Skip to content
v3.5.1 — now on Windows and macOS

Compliance, on yourendpoint.

Cloud platforms scan your cloud. ComplianceGuard scans the machines your business runs on — collecting, scoring, and signing SOC 2, ISO 27001, and HIPAA evidence locally. Nothing leaves your network.

Windows 10/11 · macOS 12+ (Intel & Apple Silicon) · ~568 tests passing · Source-available under BSL 1.1

See it in action

Two minutes, start to finish.

Watch ComplianceGuard scan an endpoint, score it against SOC 2, and produce signed evidence — no cloud round-trip required.

Your cloud is covered.
Your endpoints are not.

Cloud compliance platforms see your AWS account. They cannot see the password policy, disk encryption, firewall rules, or event logs on the machines your business actually runs on. That evidence lives on the endpoint — and auditors ask for it. ComplianceGuard lives there too.

0

Controls scored across SOC 2, ISO 27001, and HIPAA — in one collection pass

0

Bytes of evidence leave your network unless you explicitly choose to sync

0 sec

From first scan to a per-control readiness score on the machine itself

How it works

From install to audit-ready,
in minutes.

  1. Install

    Run the installer for Windows or macOS. No admin privileges, no API keys, no agents to deploy.

  2. Scan

    ComplianceGuard reads the OS directly — password policy, firewall, disk encryption, audit logging.

  3. Connect AWS

    Add credentials once, encrypted locally. Cloud evidence joins the same pack automatically.

  4. Hand off

    Export an auditor-ready PDF evidence pack, mapped control-by-control to the framework.

ComplianceGuard — install
$ ./ComplianceGuard-Setup
no admin · no API keys · no agents
Installed in 12s ✓

Output shown is illustrative. Actual results depend on your machine configuration.

The product

Evidence collection,
down to the operating system.

Real-time scoring

Know exactly where you stand.

Your compliance score updates the moment a scan completes. See which of the 54 SOC 2 controls you're passing and which need work — with remediation scripts for the gaps — before you ever engage an auditor.

ComplianceGuard
ComplianceGuard dashboard showing a real-time compliance score, per-category breakdowns, and a per-control heatmap

Endpoint evidence

Reads your machine. Not your cloud.

ComplianceGuard reads directly from the Windows Registry, event logs, firewall configuration, and user accounts — and the macOS equivalents. No agent to deploy. No API key. Evidence collected in about 30 seconds.

ComplianceGuard
ComplianceGuard evidence list with searchable, filterable evidence items and their compliance status

One connection. Automatic cloud evidence.

Connect your AWS account once. IAM configurations, S3 bucket policies, and security settings join the same evidence pack on every scan.

Hand it to your auditor on day one.

Every evidence pack exports as an auditor-ready PDF, mapped control-by-control to the framework. No reformatting. No back-and-forth.

Credentials never leave the machine.

AWS credentials are encrypted at rest with HKDF-SHA256-derived Fernet keys and stored locally. Evidence stays in your local database.

Works without an internet connection.

Evidence collection and reporting run fully offline — built for air-gapped environments and restricted networks.

Frameworks

Three frameworks.
One evidence engine.

The same OS-level evidence collection powers SOC 2, ISO 27001 and HIPAA — mapped directly to the controls auditors actually check.

SOC 2

Type II, fully scored.

54 controls mapped to the SOC 2 Trust Services Criteria, evaluated automatically. The standard for enterprise SaaS deals.

54controls

ISO 27001

Annex A, end to end.

47 controls mapped and scored across all 14 Annex A domains. Required for European enterprise contracts.

47controls

HIPAA

Security Rule, in one pass.

47 safeguards across all five 45 CFR Part 164 sections, required and addressable. Built for health-tech.

47safeguards

Architecture

Nothing leaves your network.
Ever.

Every byte of evidence stays inside the boundary you control. We don’t have a database for your data, because we never see it.

Your network boundary
Your machineRegistry · firewall · disk
Your AWSIAM · S3 · groups
OS configsPolicies · patch level
Event logsAudit trail
Local evidence storeSQLite · encrypted

0

bytes uploaded to our servers

100%

of evidence stays on your machine

AES-256

credential encryption at rest

AICPA TSC-mapped

Every control mapped to the Trust Services Criteria — the exact format auditors accept for SOC 2 Type I and Type II.

Offline-verified licensing

Ed25519 public-key license verification with no license server and no phone-home — coherent with the air-gap story.

Source-available, BSL 1.1

You can read the code that reads your system. Every line of evidence collection and scoring logic is auditable.

How we compare

Different by architecture.

Cloud compliance platforms and ComplianceGuard solve different layers of the same problem. The difference is where the evidence comes from — and where it stays.

