controls.
SOC 2 · ISO · FedRAMP · HIPAA
POST /compliance/reports/generate?framework=SOC2&lookbackDays=90 evaluates every control against your live posture (audit trail, RBAC, MFA, key rotation, encryption, …) and persists an immutable snapshot with a SHA-256 integrityHash. ADMIN+ only; emits a COMPLIANCE_REPORT_GENERATED audit event.
immutable · signed · audited
GET /compliance/reports/{id}/download?format=csv|json|pdf returns the controls table (code · category · title · status · rationale · gaps) plus the report metadata. ComplianceFreshnessScheduler refreshes the latest snapshots automatically.
CSV · JSON · PDF · auto-refresh
What's inside
Each cloud control (e.g. S3 public access, IAM MFA, KMS rotation, K8s RBAC) is mapped to the relevant SOC 2 / ISO 27001 / HIPAA / FedRAMP control IDs — so a single drift event lights up every framework it affects.
Generate a per-framework evidence pack (PDF + raw JSON + screenshots) for any date range — useful for fieldwork, customer security reviews and certification surveillance audits.
Each evidence artefact has a freshness window. We surface controls whose evidence is about to expire — so the next audit doesn't open with 'this screenshot is 14 months old'.
Capabilities
Before vs after Lumicost
Without Lumicost
With Lumicost
Where teams use it
Stand up evidence collection in under a week and walk into the auditor with a complete pack on day one.
Run SOC 2 + ISO 27001 + HIPAA on the same telemetry without three parallel evidence projects.
Customer asks 'show me your S3 public-access posture last quarter' → exported PDF in 30 seconds.
From the field
“Compliance is not a PDF you produce once a year. Lumicost evaluates 45 controls across SOC 2, ISO 27001, FedRAMP Low and HIPAA against your live posture and signs the snapshot. The auditor downloads the same JSON your engineers do.”
Plays nice with your stack
FAQ
No. We make the auditor's job 10× faster by giving them clean, signed evidence in their preferred format.
Yes — define your own control mappings via a YAML schema. Useful for internal control catalogues and customer-specific addenda.
Connect read-only credentials. First insights in 24 hours. No credit card.
90 seconds · read-only credentials · no credit card