solutions · compliance & audit

Audit evidence that collects itself.

The same agent that watches your servers maps what it sees to PCI DSS 4.0 and SOX ITGC controls: file integrity, access logging, privileged actions, change records. When the auditor asks, the evidence is already there - continuous, attributed, and exportable as a report.

Free plan · no card · commercial use allowed

sound familiar?

Audits are painful because evidence is an afterthought.

The screenshot hunt

The month before the audit becomes a scramble to reconstruct proof of things that were true all year. Continuous collection means the evidence exists the moment the control operates, not when someone remembers to capture it.

Controls without proof

The policy says access is logged and changes are reviewed. The auditor wants to see it - per host, with timestamps. Events are mapped to the specific control they satisfy, so the answer is a report, not a meeting.

Changes nobody can explain

A config file changed in scope and nobody knows who, when, or why - that is a finding. Every SSH session, command, and file change is attributed and checked against authorized maintenance windows.

what you get

Continuous evidence, mapped to the frameworks auditors use.

PCI DSS 4.0 Requirement 10 and 11 evidence and SOX Section 302 and 404 ITGC evidence, collected by the same agent that does the security monitoring - one install, both jobs.

Questions compliance teams ask

Which frameworks are covered?
PCI DSS 4.0, with evidence collection mapped to Requirement 10 and 11 controls such as user access logging, admin action logging, authentication failure tracking, and file integrity monitoring. And SOX Section 302 and 404 IT general controls: change detection, access logging, and operations monitoring.
How is the evidence actually produced?
The agent observes events at the kernel with eBPF and maps each one to the control it satisfies. Evidence accumulates continuously per host, and audit-ready PDF reports are generated from it - there is nothing to screenshot or assemble by hand.
Do we have to monitor every server, or just the in-scope ones?
You choose. Many teams point compliance policies at the hosts in their Cardholder Data Environment or SOX scope, and use the same platform for plain monitoring and on-call everywhere else.
Which plan includes compliance evidence?
The Business plan at £149 a month for 25 hosts with 90-day retention includes compliance evidence and reports for PCI DSS and SOX, alongside everything in Professional. Your whole team is included on every plan.

Walk into the audit with the evidence already collected.

Install the agent on your in-scope hosts and evidence starts accumulating today - attributed, mapped to controls, and ready to export.

Start free

free plan · no card · commercial use allowed