Skip to content

compliance as code

Compliance evidence, structured.

Compscan centralizes technical evidence, evaluates a disclosed set of framework mappings, and produces reviewable reports. It reports what it can prove — and names what it can't.

terminal.live

$ compscan scan --frameworks iso27001,soc2,nist

[ok] 12 starter controls loaded

[unknown] 3 controls missing evidence

[fail] 1 technical check failed

_run report --format pdf

Other tools would show 15/16. We show 12 confirmed, 3 unknown, 1 failed.

Coverage

starter

Evidence

on sync

Reports

review

What is Compscan?

Compscan is a compliance automation platform for engineering and security teams. Instead of manually collecting evidence across cloud services, repositories, and ticket systems, teams connect once and continuously evaluate controls against their required frameworks. Compscan is one part of ScanComb — alongside free open-source tools and hands-on professional services.

Start where you are

Three levels of depth, one place — enter at whichever tier fits you today.

Tier 1

Start free

SentryHive and CostHive — free, open-source AWS orchestration tools. No account required.

Explore open source

Tier 2

Automate

Compscan runs scoped technical checks against starter SOC 2, ISO 27001, NIST CSF, and CIS mappings.

Get started

Tier 3

Get expert help

DevSecOps engineering, threat analysis, and security advisory — human expertise on top of the platform.

Talk to our team

How it works

01

Connect

Link your cloud accounts and repositories with least-privilege, read-only access.

02

Collect

Gather machine-verifiable evidence when connected systems are synchronized.

03

Evaluate

Map evidence to control statements. Report confirmed passes and failures separately from unknown, stale, conflicting, and manual outcomes.

04

Report

Generate review packages and track progress while keeping human sign-off in the loop.

We won't guess.

Most compliance tools give you two states: pass, or not yet. Everything ambiguous gets rounded toward green, because green is what sells. Compscan reports six states — and never lets four of them become a pass.

Confirmed

Verified against current evidence. These are the only states we count.

Pass

Verified by current evidence within its freshness window.

Fail

Verified as not meeting the control.

Not confirmed — never counted as a pass

Ambiguous or excluded. Surfaced by name, never rounded toward green.

Unknown

No evidence found. Not assumed compliant.

Stale

Evidence exists but has aged past its limit.

Conflict

Scanners disagree. Surfaced, not silently resolved.

Manual

Requires human evidence. Excluded from automated claims.

Error

The check itself failed to run.

Unknown never becomes pass. Stale never becomes pass. Conflicting never becomes pass.Not by default, not with AI, not to make a number look better.

Frameworks supported

One connection, many frameworks.

ISO 27001SOC 2NIST CSFCIS Controls
Explore framework details

Integrations

Provider integrations for source, cloud, and operational signals.

AWS
GitHub
GitLab
AzureSoon
GCPSoon

Why engineering teams choose Compscan

Read-only by default

Least-privilege integration model keeps your production systems safe while still producing verifiable evidence.

Evidence-grade output

Every check is timestamped and traceable, so audit exports are evidence packs, not screenshots and guesswork.

Unknown is a state, not a rounding error

When evidence is missing, stale, or contradictory, Compscan says so. Four states can never become a pass — no defaults, no inference, no AI override. The number you show an auditor is the number we could prove.

See the seven states

AI that explains, never decides

AI drafts mappings, explains conflicts, and suggests fixes. It cannot mark a control as passing. Compliance states are computed by deterministic code and confirmed by humans — every time.

Not sure which certification you need?

Use the compliance advisor to answer a few practical questions and get a prioritized, market-aware recommendation.

Try the advisor

Ship compliance with confidence

Get started now. Read-only integrations, scoped checks, and reviewable output.

Read-only accessEvidence-grade exportsEngineering-first UX