CapabilityComplianceGuardVantaDrata
Evidence sourceThe endpoint itselfCloud APIs onlyCloud APIs only
Data stays on your machine
Works offline / air-gapped
Compliance frameworksSOC 2 · ISO 27001 · HIPAASOC 2 · ISO 27001SOC 2 · ISO 27001
Per-seat pricingNo — flat rateYesYes
Setup timeMinutesWeeksWeeks
Source codeBSL 1.1 source-availableProprietaryProprietary
Free tier

Competitor capabilities based on publicly available information as of 2026.

Enterprise · Air-gapped

Built for the rooms
internet doesn’t reach.

Government, defence and regulated finance teams need evidence that proves itself — without phoning home. Ships fully offline with a cryptographic audit trail.

Contact sales

Tamper-evident audit log

Every evaluation, evidence collection and config change is appended to a SHA-256 hash chain. One altered byte breaks the chain — verifiable end-to-end in one request.

RBAC: admin + auditor

Separate read-only auditor accounts. Last-admin lockout guard. First registered user seeded as admin via migration.

NDJSON streaming export

Stream every evidence item, evaluation and audit row as newline-delimited JSON, scoped to the authenticated tenant.

Hardened, air-gapped deploy

Pre-bundled Docker images. Hardened Nginx (TLS 1.2+, HSTS, no server banner). ENTERPRISE_MODE disables telemetry. Zero outbound calls.

audit_log · sha-256 chainverified
#4000x7a3f…b21c
#4010x14de…9f08
#4020xc9b2…5e7d
#4030x4f80…ae33
#4040x2bce…c640
GET /api/v1/enterprise/audit-log/verify{ valid: true }

Pricing

Start free. Scale when ready.

Free

$0forever

See exactly where you stand on SOC 2 before you pay anything.

  • Evidence collection — all 8 categories
  • 12 core SOC 2 controls
  • Overall compliance score
  • 1 machine · 1 user · community support
Download Free
Most popular

Pro

$149/month

Everything you need to hand an auditor a complete evidence pack.

  • All 54 SOC 2 controls · ISO 27001 (47) · HIPAA (47)
  • Per-control scoring, gaps, and remediation scripts
  • Control heatmap and score trend (Type II timeline)
  • Manual evidence upload + evaluation history
Start with Pro

Enterprise

$599/month

Tamper-evident, air-gapped sovereignty for regulated industries.

  • Everything in Pro
  • Tamper-evident audit log (SHA-256 hash chain)
  • RBAC — admin and auditor roles
  • Custom PDF branding
Contact Sales

Self-hosted pricing, billed annually. Managed hosting available.

Compare all plans and managed hosting

FAQ

Common questions.

Three, from a single collection pass: SOC 2 Type II (54 controls mapped to the AICPA Trust Services Criteria), ISO 27001 (47 scored controls spanning all 14 Annex A domains), and the HIPAA Security Rule (47 safeguards across all five 45 CFR Part 164 sections). The same OS-level evidence feeds all three.

Every evidence pack is mapped control-by-control to the AICPA Trust Services Criteria — the exact framework SOC 2 auditors work from. The PDF export follows the format used in successful SOC 2 Type I and Type II audits, so there's no reformatting and no back-and-forth. A formal SOC 2 report still requires a licensed CPA firm; ComplianceGuard gets you to that engagement prepared.

They scan cloud infrastructure; ComplianceGuard scans the machines themselves. Password policies, firewall rules, disk encryption, event logs — that evidence lives on the endpoint, not in AWS. Many teams run both: a cloud platform for SaaS integrations, ComplianceGuard for the endpoint evidence those platforms structurally can't see.

Don't trust claims — read the code. ComplianceGuard is source-available under BSL 1.1: every line that touches your machine is auditable. Licensing uses offline Ed25519 public-key verification, credentials are encrypted with HKDF-derived Fernet keys, and ~568 tests run on every commit. Most importantly, the architecture means we never receive your evidence — it stays on your disk, under your control.

You can — most first SOC 2 audits start that way. ComplianceGuard automates the collection: instead of checking firewall settings by hand, running scripts, and copying output into a spreadsheet, it reads everything in about 30 seconds and formats it the way your auditor expects.

It stays on your machine. ComplianceGuard reads from your OS and your AWS account, writes to a local SQLite database, and exports a PDF when you ask. There is no upload step and no telemetry. Evidence only moves if you explicitly enable the optional multi-machine dashboard sync.

Credentials are encrypted at rest using a Fernet key derived via HKDF-SHA256 from your local secret key. They are decrypted in memory only at evidence-collection time and are never transmitted anywhere. The source code is available, so you can verify this yourself.

No auditor marketplace — use whichever firm you want. No 40-app integration catalog — the focus is evidence, not workflow chrome. And no lock-in: evidence is stored locally in standard formats, so you can export it and switch tools at any time.

Your next enterprise deal
is waiting on a SOC 2 report.

Get audit-ready with evidence collected from the machines themselves — scored, signed, and under your control.

No account required. No cloud storage. No credit card for the free tier.