Skip to content
Browse docs

Compliance

Be audit-ready every day, not the week before the auditor arrives. The Compliance module continuously maps what Vigil already collects to the controls your frameworks require.

What it is

Automated evidence collection and control mapping across major frameworks, with a per-framework score and gap analysis so you always know where you stand.

What you get

  • Frameworks: SOC2, GDPR, HIPAA, PCI-DSS, ISO 27001
  • Automated evidence collection — reuses your existing monitoring, security, and cost data as control evidence, so you’re not gathering it by hand
  • Control mapping & gap analysis — see which controls are met and which need attention
  • Per-framework compliance score
  • Audit-readiness reports
  • Evidence templates and client upload — attach the documents only you can provide

How to enable

Included in the Complete package, or available as an add-on. Tell your Vigil team which framework(s) you’re pursuing.

How to read it

  • Framework score — coverage across that framework’s controls.
  • Controls — each control, its status, and the evidence attached to it.
  • Gap analysis — the specific controls still missing evidence, so you know exactly what to close.
  • Evidence — auto-collected items plus anything you’ve uploaded.

FAQ

Does Vigil certify me? Vigil gets you audit-ready and provides the evidence and readiness reports. Certification is issued by an accredited auditor. For hands-on preparation, see the one-time SOC2 Type I / Type II engagements in Plans & modules.

Where does evidence come from? Largely from data Vigil already collects (security scans, access data, monitoring). You upload only what’s unique to your organization.

Which frameworks are fully available today? SOC2 and GDPR have the deepest coverage; HIPAA, PCI-DSS, and ISO 27001 are supported for evidence mapping. Ask your Vigil team about coverage for your specific audit.

Was this page helpful?

Your response helps us improve this page.