Compliance
How DriftGuard maps to DORA, NIS2, ISO 27001, and CIS Benchmarks.
DriftGuard provides an audit-ready trail of every infrastructure change reviewed, blocked, or approved. Findings and policy decisions are timestamped and recorded in the append-only audit log, exportable as CSV to support your DORA evidence file.
Every DriftGuard PR analysis flags findings against NIS2 risk categories. Incident evidence — severity, blast radius, remediation time — is structured for NIS2 reporting.
Checkov findings are mapped to ISO 27001 Annex A controls. Security assessment evidence per PR satisfies A.8.29 requirements without additional tooling.
DriftGuard processes only repository metadata and infrastructure plan output — no user data, no PII. Data residency is EU-only. DPA available on request.
SOC 2 Type II audit scheduled Q4 2026 with Vanta-assisted readiness. CC8 (change management) evidence is already produced as a side effect of every DriftGuard PR review.
Need a compliance evidence export for your auditor? Request one for SOC 2, ISO 27001, DORA, or NIS2 — these are prepared on request, not self-serve.