compliance as code
Compliance evidence, structured.
Compscan centralizes technical evidence, evaluates a disclosed set of framework mappings, and produces reviewable reports. It reports what it can prove — and names what it can't.
$ compscan scan --frameworks iso27001,soc2,nist
[ok] 12 starter controls loaded
[unknown] 3 controls missing evidence
[fail] 1 technical check failed
_run report --format pdf
Other tools would show 15/16. We show 12 confirmed, 3 unknown, 1 failed.
Coverage
starter
Evidence
on sync
Reports
review
What is Compscan?
Compscan is a compliance automation platform for engineering and security teams. Instead of manually collecting evidence across cloud services, repositories, and ticket systems, teams connect once and continuously evaluate controls against their required frameworks. Compscan is one part of ScanComb — alongside free open-source tools and hands-on professional services.
Start where you are
Three levels of depth, one place — enter at whichever tier fits you today.
Tier 1
Start free
SentryHive and CostHive — free, open-source AWS orchestration tools. No account required.
Explore open sourceTier 2
Automate
Compscan runs scoped technical checks against starter SOC 2, ISO 27001, NIST CSF, and CIS mappings.
Get startedTier 3
Get expert help
DevSecOps engineering, threat analysis, and security advisory — human expertise on top of the platform.
Talk to our teamHow it works
01
Connect
Link your cloud accounts and repositories with least-privilege, read-only access.
02
Collect
Gather machine-verifiable evidence when connected systems are synchronized.
03
Evaluate
Map evidence to control statements. Report confirmed passes and failures separately from unknown, stale, conflicting, and manual outcomes.
04
Report
Generate review packages and track progress while keeping human sign-off in the loop.
We won't guess.
Most compliance tools give you two states: pass, or not yet. Everything ambiguous gets rounded toward green, because green is what sells. Compscan reports six states — and never lets four of them become a pass.
Confirmed
Verified against current evidence. These are the only states we count.
Pass
Verified by current evidence within its freshness window.
Fail
Verified as not meeting the control.
Not confirmed — never counted as a pass
Ambiguous or excluded. Surfaced by name, never rounded toward green.
Unknown
No evidence found. Not assumed compliant.
Stale
Evidence exists but has aged past its limit.
Conflict
Scanners disagree. Surfaced, not silently resolved.
Manual
Requires human evidence. Excluded from automated claims.
Error
The check itself failed to run.
Unknown never becomes pass. Stale never becomes pass. Conflicting never becomes pass.Not by default, not with AI, not to make a number look better.
Frameworks supported
One connection, many frameworks.
Integrations
Provider integrations for source, cloud, and operational signals.
Why engineering teams choose Compscan
Read-only by default
Least-privilege integration model keeps your production systems safe while still producing verifiable evidence.
Evidence-grade output
Every check is timestamped and traceable, so audit exports are evidence packs, not screenshots and guesswork.
Unknown is a state, not a rounding error
When evidence is missing, stale, or contradictory, Compscan says so. Four states can never become a pass — no defaults, no inference, no AI override. The number you show an auditor is the number we could prove.
See the seven statesAI that explains, never decides
AI drafts mappings, explains conflicts, and suggests fixes. It cannot mark a control as passing. Compliance states are computed by deterministic code and confirmed by humans — every time.
Not sure which certification you need?
Use the compliance advisor to answer a few practical questions and get a prioritized, market-aware recommendation.
Try the advisorShip compliance with confidence
Get started now. Read-only integrations, scoped checks, and reviewable output.