runs in your browser5 frameworksover the audit graphApache-2.0 · zero-dep

Turn the audit chain into auditor evidence.

EcoCloud already hash-chains every agent action. This maps that signed log onto the published control clauses of the framework your buyer's auditor speaks — SOC 2, ISO/IEC 27001:2022, FDA 21 CFR Part 11, NIST SP 800-171, or the HIPAA Security Rule — and reports, per control, the evidence count, what's covered, and what gaps remain. Pick your vertical's framework below. Honest scope: it's evidence mapping for your auditor, not a certification, and it never asserts a cert is held; a control with no evidence is a gap, never a clean bill.

Framework
control coverageSOC 2
coverage
controls covered
gaps

Honest scope. A deterministic evidence mapper — it classifies your audit events onto the published control clauses of each standard (e.g. SOC 2 CC6.3, ISO A.5.18, 21 CFR 11.10(g), NIST 3.1.2, HIPAA 164.308(a)(4)) and reports coverage + gaps. The crosswalk is factual — public control text ↔ a primitive EcoCloud actually enforces — but it does not issue a certification (only a licensed auditor does), does not assert any cert is held, and does not collect the log. FAIL-CLOSED — a control with fewer than min_evidence matching events is a gap, an empty or garbled log yields all-gaps, and an event with no action contributes nothing. Where a framework has no clause for a family (21 CFR Part 11 has no incident/recovery control), it's omitted rather than faked. Source: flowdesk-compliance-kernel.js · conformance suite.