What Compliance Platform gives your team
These capabilities map to the Compliance Platform workspace in YottaBot — Programs (Frameworks, Controls, Audits), Automation (Evidence Tasks, Schedules), Work (Investigations, Findings), Documents (Evidence, Reports, Policies), and Settings — all governed by the same identity, policy, and audit as the rest of the control plane
- 01Framework & control packsSOC 2-first framework packs that map external requirements to normalized controls — so one evidence task can satisfy CC6.1 for SOC 2 and the matching ISO 27001 and HIPAA controls at once. Packs are data, not hard-coded pages
- 02Scheduled evidence collectionDaily, weekly, monthly, quarterly, or annual evidence tasks keep proof fresh — with period windows, due dates, owners, reviewers, run-now overrides, and stale/missing-evidence alerts, so nothing quietly expires between audits
- 03Compliance investigationsMissing, stale, or failed evidence — or a failed control — launches a governed investigation that walks Context, Identity, Issues, and logs to explain the gap and what to do next, writing each hop as it goes
- 04Evidence-backed findingsFindings are first-class compliance records — severity, confidence, status, affected control, cited evidence, and a recommendation — and can open or link a remediation ticket in Issues so the fix is tracked where your team already works
- 05Downloadable evidence packetsExport an immutable ZIP or JSON packet with a manifest, checksums, control mappings, collection period, collector metadata, review state, and citations — auditor-ready, and re-generated as a new snapshot rather than mutated when evidence changes
- 06Reports & policiesPolicy documents and human-readable reports live in the native Documents product, curated by directory or tag — kept beside the evidence and findings they support, versioned in one knowledge base rather than a parallel document store
- 07Governance & deployment targetsPrefixed compliance permissions, evidence scope, approval gates, and a deployment-target cluster/namespace on every run. Agents collect and investigate; they never read raw secret values, bypass resource grants, or run broad privileged scans